Solved

Exchange 2016 SPAM Filtering

Posted on 2016-09-16
5
189 Views
Last Modified: 2016-09-19
Hi Experts,

Recently I setup an Exchange 2016 server with Edge Transport server. I configured the IP Block List Providers, and reject emails from Exchange hosted domain (eg. the domain hosted in exchange is myabc.com, I use Set-SenderFilterConfig to block myabc.com. Because internal emails shall be sent to server via SMTPS port 587). all settings are done in Edge Transport Server. However, I still can receive some SPAM mails.

I checked the sender IP from the Agent Log in Edge Transport server, the IP is in the blacklist of IP Block List Provider (eg. spamcop.net). But in the Agent Log, I can see it bypass the IP Block List Providers check up.

All emails' FROM are hosted domain (eg. @myabc.com), which I expect it shall be rejected by Sender Filter Config. However, it actually doesn't work.

I am not sure how these SPAM mails bypass the filters in Edge Transport server. What else shall I do to prevent it?
0
Comment
Question by:David_zu
5 Comments
 
LVL 19

Assisted Solution

by:R--R
R--R earned 160 total points
ID: 41801182
Please check whether Connection Filtering agent is enabled on the Edge server by running Get-TransportAgent
0
 
LVL 63

Assisted Solution

by:Simon Butler (Sembee)
Simon Butler (Sembee) earned 160 total points
ID: 41801282
"What else shall I do to prevent it? "

Have you already bought your Exchange 2016 licences? If not, then dump the Edge. The built in spam filtering from Microsoft is very poor. Using Blacklists is about the best it can do. For the cost of the server licence (both Windows and Exchange) you can use a third party product or service that will do a much better job, give you better reporting and monitoring and generally be a lot more satisfactory.
0
 
LVL 92

Accepted Solution

by:
John Hurst earned 180 total points
ID: 41801441
You should get a proper spam filter. Barracuda is good, Symantec Mail Security for Exchange is good.

We outsource our email at all clients and use suppliers who include top notch spam filtering in their offering.
0
 
LVL 1

Author Comment

by:David_zu
ID: 41804832
Hi R, I am sure the connection filter is on because only a few IP have someway to "by-pass" the filter. A lot of SPAM is still blocked by connection filter. I will let everyone share the points and close this thread. Thanks for your kindly support.
0
 
LVL 92

Expert Comment

by:John Hurst
ID: 41805215
You are very welcome and I was happy to help
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now