Solved

Exchange 2007 delivering email marked as SPAM

Posted on 2014-01-04
6
586 Views
Last Modified: 2014-01-13
Our domain has a known manufacturer's firewall through which all email traffic must flow before reaching our Exchange Server.

We subscribe to Anti-Virus and Anti-Spyware services from this firewall manufacturer.  Therefore, all email receives a scan while passing through this device.  If Spam is detected by the firewall, the message is tagged and the word "SPAM" is added to the subject line.  The email then passes through to the Exchange Server for delivery to the email recipient.

The firewall can be set to "discard" rather than "tag" the email as it comes through.  However, the "discard" action can only be set for SMTP traffic, whereas POP3 traffic can only be set to "tag".  I'm assuming that POP3 traffic would be emails from the outside world delivered to our domain via email senders using @Hotmail.com, @yahoomail.com, etc.

I would like to stop delivery of these messages to the email recipient.

I'm wondering if the Exchange Server can be set to recognize a key work in the subject line (in my case the word "SPAM") and simply NEVER deliver the email?
0
Comment
Question by:baleman2
  • 2
  • 2
  • 2
6 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 200 total points
ID: 39756189
Yes just set up a hub transport rule on the exchange server to move all messages with "SPAM" in the subject line to deleted items or a spam folder of your choosing.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 39756191
0
 

Author Comment

by:baleman2
ID: 39756217
Thanks, Pete.

I'd like to get more info concerning the destination of the discarded messages.  When you mentioned the "Deleted Items" or "Spam" folder, would that be a newly created folder on the Exchange Server?  Or, could the message continue to be delivered to the end recipient but automatically be delivered to a folder in his/her mailbox, i.e., "Junk", "Deleted Items", etc., thereby, bypassing the "Inbox" folder of the end recipient.

Our organization would benefit if the message could still be examined by the end recipient.  This would come into play when the firewall detects a "false positive" in an email message.  Right now, the message is still delivered so that the end recipient can inform me that the email "sender" is from a reliable source.  I, in turn, will add that email "sender" to the White List in the firewall which allows delivery.  

Although our White List now contains most of the email addresses of trusted "senders", a transport rule deleting all messages with the word "SPAM" in the subject line would prohibit an end recipient receiving a possibly important email.

I'm just beginning the process of thinking this through.  Any additional input would be greatly appreciated.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39757935
"I'm assuming that POP3 traffic would be emails from the outside world delivered to our domain via email senders using @Hotmail.com, @yahoomail.com, etc."

Your assumption there is WRONG.

POP3 traffic would be traffic from your server to your own clients using POP3. With Exchange, you don't normally use POP3, you would use Outlook Anywhere.

Therefore all of your external email traffic is SMTP traffic - nothing else.

The simple method is the one that has been outlined - set your firewall to discard nothing, then configure a transport rule to assign an SCL value of 9 to all emails with the spam tag. The messages will then go in to the junk email folder within Outlook. This is also available through OWA. User can then sort through the messages themselves, deleting the spam and rescuing the valid.

Simon.
0
 

Author Comment

by:baleman2
ID: 39759356
To Simon:

Before I received your post, I'd followed Pete's instructions and created a Transport Rule.  If the word "SPAM" is detected in the Subject Line, the email never gets delivered by our Exchange Server.  The word "SPAM" would be in the Subject Line ONLY if placed there as a "tag" by our hardware firewall (before passing the message along to the Exchange Server) - which would ONLY place the word "SPAM" there if something was detected based on its own malware/spyware/virus definitions.  

In doing so, I found that (within the options provided) I could send a "bounceback" message to the original sender.  I could also modify the message to read, "Our Exchange Server has detected a problem with your email.  Please contact the Addressee with this information."

If there is not some undiscovered problem with this option, I may just leave it alone.  This has already stopped nuisance emails from populating our end users' mailboxes.  It also gives the "sender" (if a valid sender) the opportunity to call in and get on our White List.  If the original sender is not a valid sender anyway, no harm done???????  If the original sender's email was indeed infected, the bounceback message would give them some warning of problems on their end.

Please advise.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 300 total points
ID: 39760074
That is the best way to do things, although ideally the bounce should happen at the point of delivery. If you are allowing the email to be delivered then Exchange bounces it, you are causing backscatter - this can get you blacklisted.
Is the firewall unable to bounce the message? Again by using the firewall to bounce the message the NDR could include information about why it was bounced - being on a blacklist for example, and which one.

You are correct that spammers will not see the messages, but you could cause more problems than it is worth.

Rules to bounce the message should be done at the gateway, otherwise you need to delete or put the messages in to the junk email folder. Bouncing them further on is a bad idea.

Simon.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question