11.07.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 16 Antispam control of the SMTP serverNote: SpamAssassin checks only messages which do not exceed the size of 128 KB since spammessages are mostly not so large and checking of large messages might overload or slow downthe server’s performance.Since individual users must check the messages in the “Learn” mode, the spam evaluationtools must be embedded in mail clients. By default, these tools include only MS Outlook withthe <strong>Kerio</strong> Outlook Connector and the <strong>Kerio</strong> WebMail interface. Users can click special buttonsin the toolbar to mark an incorrectly evaluated message as non-spam.For email clients with IMAP accounts as well as for MS Entourage (for IMAP and Exchangeaccounts), there is another method of how to teach the Bayesian filter. These users can markincorrectly classified messages by moving them to appropriate folders. If users want to marka message as spam, they can move such messages to Junk E-mail. To mark a message as notspam, they can move it to Inbox.TIP: To use this method as efficiently as possible, set users a spam rule (either when creatinguser accounts in <strong>Kerio</strong> MailServer or by defining a corresponding sieve rule for incoming mail).Any messages marked by <strong>Kerio</strong> MailServer as spam will be automatically moved to the JunkE-Mail folder. Messages that are incorrectly marked as spam can be moved to Inbox by hand.Spam messages let in by mistake can be moved to the Spam folder manually. This ensuresproper and efficient learning and improvement of the Bayesian filter.Online SURBL databaseThis part of the filter tests contents of messages (links to websites possibly included in messagebodies) against special online databases.SpamAssassin can use multiple online databases. In <strong>Kerio</strong> MailServer, it, however, uses onlythe SURBL database since the other databases are already used for other tests.16.5 Email policy records checkMany spam emails are sent from a fake sender email address. Checking “email policy” recordsis used for filtering such messages.The check verifies whether IP addresses of the remote SMTP server are authorized to sendemails to the domain specified. Spammers thus have to use their real addresses and theunsolicited emails can be recognized quickly using different blacklists.There are two similar technologies available for performing “email policy” records check in<strong>Kerio</strong> MailServer. The first one is Caller ID created by Microsoft, the other one is a projectnamed SPF (Sender Policy Framework). Both technologies provide explicit verification of messagesenders. During this verification process, the IP addresses of SMTP servers that sendmail from the specific domain are published. For each domain that supports at least one ofthe above technologies, a TXT record is stored in DNS with a list of IP addresses that sendemail from the specific domain. <strong>Kerio</strong> MailServer then compares the IP address of the SMTPserver with IP addresses contained in this DNS record. This method guarantee verification of184

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!