Solved

Exchange 2016 SPAM Filtering

Posted on 2016-09-16
5
241 Views
Last Modified: 2016-09-19
Hi Experts,

Recently I setup an Exchange 2016 server with Edge Transport server. I configured the IP Block List Providers, and reject emails from Exchange hosted domain (eg. the domain hosted in exchange is myabc.com, I use Set-SenderFilterConfig to block myabc.com. Because internal emails shall be sent to server via SMTPS port 587). all settings are done in Edge Transport Server. However, I still can receive some SPAM mails.

I checked the sender IP from the Agent Log in Edge Transport server, the IP is in the blacklist of IP Block List Provider (eg. spamcop.net). But in the Agent Log, I can see it bypass the IP Block List Providers check up.

All emails' FROM are hosted domain (eg. @myabc.com), which I expect it shall be rejected by Sender Filter Config. However, it actually doesn't work.

I am not sure how these SPAM mails bypass the filters in Edge Transport server. What else shall I do to prevent it?
0
Comment
Question by:David_zu
5 Comments
 
LVL 19

Assisted Solution

by:R--R
R--R earned 160 total points
ID: 41801182
Please check whether Connection Filtering agent is enabled on the Edge server by running Get-TransportAgent
0
 
LVL 63

Assisted Solution

by:Simon Butler (Sembee)
Simon Butler (Sembee) earned 160 total points
ID: 41801282
"What else shall I do to prevent it? "

Have you already bought your Exchange 2016 licences? If not, then dump the Edge. The built in spam filtering from Microsoft is very poor. Using Blacklists is about the best it can do. For the cost of the server licence (both Windows and Exchange) you can use a third party product or service that will do a much better job, give you better reporting and monitoring and generally be a lot more satisfactory.
0
 
LVL 93

Accepted Solution

by:
John Hurst earned 180 total points
ID: 41801441
You should get a proper spam filter. Barracuda is good, Symantec Mail Security for Exchange is good.

We outsource our email at all clients and use suppliers who include top notch spam filtering in their offering.
0
 
LVL 1

Author Comment

by:David_zu
ID: 41804832
Hi R, I am sure the connection filter is on because only a few IP have someway to "by-pass" the filter. A lot of SPAM is still blocked by connection filter. I will let everyone share the points and close this thread. Thanks for your kindly support.
0
 
LVL 93

Expert Comment

by:John Hurst
ID: 41805215
You are very welcome and I was happy to help
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
how to add IIS SMTP to handle application/Scanner relays into office 365.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question