Exchange 2013 Spam Filtering does not seem to be working

Posted on 2014-04-07
Last Modified: 2014-04-09
We have just recently migrated from Exchange 2010 to Exchange 2013 and when we made the switch we immediately started receiving a ton of spam.  I have run the antispm install script and have verified that all of our settings (blacklists, whitelists, etc.) were transfered over. From what I can tell, everything is setup properly on the new server, but we are getting much more spam. How can I tell that everything anti-spam is working properly on the Exchange 2013 server?

If I run Get-TransportAgent I receive the following:
Identity                                           Enabled         Priority
--------                                           -------         --------
Transport Rule Agent                               True            1
Malware Agent                                      True            2
Text Messaging Routing Agent                       True            3
Text Messaging Delivery Agent                      True            4
Content Filter Agent                               True            5
Sender Id Agent                                    True            6
Sender Filter Agent                                True            7
Recipient Filter Agent                             True            8
Protocol Analysis Agent                            True            9
Question by:OAC Technology
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39983940
If you use perfmon you can see how many messages were scanned by each option - for the content filter agent it will also show you what the count of each SCL value is.

Start there first, see if the values are above zero or not (they are reset by restarting the transport service).


Author Comment

by:OAC Technology
ID: 39984128
It looks like Performance Monitor is showing that messages are being scanned. As far as I can tell everything is set as it should be but we are getting spam email after spam email.
LVL 17

Expert Comment

by:Brad Bouchard
ID: 39984200
I'd check your SCL levels.  See here:

You can adjust them a little at a time until you find the sweet spot.
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

by:OAC Technology
ID: 39984212
I just realized that Connection Filtering isn't installed on Exchange 2013. When I run Enable-TransportAgent "Connection Filtering Agent"
I get the response "Transport agent "Connection Filtering Agent" isn't found. This means my RBL's and reverse DNS aren't looking, correct? Is there a way to enable this?
LVL 17

Accepted Solution

Brad Bouchard earned 500 total points
ID: 39984267

Author Comment

by:OAC Technology
ID: 39984277
Thanks. I was able to get this installed, but there is a 3 or 4 minute delay on incoming emails. Although if it is working properly and we don't get any more spam, it is worth the delay. I'll post back tomorrow if this did not solve the problem. Thanks for your help!
LVL 17

Expert Comment

by:Brad Bouchard
ID: 39984445
The delay will most likely go away.  Let me know how it goes.

Author Comment

by:OAC Technology
ID: 39988771
The delay is still there, but spam has drastically decreased now. Thank you for your help on this

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question