Skip to main content

Filtering out spoofed emails in Outlook

I recently had a rash of email come in through my SBS 2008 (Exchange 2007) server purporting to be from eBay, Amazon etc.

They were, of course, phishing emails but they were “close enough” to the real thing to get low SCL (Spam Confidence Level) and PCL (phishing confidence level) and hence were not rejected by the anti-spam features in Exchange 2007.

They were however marked as “fail” or “softfail” by the SenderID checks (Sender Policy Framework aka SPF defines which hosts are allowed to send mail “on behalf of” a given email domain). Since the spammers weren’t on the allowed list, the email was failed the SenderID check.

So, how do we ensure that emails that fail the SenderID check don’t get delivered to the user’s inbox?

Well, the more dramatic solution is to just reject or delete any emails that fail the test. You can read how to do that here - http://technet.microsoft.com/en-us/library/bb125259.aspx 

That was a bit drastic at this stage so I found another solution here (http://serverfault.com/questions/37232/exchange-2007-move-messages-with-senderid-fail-to-junk-mail-folder) which worked a treat.

The suggested solution is easy to implement – create an inbox rule to move messages that contain “fail” or “softfail” messages to the JunkMail folder.

The text strings I used were:

X-MS-Exchange-Organization-SenderIdResult: Fail or
X-MS-Exchange-Organization-SenderIdResult: SoftFail

image

And since then, nary a hint of spoofed email in my inbox!

Comments

Popular posts from this blog

Alexa has performance rankings too!

I must confess that this one had slipped past me… I wasn’t aware that Alexa was now offering performance rankings as well! Alexa now shows an “average load time” as well as a “comparitive ranking” (i.e. 51% of sites are slower). Interesting data for your next website analysis! It’s worth noting that the quoted “1.404 seconds” is about the same as the “repeat view” measurement webpagetest.org (testing from the UK node shows that www.johnlewis.com takes about 7.2 seconds to load with an empty cache, and 1.6 seconds with a primed cache, median values over 5 runs). Presumably this is an average across all Alexa toolbar users, on all johnlewis.com pages (large and small) with empty and primed caches.

Load Testing Case Study

Since we are talking about presentations here is another one I did for the Load Testing Expo in 2009. It’s a case study of how we did the performance testing for an internet-facing content/community/jobs site. Test Expo 2009 Site Confidence & Seriti Consulting Load Test Case Study View more presentations from Stephen Thair .

Real-time Web Analytics just took a step forward with Pion v4

Awesome news from Atomic Lab’s that Pion 4.0 has been released! The new Dashboard functionality looks amazing – real-time web analytics likes page views, visitor sessions etc as well as performance analytics like load time and server reply time – along with the usual Pion goodness like tag-free analytics and customer journey visualisation with the Replay feature. Can’t wait to implement this on some customer sites!