Marc indeed has some excellent ideas and we are working to provide him with the output/logs he requires.
We strive to be flexible and add features that clients request. The end result is a cost effective customized solution. Regards, David Gregg dgSoft Internet Services +1.949.584-1514 --- mxGuard for IMail Server based spam and virus protection for under $100 Run multiple virus scanners at no extra charge! Get a free trial at http://www.mxGuard.com/Postmaster --- ----- Original Message ----- From: "isp-lists [at] beachcomp.com" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, March 19, 2004 7:12 AM Subject: RE: [IMail Forum] Spam > Marc > > Sounds like a very clever idea! > Do you know if David has any plans on implementing it into MX? > Do you have plans for mxblock, or do you think you'll be able to share it? > I'd be very interested. > > Thanks! > > _____ > > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Marc A. Funaro > Sent: Friday, March 19, 2004 10:02 AM > To: [EMAIL PROTECTED] > Subject: RE: [IMail Forum] Spam > > > We're using mxGuard with some aggressive settings, and I've written a custom > application ( "mxBlock?" :) that takes the most hardcore spam (those on two > or more blacklists, as determined by mxGuard), parses the mxGuard headers, > and creates a 15-day IPSec filter to block the IP address of a delivering > mail server that has sent three or more, 2+ blacklisted, messages to our > box. The IPSec filters are recreated every two hours, to contain all the > most recent IPs that we've received. > > The IPSec filter seems to be working great, and unless I've got this wrong, > actually has the net effect of bogging down the spamming server somewhat... > because instead of being outright rejected, the sending server simply > believes that our machine is unreachable, and keeps the spam in its smtp > queue for up to three days (someone correct me if I'm wrong here!). I > wonder, if everyone dropped packets from the really offensive sending > servers, if those servers would end up queuing lots of undeliverable spam > (?). > > We're working on whitelisting at the filter level now, as are the mxGuard > folks for the processing level. > > Regardless of the effect on the sending server of our dropping their packets > without response, we've seen a reduction in delivery from the > greatly-blacklisted spam servers overall, and mxGuard has been very accurate > with regards to the rest that we do have to process. There's still a pretty > even ratio of spam to legit messages being PROCESSED, but when a message is > on two or more blacklists, the subject modifier becomes [block] and goes > into our IPSec filters. All others have a subject modifier of [spam!] or > [spam?], and our users set up iMail rules to block/move those messages. > > As the list of IPSec-blocked IPs grows, we will see less spam overall, so > it's a cumulative thing. After 15 days, if we receive even ONE > two-or-more-blacklisted messages from an IP address we had blocked, it is > automatically reblocked. Our IPSec blocked IP filter list is now over 1000 > IPs and growing, and there's been no performance hit on the machine at all. > (My only concern is whether there is a programmatic limit on how many > filters a windows 2003 server IPSec filter list can have!!) > > It's been an interesting system to design, overall, and we couldn't have > done it without mxGuard... but i've enjoyed building it and I'm hoping to > port it from the current solution to a fully java-based add-on, right on the > mxGuard-enabled mail server... and add filter output for other types of > filters like pktFilter and perhaps other scriptable firewalls, AND take > direct-log input instead of/in addition to the slower > parsing-of-spam-headers routine already in place. > > Our above solution came out of the shortcomings of iMail 7.1x, which we are > still using because of budgetary constraints. And mxGuard has been an > excellent low-cost solution for handling spam AND viruses. > > I just realized how long and rambling this is... sorry! > > Marc > > > > -----Original Message----- > From: KathyJ [mailto:[EMAIL PROTECTED] > Sent: Friday, March 19, 2004 9:22 AM > To: [EMAIL PROTECTED] > Subject: RE: [IMail Forum] Spam > > > I too am losing the spam war, although my troops have been pushing forward > while I try to configure declude on a 30 trial basis. If I can make it work > well, my boss will buy it. > > I have basically been told my job rides on this :-( I think I will go back > to fixing PC's for a living.. or maybe waitressing. > > > > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Glenn Bullion > Sent: Friday, March 19, 2004 9:06 AM > To: IMail_Forum (E-mail) > Subject: [IMail Forum] Spam > > Just wanted to bring up a topic we've all talked about endlessly. I wanted > to see how you guys handled spam on your Imail server. I'm using a small > set of DNS blacklists, content filtering, and a semi large kill.lst file. > How about you guys? It seems like I'm losing the war badly though. > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
