Thank you very much, I will defiantly try it, Bu I still need to know how it do with Exchange Anti Spam.
Main Topics
Browse All TopicsHello all,
I have windows server 2009 with Exchange 07 running on it. I have enabled the Anti-Spam option on the Hub transport and I have been using it to filter spam. but obviously some spam still comes in. I need to know the steps to take to prevent those spam emails from coming again. For example I am getting a lot of spam emails from Facebook which I know now it contain a malware. When I check the massage details its always from different IP address's and different domains.
Below is a sample of the massage detail on one of those massages.
What should I be looking for when I get such spam? Which IP or Domain to block? What are the proper steps to take?
Received: from 14.214.205-77.rev.gaoland.
mycompany.com (10.6.0.9) with Microsoft SMTP Server id
8.1.311.2; Tue, 3 Nov 2009 09:58:19 -0700
Received: from 77.205.214.14 by mx.sina.net; Tue, 3 Nov 2009 17:53:27 +0100
From: Facebook <update+afiqsfw@facebookma
To: <user@mycompany.com>
Subject: new login system
Date: Tue, 3 Nov 2009 17:53:27 +0100
Message-ID: <000d01ca5ca6$2a672610$640
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_0
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.3416
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1437
Importance: Normal
Return-Path: holtqnzc5@shuangdeng.sina.
X-MS-Exchange-Organization
X-MS-Exchange-Organization
Received-SPF: Fail (mycompany.com: domain of
update+afiqsfw@facebookmai
permitted sender) receiver= mycompany.com;
client-ip=77.205.214.14; helo=14.214.205-77.rev.gao
X-MS-Exchange-Organization
X-MS-Exchange-Organization
X-MS-Exchange-Organization
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
here is a complete guide in how to install it AND uninstall it: http://www.petri.co.il/ins
hope this is what youre seeking :)
you will need to set you imf filter higher.
take a look at this page: http://exchangepedia.com/b
ooh.. and if needed you can also whitelist specific domains ;)
http://exchangepedia.com/b
thanx again Wraithbone, I have already done that.. but i am still getting Spam emails . let me try to explain my self better.
I am still getting spam emails after configuring all the above, I am assuming i should block the sender's email address , domain or IP address. if am correct how do i know these information from the massage detail i provided in the email erlier. specially that they always keep changeing.
this seems to be what youre looking for. with this you will be able to block for specific domains:
http://technet.microsoft.c
please tell me if this helps you.
The first line has the senders information. Received: from 14.214.205-77.rev.gaoland.
I know, I have done it and it is a never ending battle.
My recommendation is to use connection filltering in your Exchange setup. Set up RBLs that will do the checking for you. Most people will start out with zen.spamhaus.org but after much testing I have found that installing the following three RBLs in the order listed provides exceptional spam protection.
1. Spamhaus (zen.spamhaus.org)
2. Barracuda (b.barracudacentral.org) You must register for this one but it's still free
3. UCEProtect-3 (dnsbl-3.uceprotect.net)
To find out which blacklists are effective is to test the sending ip address (in the example you gave, 77.205.214.14) against blocklists at http://mxtoolbox.com/black
Please let me know if you need any additional assistance in setting your connection filtering up. There are some additional tools for testing if you need more info. In my opinion, connection filtering is the best kept secret of Exchange.
Business Accounts
Answer for Membership
by: alanhardistyPosted on 2009-11-03 at 11:24:00ID: 25732484
Install a trial of Vamsoft www.vamsoft.com only $239 if you decide to buy. Brilliant at killing spam.