Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
11.07.2015 Views

Chapter 16 Antispam control of the SMTP serverKerio MailServer uses two SMTP connection errors to recognize spam servers. These errors occurwhile establishing SMTP connection. The server that initializes the SMTP communicationshould according to the corresponding RFC wait for the reply for at least 5 minutes. Applicationsthat send spam automatically do not wait for that long since they need to send emailmessages as fast as possible to send as many spam messages as they can. It would hold theseapplications too much to keep waiting the whole period. Therefore, spammer servers behavein one of the following two predictable ways if Kerio MailServer does not answer to the SMTPgreeting for a certain period (i.e. delay is set for answers). In one case, the spammer servergives up the connection to Kerio MailServer and tries elsewhere. In the other case, it startsto send email to Kerio MailServer immediately, without receiving the SMTP greeting (in sucha case, Kerio MailServer interrupts the connection immediately).Benefits of the SMTP delay are as follows:1. Reception of spam by Kerio MailServer is eliminated by 60 — 70 per cent. This alsodecreases the load on the server since spam testing is very demanding.2. The method has no so called false positives as there is no influence to the email which isdelivered legitimately. SettingsSMTP delay settingsYou can set either the SMTP greeting delay in the Spam repellent tab of Kerio MailServer (Configuration→ Content filtering → Spam filter):Figure 16.10Spam repellentDelay SMTP greeting byUse this option to set the SMTP delay. The optimal delay value is between 25 and 30seconds. Shorter delay might not be enough (the spam sending applications use 10-20sec), longer time would impede the communication.188

16.7 Recommended configuration of antispam testsDo not apply delay for connections from...Spam repellent settings apply to all incoming SMTP communication events, i.e. also tomessages from local network, backup servers, etc. It is therefore recommended to add alltrustful IP addresses and networks to this IP address group, so that the communicationis not blocked, if the messages are apparently non-spam.Report the spam attack to security logCheck this option to record all recognized spam attacks to the Security log (for moreinformation, see chapter 22.4).If many emails go through Kerio MailServer, there are usually also many spam attackattempts, which can cause security log overflow. In such case, disable this setting.Note: The settings in this tab apply only to the unsecured SMTP communication. The spamdistributing programs do not use the secured SMTP protocol for communication.16.7 Recommended configuration of antispam testsThis section is helpful for anyone who is not sure about proper configuration of antispamfilters. The example describes optimal settings of scores for individual types of antispamtests. Notice that almost never the message blocking is not preferred to increasing of spamscore:Spam Rating tabThe essential setting is configuration of the Spam Rating tab (for details, see section 16.1). Itis recommended to leave most of the settings as predefined by default:1. Make sure that the Enable Spam Filter Rating option is enabled. If the option is inactive,enable it.This option makes the filter consider and apply results of individual evaluations (spamscores).2. Make sure that the Enable rating of messages sent from trustworthy relay agents defined inSMTP relay options option is inactive (unless you wish to check even messages sent fromtrustworthy addresses).3. Follow these instructions to set resolution of the spam filter scale:• Tag score — set the value to 5 points.• Block score — set this value to 9.9 points. This will ensure that only “hundred-percent”spam messages are discarded by the server since users are not even notified that suchmessages would have been blocked (unless at least one of the Send bounce message tothe sender or Forward the message to quarantine address options are enabled).Note: If you do not wish to block any messages no matter what the score is, set thevalue to 10.0 points. This disables blocking of messages and keeps active only thefeature of marking as spam.189

Chapter 16 Antispam control of the SMTP server<strong>Kerio</strong> MailServer uses two SMTP connection errors to recognize spam servers. These errors occurwhile establishing SMTP connection. The server that initializes the SMTP communicationshould according to the corresponding RFC wait for the reply for at least 5 minutes. Applicationsthat send spam automatically do not wait for that long since they need to send emailmessages as fast as possible to send as many spam messages as they can. It would hold theseapplications too much to keep waiting the whole period. Therefore, spammer servers behavein one of the following two predictable ways if <strong>Kerio</strong> MailServer does not answer to the SMTPgreeting for a certain period (i.e. delay is set for answers). In one case, the spammer servergives up the connection to <strong>Kerio</strong> MailServer and tries elsewhere. In the other case, it startsto send email to <strong>Kerio</strong> MailServer immediately, without receiving the SMTP greeting (in sucha case, <strong>Kerio</strong> MailServer interrupts the connection immediately).Benefits of the SMTP delay are as follows:1. Reception of spam by <strong>Kerio</strong> MailServer is eliminated by 60 — 70 per cent. This alsodecreases the load on the server since spam testing is very demanding.2. The method has no so called false positives as there is no influence to the email which isdelivered legitimately. SettingsSMTP delay settingsYou can set either the SMTP greeting delay in the Spam repellent tab of <strong>Kerio</strong> MailServer (Configuration→ Content filtering → Spam filter):Figure 16.10Spam repellentDelay SMTP greeting byUse this option to set the SMTP delay. The optimal delay value is between 25 and 30seconds. Shorter delay might not be enough (the spam sending applications use 10-20sec), longer time would impede the communication.188

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!