Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Why the antispam features do not work in my Exchange server?

Posted on 2015-02-06
8
Medium Priority
?
281 Views
Last Modified: 2015-03-12
This is using MS Exchange server 2013. However, even that I already configured the antispam to work, I don't think it is working as none of the spam caught and sent to my quarantine mailbox. This is how I configure the antispam:

   a.      Open EMS, and browse to D:\Program Files\Microsoft\Exchange Server\v15\Scripts\;
double-click Install-antispamAgents.ps, to install antispam feature

b.      In EMS, type get-transportagent:

c.      In EMS, type get-transportconfig | fl internalSMTPServers; ensure the Exchange Server IP is included

d.      In EMS, type get-transportservice | fl Agentlog*; to see the settings as follows:

-      AgentLogMaxAge
-      AgentLogDirectorySize
-      AgentLogFileSize
-      AgentLogPath
-      AgentLogEnabled
e.      In EMS, type get-contentfilterconfig | fl SCL*; to see the SCLs for Delete, Reject, and Quarantine:

-      SCLDeleteThreshold (9); SCLDeleteEnabled (true)
-      SCLRejectThreshold (8); SCLRejectEnabled (false)
-      SCLQuarantineThreshold (6); SCLQuarantineEnabled (true)

f.      In EMS, type get-OrganizationConfig | SCL*; to see the settings for SCLJunkThreshold:

-      SCLJunkThreshold (5)

g.      In EMS, type get-SenderIDConfig | fl Spoofed*; to see the settings:

-      SpoofedDomainAction (StampStatus)

h.      In EMS, type get-SenderReputationConfig | fl: to see the selective settings:

-      SenderBlockingEnabled (true)
-      SrlBlockThreshold          (6)        * default, 7
-      SenderBlockingPeriod    (36)      * default, 24

i.      In EMS, type get-SetSenderFilterConfig | fl Block*; to add in and see the current blocked sender and blocked sender domain:

Set-SenderFilterConfig -BlankSenderBlockingEnabled $true –BlockedDomainsAnd Subdomains lucernepublishing.com -BlockedSenders @{Add="user1@contoso.com","user2@contoso.com"}

-      BlankSenderBlockingEnabled (true)

j.      In EMS, type get-IPBlockListProvider; to see list of RBL in descending priority:

Add-IPBlockListProvider:
-      name (bl.spamcop.net); lookupdomain (bl.sampcop.net)
-      name (bb.barracudacentral.org); lookupdomain (bb.barracudacentral.org)
-      name (ix.dnsbl.manitu.net); lookupdomain (ix.dnsbl.manitu.net)
-      name (combined.njabl.org); lookupdomain (combined.njabl.org)
-      name (zen.spamhaus.org); lookupdomain (zen.spamhaus.org)
-      name (psbl.surriel.net); lookupdomain (psbl.surriel.net)

k.      In EMS, type get-IPAllowListProvider; to see list of RBL in descending priority:

Add-IPAllowListProvider:
-      name (swl.spamhaus.org); lookupdomain (swl.spamhaus.org)
-      name (iadb.isipp.com); lookupdomain (iadb.isipp.com)
-      name (query.bondedsender.org); lookupdomain (query.bondedsender.org)


Anything I missed out?
0
Comment
Question by:MichaelBalack
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 4

Expert Comment

by:Alexander Kireev
ID: 40596584
Hello,

Did you restart "MsExchange Transport Service" service to take effect?

To verify you could check statistics of your Anti-Spam filters by Get-AntiSpamFilteringReport.ps1 script.
https://technet.microsoft.com/en-us/library/bb124795%28v=exchg.150%29.aspx
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40600260
Hi Alexander,

Yes, transport service was restarted.

Give me some times to look into the link.
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40627663
Hi Alexander,

Sorry for the delay due to the long lunar chinese new year. I'll look into it tonite.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 1

Author Comment

by:MichaelBalack
ID: 40637797
Hi Alexander,

Please see the errors...
get-antispamreport.bmp
0
 
LVL 4

Expert Comment

by:Alexander Kireev
ID: 40637833
Hello,

I think that you didn't set a command parameter.

You can run this script to draw a report for the Exchange Anti Spam Agents. The following values are accepted as command parameters:

    messagesrejected
    messagesdeleted
    connections
    messagesquarantined

Usage:

    .\Get-AntispamFilteringReport.ps1 <command> –report <path>
http://www.proexchange.be/blogs/exchange2010/archive/2011/12/18/the-exchange-2010-scripts.aspx
http://social.technet.microsoft.com/wiki/contents/articles/19122.exchange-server-how-to-diagnose-spam-problem.aspx
0
 
LVL 1

Author Comment

by:MichaelBalack
ID: 40637900
Hi Alexander,

I typed ".\get-antispamfilteringreport.ps1 messagesrejected c:\drivers\antispam_1.txt", and error occurred.

I typed ".\get-antispamsclhistogram.ps1" and the following table displayed:

name                                                                                     value
1                                                                                             1
8                                                                                             1
0                                                                                             3
7                                                                                             32
not availble: content filtering bypassed                          67

Any comment?
0
 
LVL 4

Accepted Solution

by:
Alexander Kireev earned 2000 total points
ID: 40638102
Is your ContentFilter Enabled? (Set-ContentFilterConfig -Enabled $true)
Is your SenderID Enabled? (Set-SenderIdConfig -Enabled $true)

Try to troubleshoot your Anti-spam by recomendations from an articles:
http://www.theemailadmin.com/2012/09/troubleshooting-exchanges-built-in-anti-spam-technologies-pt-6-sender-id/
https://technet.microsoft.com/en-us/library/jj937231%28v=exchg.150%29.aspx
0
 
LVL 1

Author Closing Comment

by:MichaelBalack
ID: 40661367
Specially thanks to Alessandro for his patience and efforts. I started to receive spams being quarantined day by day. These are trully spams.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
The main intent of this article is to make you aware of ‘Exchange fail to mount’ error, its effects, causes, and solution.
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question