Actually, I have just such an account (used mainly for testing) -- never
gets dropped by our rules. Does get flagged sometimes, but you would have to
have more than such an address problem (in fact, the account I use has
several problems, such as failing the IPNOTINMX test, but none severe enough
to be a problem).  As I said below, if you have remote forwarding users
(like these, or users who work from outside your IP's), you would want to
add a warning label to such mails, not delete on that one problem. Of
course, I know some companies who simply set policies that all external
users use web mail only, no outside servers can send company email (usually
for tracking/archiving/legal reasons) -- they can be more strict about
internal mail addresses coming from outside (and VPN connections used to
overcome remote IPs).  It can be annoying to sales types and road warriors,
if not set up correctly.

We use declude to add enough weight to flag these emails (internal from
address, not from our server) as spam. Fail any other test and they get held
(we hold at 15 and I've seen emails that end up with over 100 points, due to
include of spam URL and phrases, failing every single ip4r test, etc ).
legit internal mail gets negative points (or whitelisted from some IP's -
when AUTH detection is added, we use that).  Mail claiming to be from our
server is simply deleted - I monitored this for some time and there was
never a legit mail server that did this. We also evaluate spam URL's for
some time (2 levels of hold, moving to delete after some time), rather than
allowing deletion immediately after such an URL (or sending server) is
found. I don't know if you can do this directly with IMAIL's anti-spam.

No doubt, the spammers will keep finding more ways around the rules and new
rules and detection methods will get developed -- keeping all of us busy
messing with this instead of actually answering the legit emails we receive.

Karen

> -----Original Message-----
> From: Evan Pearce
>
> On 12/08/2003 at 13:45:44, Karen D. Oland wrote:
>
> > We also drop mail that claims to be from an account on our  server that
is
> > not sent from our IP's (or add a warning in the subject line,  if you
have
> > external /remove users -- soon declude will detect auth users  and we
will be
> > able to block all fake users as you are seeing entirely,  without
weights).
>
> There is actually a risk of false positives in doing that. Whether it
> affects you or not really depends on your users.
>
> Suppose user1 has accounts with you and some other mail server, but
> has their other mail forwarding back to their account with you. Then
> suppose [EMAIL PROTECTED] sends mail to [EMAIL PROTECTED]
> The server at them.example.net will forward it back to your server
> with an envelope sender address of <[EMAIL PROTECTED]> and
> recipient of <[EMAIL PROTECTED]>.

---
[This E-mail scanned for viruses by Declude Virus]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to