Marc indeed has some excellent ideas and we are working to provide him with
the output/logs he requires.

We strive to be flexible and add features that clients request. The end
result is a cost effective customized solution.

Regards,

David Gregg
dgSoft Internet Services
+1.949.584-1514

---
mxGuard for IMail
Server based spam and virus protection for under $100
Run multiple virus scanners at no extra charge!
Get a free trial at http://www.mxGuard.com/Postmaster
---

----- Original Message ----- 
From: "isp-lists [at] beachcomp.com" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, March 19, 2004 7:12 AM
Subject: RE: [IMail Forum] Spam


> Marc
>
> Sounds like a very clever idea!
> Do you know if David has any plans on implementing it into MX?
> Do you have plans for mxblock, or do you think you'll be able to share it?
> I'd be very interested.
>
> Thanks!
>
>   _____
>
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of Marc A. Funaro
> Sent: Friday, March 19, 2004 10:02 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] Spam
>
>
> We're using mxGuard with some aggressive settings, and I've written a
custom
> application ( "mxBlock?" :) that takes the most hardcore spam (those on
two
> or more blacklists, as determined by mxGuard), parses the mxGuard headers,
> and creates a 15-day IPSec filter to block the IP address of a delivering
> mail server that has sent three or more, 2+ blacklisted, messages to our
> box.  The IPSec filters are recreated every two hours, to contain all the
> most recent IPs that we've received.
>
> The IPSec filter seems to be working great, and unless I've got this
wrong,
> actually has the net effect of bogging down the spamming server
somewhat...
> because instead of being outright rejected, the sending server simply
> believes that our machine is unreachable, and keeps the spam in its smtp
> queue for up to three days (someone correct me if I'm wrong here!).  I
> wonder, if everyone dropped packets from the really offensive sending
> servers, if those servers would end up queuing lots of undeliverable spam
> (?).
>
> We're working on whitelisting at the filter level now, as are the mxGuard
> folks for the processing level.
>
> Regardless of the effect on the sending server of our dropping their
packets
> without response, we've seen a reduction in delivery from the
> greatly-blacklisted spam servers overall, and mxGuard has been very
accurate
> with regards to the rest that we do have to process.  There's still a
pretty
> even ratio of spam to legit messages being PROCESSED, but when a message
is
> on two or more blacklists, the subject modifier becomes [block] and goes
> into our IPSec filters.  All others have a subject modifier of [spam!] or
> [spam?], and our users set up iMail rules to block/move those messages.
>
> As the list of IPSec-blocked IPs grows, we will see less spam overall, so
> it's a cumulative thing.  After 15 days, if we receive even ONE
> two-or-more-blacklisted messages from an IP address we had blocked, it is
> automatically reblocked.  Our IPSec blocked IP filter list is now over
1000
> IPs and growing, and there's been no performance hit on the machine at
all.
> (My only concern is whether there is a programmatic limit on how many
> filters a windows 2003 server IPSec filter list can have!!)
>
> It's been an interesting system to design, overall, and we couldn't have
> done it without mxGuard... but i've enjoyed building it and I'm hoping to
> port it from the current solution to a fully java-based add-on, right on
the
> mxGuard-enabled mail server... and add filter output for other types of
> filters like pktFilter and perhaps other scriptable firewalls, AND take
> direct-log input instead of/in addition to the slower
> parsing-of-spam-headers routine already in place.
>
> Our above solution came out of the shortcomings of iMail 7.1x, which we
are
> still using because of budgetary constraints.  And mxGuard has been an
> excellent low-cost solution for handling spam AND viruses.
>
> I just realized how long and rambling this is... sorry!
>
> Marc
>
>
>
> -----Original Message-----
> From: KathyJ [mailto:[EMAIL PROTECTED]
> Sent: Friday, March 19, 2004 9:22 AM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] Spam
>
>
>  I too am losing the spam war, although my troops have been pushing
forward
> while I try to configure declude on a 30 trial basis.  If I can make it
work
> well, my boss will buy it.
>
> I have basically been told my job rides on this :-(  I think I will go
back
> to fixing PC's for a living.. or maybe waitressing.
>
>
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of Glenn Bullion
> Sent: Friday, March 19, 2004 9:06 AM
> To: IMail_Forum (E-mail)
> Subject: [IMail Forum] Spam
>
> Just wanted to bring up a topic we've all talked about endlessly.  I
wanted
> to see how you guys handled spam on your Imail server.  I'm using a small
> set of DNS blacklists, content filtering, and a semi large kill.lst file.
> How about you guys?  It seems like I'm losing the war badly though.
>


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to