Exchange IMF - filtering html emails with xml file?

Posted on 2009-02-24
Last Modified: 2012-05-06
I am running exchange 2003 sp2 and have IMF v2 enabled.  IMF seems to be working well, however we are getting an influx of spoofed email.  In particular it's the email going around with varying (legitimate looking) subject lines, but the following in the body (see sample bmp).
"We ship worldwide! To all countries! To all destinations"
I attempted to setup the custom weight XML file with body filtering enabled for the phrase above, however since the email is in html form, i think it is bypassing it.  This rule is working as i sent a text email from a personal address with the phrase and it was caught, sending it to the UCEarchive folder.  Any thoughts on a new xml file entry that might catch this HTML email at the gateway before hitting my user's mailboxes?
Thanks in advance!
Question by:joseph_mumm
    LVL 3

    Accepted Solution

    Try using these settings to stop receiving emails on exchange server

    Recepient Filtering - Checked Filter recipients who are not in directory.

    Sender Filtering - Checked archive filtered messages,Filter messages with blank sender,accept messages without notifying sender of filtering.

    Connection Filtering - Added and added the ip address to except 3 and 9.

    IMF - Block messages with an SCL rating greater than or equal to 7
             Move messages with an SCL rating greater than or equal to 6      

    Sender Id filtering - Accept
    LVL 15

    Expert Comment

    This doesn't use the IMF but....

    Make sure reverse DNS checking is on.  You can turn it on under ESM > Administratove Groups > First administrative group > Servers > (your server name) > Protocol > SMTP > right click on Default SMTP Virtual Server >  click on the Delivery tab > click on the advance button > check the box that says Perform reverse DNS lookup on incoming messages.

    If that doesn't work then a temporary fix would be to create a rule in Outlook to move any emails sent from the user  to the user to the junk email directory.  For the few users that do send email to their own email addresses setup a new folder called "Emails to myself" and have all the emails go their.


    Author Comment

    tenaj-207... any suggestions for external dns servers to query for the reverse lookup?
    LVL 15

    Expert Comment

    Your defaults should be fine.  Any DNS server can do a reverse dns lookup, there's no need to configure the external dns servers.

    Author Closing Comment

    there was a bunch of RBL's in the conneciton filtering options, however connection filtering was not checked off in the smtp virtual server.  Thanks!

    Featured Post

    Why spend so long doing email signature updates?

    Do you spend loads of your time carrying out email signature updates? Not very interesting are they? Don’t let signature updates get you down. Let Exclaimer Cloud - Signatures for Office 365 make managing email signatures a breeze.

    Join & Write a Comment

    Suggested Solutions

    Email statistics and Mailbox database quotas You might have an interest in attaining information such as mailbox details, mailbox statistics and mailbox database details from Exchange server. At that point, knowing how to retrieve this information …
    Set up iPhone and iPad email signatures to always send in high-quality HTML with this step-by step guide.
    In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
    The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

    729 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now