Solved

Can Forefront 2010 Excnage block sender keywords?

Posted on 2010-11-25
13
1,046 Views
Last Modified: 2012-05-10
I have Forefront 2010 for Exchange installed. I get spam from senders such as:-

Best Pfizer <me@mydomain.com>

Obviously I don't want to block my own address or domain in Forefront, what I want to do is scan for certain words in the senders address, or scan the entire email (body, headers and subject etc)...

Can this be done
0
Comment
Question by:Chris Millard
  • 4
  • 3
  • 3
  • +2
13 Comments
 
LVL 33

Expert Comment

by:Busbar
ID: 34211123
configure and enable back scaktter, this will prevent this.
0
 
LVL 17

Author Comment

by:Chris Millard
ID: 34211352
Do you by any chance have a link to how to do this?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 34211489
@Busbar - What are you referring to?

Backscatter is the sending on Non Delivery Reports to Spammers due to not having Recipient Filtering on your own server.  What has this got to do with the question?

@roybridge - You can configure Content Filtering on the FTMG server to pick up words that don't get automatically filtered.  Personally - I have found the Anti-Spam measures on Exchange 2010 and FTMG to be severely lacking and have disabled them in favour of Vamsoft ORF - which continues to do a much better job IMHO.
0
 
LVL 16

Expert Comment

by:Auric1983
ID: 34212421
I agree with @Alanhardisty, regarding Vamsoft ORF, it's cheap and works really really well.  We use it here and have close to a 98% spam blocking ratio.



0
 
LVL 33

Expert Comment

by:Busbar
ID: 34212500
@Alan,
FFPE wasn't but biggest strength points I understood BS wrongfully, thanks for pointing it out.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 34212754
No probs Busbar.  Wasn't sure if you were posting in the wrong question : )
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 34213698
Sure it can do it.

Open the gui - select Policy Management
Select filters - -Filter lists.
Click create - select Keyword - Give the filter a meaningful name - such as 'Naughty Words'
Add the words to the list then click next.
Edit - of necessary - the hub transport details and what to do with emails that match these words and finally whether the filter is to act on inbound, outbound or internal mails (or all of them).
Then click on CREATE.
Job done

0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 34213702
You can also select other wizards in the same section for sender, recipient, domains etc and slowly build up your set of rules.
0
 
LVL 17

Accepted Solution

by:
Chris Millard earned 0 total points
ID: 34345840
Unfortunately I have not been able to get ForeFront to block keywords in the senders address, and can not afford to purchase a 3rd party program to do this, so I will live with it for the time being.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 34345994
Let me break this down a last time.

In respect to your specific question - turn on the option to allow delivery to addresses named in your central Exchange address list . This will stop the delivery of ANYthing that uses your internal namespace without having a valid user name/mail address. I've attached a screenshot for you to view.

Checking words is performed by a various filer lists as I mention previously.


 block-recip.docx
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 34346981
Not sure if my article about preventing spam from your own domain is something you would consider as a solution to your problem.

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2727-Prevent-Spam-From-Your-Own-Domain-in-Exchange-2007.html

This removes the ability for anonymous users to send mail from your internal domains to your server, cutting this type of spam out completely.

Don't know why I didn't think of this before!

Alan
0
 
LVL 17

Author Closing Comment

by:Chris Millard
ID: 34387548
I have not been able to resolve this issue, so will continue as-is.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 34387606
Absolutely ridiculous.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now