Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Exchange 2007 delivering email marked as SPAM

Posted on 2014-01-04
6
Medium Priority
?
612 Views
Last Modified: 2014-01-13
Our domain has a known manufacturer's firewall through which all email traffic must flow before reaching our Exchange Server.

We subscribe to Anti-Virus and Anti-Spyware services from this firewall manufacturer.  Therefore, all email receives a scan while passing through this device.  If Spam is detected by the firewall, the message is tagged and the word "SPAM" is added to the subject line.  The email then passes through to the Exchange Server for delivery to the email recipient.

The firewall can be set to "discard" rather than "tag" the email as it comes through.  However, the "discard" action can only be set for SMTP traffic, whereas POP3 traffic can only be set to "tag".  I'm assuming that POP3 traffic would be emails from the outside world delivered to our domain via email senders using @Hotmail.com, @yahoomail.com, etc.

I would like to stop delivery of these messages to the email recipient.

I'm wondering if the Exchange Server can be set to recognize a key work in the subject line (in my case the word "SPAM") and simply NEVER deliver the email?
0
Comment
Question by:baleman2
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 800 total points
ID: 39756189
Yes just set up a hub transport rule on the exchange server to move all messages with "SPAM" in the subject line to deleted items or a spam folder of your choosing.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 39756191
0
 

Author Comment

by:baleman2
ID: 39756217
Thanks, Pete.

I'd like to get more info concerning the destination of the discarded messages.  When you mentioned the "Deleted Items" or "Spam" folder, would that be a newly created folder on the Exchange Server?  Or, could the message continue to be delivered to the end recipient but automatically be delivered to a folder in his/her mailbox, i.e., "Junk", "Deleted Items", etc., thereby, bypassing the "Inbox" folder of the end recipient.

Our organization would benefit if the message could still be examined by the end recipient.  This would come into play when the firewall detects a "false positive" in an email message.  Right now, the message is still delivered so that the end recipient can inform me that the email "sender" is from a reliable source.  I, in turn, will add that email "sender" to the White List in the firewall which allows delivery.  

Although our White List now contains most of the email addresses of trusted "senders", a transport rule deleting all messages with the word "SPAM" in the subject line would prohibit an end recipient receiving a possibly important email.

I'm just beginning the process of thinking this through.  Any additional input would be greatly appreciated.
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39757935
"I'm assuming that POP3 traffic would be emails from the outside world delivered to our domain via email senders using @Hotmail.com, @yahoomail.com, etc."

Your assumption there is WRONG.

POP3 traffic would be traffic from your server to your own clients using POP3. With Exchange, you don't normally use POP3, you would use Outlook Anywhere.

Therefore all of your external email traffic is SMTP traffic - nothing else.

The simple method is the one that has been outlined - set your firewall to discard nothing, then configure a transport rule to assign an SCL value of 9 to all emails with the spam tag. The messages will then go in to the junk email folder within Outlook. This is also available through OWA. User can then sort through the messages themselves, deleting the spam and rescuing the valid.

Simon.
0
 

Author Comment

by:baleman2
ID: 39759356
To Simon:

Before I received your post, I'd followed Pete's instructions and created a Transport Rule.  If the word "SPAM" is detected in the Subject Line, the email never gets delivered by our Exchange Server.  The word "SPAM" would be in the Subject Line ONLY if placed there as a "tag" by our hardware firewall (before passing the message along to the Exchange Server) - which would ONLY place the word "SPAM" there if something was detected based on its own malware/spyware/virus definitions.  

In doing so, I found that (within the options provided) I could send a "bounceback" message to the original sender.  I could also modify the message to read, "Our Exchange Server has detected a problem with your email.  Please contact the Addressee with this information."

If there is not some undiscovered problem with this option, I may just leave it alone.  This has already stopped nuisance emails from populating our end users' mailboxes.  It also gives the "sender" (if a valid sender) the opportunity to call in and get on our White List.  If the original sender is not a valid sender anyway, no harm done???????  If the original sender's email was indeed infected, the bounceback message would give them some warning of problems on their end.

Please advise.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 1200 total points
ID: 39760074
That is the best way to do things, although ideally the bounce should happen at the point of delivery. If you are allowing the email to be delivered then Exchange bounces it, you are causing backscatter - this can get you blacklisted.
Is the firewall unable to bounce the message? Again by using the firewall to bounce the message the NDR could include information about why it was bounced - being on a blacklist for example, and which one.

You are correct that spammers will not see the messages, but you could cause more problems than it is worth.

Rules to bounce the message should be done at the gateway, otherwise you need to delete or put the messages in to the junk email folder. Bouncing them further on is a bad idea.

Simon.
0

Featured Post

Learn Veeam advantages over legacy backup

Every day, more and more legacy backup customers switch to Veeam. Technologies designed for the client-server era cannot restore any IT service running in the hybrid cloud within seconds. Learn top Veeam advantages over legacy backup and get Veeam for the price of your renewal

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After hours on line I found a solution which pointed to the inherited Active Directory permissions . You have to give/allow permissions to the "Exchange trusted subsystem" for the user in the Active Directory...
If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question