Home > Ask the Security Experts > Application Security Questions & Answers > Enterprise-level spam filters
Ask The Security Expert: Questions & Answers
EMAIL THIS

Enterprise-level spam filters

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 16 January 2006
Our company uses IMAIL from Ipswitch. Its spam filter works reasonably well, but our executives complain that hotel and airline reservations get caught in the spam filter. Although, we whitelist the airlines and hotels, they use mail services to send reservation confirmations and price updates, which seem to end up on the public blacklists. Is there a corporate spam filter that allows individual users to add specific e-mail addresses to block or whitelist as needed? This would reduce the amount of daily IT effort it takes to adjust our spam filters.


BROWSE BY TAG
Application Security,   Application and Platform Security,   Email Protection,   Email Security Guidelines, Encryption and Appliances,   Email and Messaging Threats (spam, phishing, instant messaging),   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Application Security
Are Web application penetration tests still important?
What does 'invoked by uid 78' mean?
How secure are iPhone App Store mobile applications?
What security software should be installed on Internet café computers?
Are message stubs a secure part of email retention policies?
How does a Web server model differ from an application server model?
Can Google Earth and other mash-up applications threaten enterprise security?
Do European laws prevent a U.S. company from blocking spam?
Can one antivirus program be used to get rid of spyware?
How to prevent cross-site scripting (XSS) session hijacking

Email Security Guidelines, Encryption and Appliances
What does 'invoked by uid 78' mean?
How to configure firewall ports for webmail system implementation
Fierce competition prompted new Cisco email security options
Cisco brings email security appliances closer to SaaS
Cisco offers more email security choices, but lacks vision
Information security book excerpts and reviews
Are message stubs a secure part of email retention policies?
Strategies for email archiving and meeting compliance regulations
Product Review: Astaro Mail Gateway 4000
What are the security risks of opening port 110 and port 25?

Email and Messaging Threats (spam, phishing, instant messaging)
How to prevent brute force webmail attacks
Unified communications: Securing a converged infrastructure
Chained Exploits: How to prevent phishing attacks from corporate spies
3FN.net ISP shutdown interrupts spam campaigns
Swine flu outbreak results in spam pandemic
What does 'invoked by uid 78' mean?
Economy fuels malware, spam
Internet Explorer 8 includes a bevy of security features
Adobe JBIG2 exploits being spammed, IBM warns
Fierce competition prompted new Cisco email security options
Email and Messaging Threats (spam, phishing, instant messaging) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
asymmetric cryptography  (SearchSecurity.com)
challenge-response system  (SearchSecurity.com)
cryptographic checksum  (SearchSecurity.com)
data encryption/decryption IC  (SearchSecurity.com)
elliptical curve cryptography  (SearchSecurity.com)
Escrowed Encryption Standard  (SearchSecurity.com)
MPPE  (SearchSecurity.com)
Quiz: Cryptography  (SearchSecurity.com)
session key  (SearchSecurity.com)
Twofish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Although they may exist, I'm not aware of any enterprise-level spam filters that allow individual users to directly add e-mail addresses to black or whitelists. The reasons for this are:

  1. System administrators would quickly lose control of the e-mail server and the ability to enforce the corporate e-mail policy.
  2. One person's e-mail may be another person's spam.

I suggest using a spam filter that not only blocks e-mails, but also quarantines them. This notifies users when they receive a suspicious e-mail, and allows them to preview the message and decide if it is a message they want. Tumbleweeds offers a hardware spam filter, called MailGate Appliance, that also quarantines. The E-mail Protection Agency also offers a managed spam service. It automatically quarantines e-mails classified as spam and keeps them on the system for 28 days. During this period, administrators can log in to the online portal where the spam e-mails are stored, preview and release them if needed. While it does not completely eliminate this task from the network administrator's workload, the quarantine approach is less onerous than trying to continually adjust your spam filters, and it avoids the risk of exposing the network to malicious code sent from untrusted sources.


More Information

  • Read this tip to learn how to direct inbound SMTP traffic to an ISA Server first to nab malicious messages and reduce the overall volume of SMTP mail that your server must process.
  • Find tools and tactics to help your organization mitigate the risk of spam attacks, as recommended by your peers.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts