Solved

Why the antispam features do not work in my Exchange server?

Posted on 2015-02-06
8
222 Views
Last Modified: 2015-03-12
This is using MS Exchange server 2013. However, even that I already configured the antispam to work, I don't think it is working as none of the spam caught and sent to my quarantine mailbox. This is how I configure the antispam:

   a.      Open EMS, and browse to D:\Program Files\Microsoft\Exchange Server\v15\Scripts\;
double-click Install-antispamAgents.ps, to install antispam feature

b.      In EMS, type get-transportagent:

c.      In EMS, type get-transportconfig | fl internalSMTPServers; ensure the Exchange Server IP is included

d.      In EMS, type get-transportservice | fl Agentlog*; to see the settings as follows:

-      AgentLogMaxAge
-      AgentLogDirectorySize
-      AgentLogFileSize
-      AgentLogPath
-      AgentLogEnabled
e.      In EMS, type get-contentfilterconfig | fl SCL*; to see the SCLs for Delete, Reject, and Quarantine:

-      SCLDeleteThreshold (9); SCLDeleteEnabled (true)
-      SCLRejectThreshold (8); SCLRejectEnabled (false)
-      SCLQuarantineThreshold (6); SCLQuarantineEnabled (true)

f.      In EMS, type get-OrganizationConfig | SCL*; to see the settings for SCLJunkThreshold:

-      SCLJunkThreshold (5)

g.      In EMS, type get-SenderIDConfig | fl Spoofed*; to see the settings:

-      SpoofedDomainAction (StampStatus)

h.      In EMS, type get-SenderReputationConfig | fl: to see the selective settings:

-      SenderBlockingEnabled (true)
-      SrlBlockThreshold          (6)        * default, 7
-      SenderBlockingPeriod    (36)      * default, 24

i.      In EMS, type get-SetSenderFilterConfig | fl Block*; to add in and see the current blocked sender and blocked sender domain:

Set-SenderFilterConfig -BlankSenderBlockingEnabled $true –BlockedDomainsAnd Subdomains lucernepublishing.com -BlockedSenders @{Add="user1@contoso.com","user2@contoso.com"}

-      BlankSenderBlockingEnabled (true)

j.      In EMS, type get-IPBlockListProvider; to see list of RBL in descending priority:

Add-IPBlockListProvider:
-      name (bl.spamcop.net); lookupdomain (bl.sampcop.net)
-      name (bb.barracudacentral.org); lookupdomain (bb.barracudacentral.org)
-      name (ix.dnsbl.manitu.net); lookupdomain (ix.dnsbl.manitu.net)
-      name (combined.njabl.org); lookupdomain (combined.njabl.org)
-      name (zen.spamhaus.org); lookupdomain (zen.spamhaus.org)
-      name (psbl.surriel.net); lookupdomain (psbl.surriel.net)

k.      In EMS, type get-IPAllowListProvider; to see list of RBL in descending priority:

Add-IPAllowListProvider:
-      name (swl.spamhaus.org); lookupdomain (swl.spamhaus.org)
-      name (iadb.isipp.com); lookupdomain (iadb.isipp.com)
-      name (query.bondedsender.org); lookupdomain (query.bondedsender.org)


Anything I missed out?
0
Comment
Question by:MichaelBalack
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 4

Expert Comment

by:Alexander Kireev
ID: 40596584
Hello,

Did you restart "MsExchange Transport Service" service to take effect?

To verify you could check statistics of your Anti-Spam filters by Get-AntiSpamFilteringReport.ps1 script.
https://technet.microsoft.com/en-us/library/bb124795%28v=exchg.150%29.aspx
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40600260
Hi Alexander,

Yes, transport service was restarted.

Give me some times to look into the link.
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40627663
Hi Alexander,

Sorry for the delay due to the long lunar chinese new year. I'll look into it tonite.
0
Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

 
LVL 1

Author Comment

by:MichaelBalack
ID: 40637797
Hi Alexander,

Please see the errors...
get-antispamreport.bmp
0
 
LVL 4

Expert Comment

by:Alexander Kireev
ID: 40637833
Hello,

I think that you didn't set a command parameter.

You can run this script to draw a report for the Exchange Anti Spam Agents. The following values are accepted as command parameters:

    messagesrejected
    messagesdeleted
    connections
    messagesquarantined

Usage:

    .\Get-AntispamFilteringReport.ps1 <command> –report <path>
http://www.proexchange.be/blogs/exchange2010/archive/2011/12/18/the-exchange-2010-scripts.aspx
http://social.technet.microsoft.com/wiki/contents/articles/19122.exchange-server-how-to-diagnose-spam-problem.aspx
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40637900
Hi Alexander,

I typed ".\get-antispamfilteringreport.ps1 messagesrejected c:\drivers\antispam_1.txt", and error occurred.

I typed ".\get-antispamsclhistogram.ps1" and the following table displayed:

name                                                                                     value
1                                                                                             1
8                                                                                             1
0                                                                                             3
7                                                                                             32
not availble: content filtering bypassed                          67

Any comment?
0
 
LVL 4

Accepted Solution

by:
Alexander Kireev earned 500 total points
ID: 40638102
Is your ContentFilter Enabled? (Set-ContentFilterConfig -Enabled $true)
Is your SenderID Enabled? (Set-SenderIdConfig -Enabled $true)

Try to troubleshoot your Anti-spam by recomendations from an articles:
http://www.theemailadmin.com/2012/09/troubleshooting-exchanges-built-in-anti-spam-technologies-pt-6-sender-id/
https://technet.microsoft.com/en-us/library/jj937231%28v=exchg.150%29.aspx
0
 
LVL 1

Author Closing Comment

by:MichaelBalack
ID: 40661367
Specially thanks to Alessandro for his patience and efforts. I started to receive spams being quarantined day by day. These are trully spams.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out what you should include to make the best professional email signature for your organization.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question