Actually, I have just such an account (used mainly for testing) -- never gets dropped by our rules. Does get flagged sometimes, but you would have to have more than such an address problem (in fact, the account I use has several problems, such as failing the IPNOTINMX test, but none severe enough to be a problem). As I said below, if you have remote forwarding users (like these, or users who work from outside your IP's), you would want to add a warning label to such mails, not delete on that one problem. Of course, I know some companies who simply set policies that all external users use web mail only, no outside servers can send company email (usually for tracking/archiving/legal reasons) -- they can be more strict about internal mail addresses coming from outside (and VPN connections used to overcome remote IPs). It can be annoying to sales types and road warriors, if not set up correctly.
We use declude to add enough weight to flag these emails (internal from address, not from our server) as spam. Fail any other test and they get held (we hold at 15 and I've seen emails that end up with over 100 points, due to include of spam URL and phrases, failing every single ip4r test, etc ). legit internal mail gets negative points (or whitelisted from some IP's - when AUTH detection is added, we use that). Mail claiming to be from our server is simply deleted - I monitored this for some time and there was never a legit mail server that did this. We also evaluate spam URL's for some time (2 levels of hold, moving to delete after some time), rather than allowing deletion immediately after such an URL (or sending server) is found. I don't know if you can do this directly with IMAIL's anti-spam. No doubt, the spammers will keep finding more ways around the rules and new rules and detection methods will get developed -- keeping all of us busy messing with this instead of actually answering the legit emails we receive. Karen > -----Original Message----- > From: Evan Pearce > > On 12/08/2003 at 13:45:44, Karen D. Oland wrote: > > > We also drop mail that claims to be from an account on our server that is > > not sent from our IP's (or add a warning in the subject line, if you have > > external /remove users -- soon declude will detect auth users and we will be > > able to block all fake users as you are seeing entirely, without weights). > > There is actually a risk of false positives in doing that. Whether it > affects you or not really depends on your users. > > Suppose user1 has accounts with you and some other mail server, but > has their other mail forwarding back to their account with you. Then > suppose [EMAIL PROTECTED] sends mail to [EMAIL PROTECTED] > The server at them.example.net will forward it back to your server > with an envelope sender address of <[EMAIL PROTECTED]> and > recipient of <[EMAIL PROTECTED]>. --- [This E-mail scanned for viruses by Declude Virus] To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
