Home > Ask the Security Experts > Application Security Questions & Answers > Enterprise-level spam filters
Ask The Security Expert: Questions & Answers
EMAIL THIS

Enterprise-level spam filters

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 16 January 2006
Our company uses IMAIL from Ipswitch. Its spam filter works reasonably well, but our executives complain that hotel and airline reservations get caught in the spam filter. Although, we whitelist the airlines and hotels, they use mail services to send reservation confirmations and price updates, which seem to end up on the public blacklists. Is there a corporate spam filter that allows individual users to add specific e-mail addresses to block or whitelist as needed? This would reduce the amount of daily IT effort it takes to adjust our spam filters.

>
EXPERT RESPONSE
Although they may exist, I'm not aware of any enterprise-level spam filters that allow individual users to directly add e-mail addresses to black or whitelists. The reasons for this are:
  1. System administrators would quickly lose control of the e-mail server and the ability to enforce the corporate e-mail policy.
  2. One person's e-mail may be another person's spam.

I suggest using a spam filter that not only blocks e-mails, but also quarantines them. This notifies users when they receive a suspicious e-mail, and allows them to preview the message and decide if it is a message they want. Tumbleweeds offers a hardware spam filter, called MailGate Appliance, that also quarantines. The E-mail Protection Agency also offers a managed spam service. It automatically quarantines e-mails classified as spam and keeps them on the system for 28 days. During this period, administrators can log in to the online portal where the spam e-mails are stored, preview and release them if needed. While it does not completely eliminate this task from the network administrator's workload, the quarantine approach is less onerous than trying to continually adjust your spam filters, and it avoids the risk of exposing the network to malicious code sent from untrusted sources.


More Information

  • Read this tip to learn how to direct inbound SMTP traffic to an ISA Server first to nab malicious messages and reduce the overall volume of SMTP mail that your server must process.
  • Find tools and tactics to help your organization mitigate the risk of spam attacks, as recommended by your peers.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    Protecting exposed servers from Google hacks (and Google 'dorks')
    Which automated quality assurance tools can be used to test software?
    Has proof-of-concept mobile device malware translated into any meaningful attacks?
    How to test the security of personal details submitted to a website
    Is security improved when the number of Internet gateways is reduced?
    Are Internet cafe users' email credentials at risk?
    Which operating system can best secure an FTP site?
    Will firewall technology have to adapt to applications that use port 80?
    How secure is a mobile phone platform that has an open source framework?
    What ports should be opened and closed when IPsec filters are implemented?

    Spam and Antispam
    Spam Blockers Losing Ground on Sophisticated Attackers
    Companies still monitoring email manually, survey finds
    Google Docs used in latest spam run
    New phishing, Zeus Trojan technique spreads crimeware
    Kraken botnet balloons to dangerous levels
    New Storm attack exploits April Fool's Day
    Gmail CAPTCHA cracking leads to spam surge
    Clinton, Obama campaigns used in spam blasts
    Google-Postini email services deliver security market message
    Product review: Webroot's Webroot Antispyware Corporate Edition with AntiVirus
    Spam and Antispam Research

    Email Security Appliances
    Small email security vendors thrive in saturated market
    Tumbleweed merger seen as a negative for email security customers
    Companies still monitoring email manually, survey finds
    Trend Micro aims Message Archiver at midmarket
    Are challenge-response technologies the best way to stop spam?
    Most antispam technologies get failing grade
    Security vendor Postini acquired by Google
    How vulnerable are document scanners and other 'scan to email' appliances?
    ClamAV clamps down on e-mail security
    Companies plug FTP holes with secure FTP servers

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    CAPTCHA  (SearchSecurity.com)
    challenge-response system  (SearchSecurity.com)
    content filtering  (SearchSecurity.com)
    DomainKeys  (SearchSecurity.com)
    Joe job  (SearchSecurity.com)
    munging  (SearchSecurity.com)
    Register of Known Spam Operations  (SearchSecurity.com)
    Sender Policy Framework  (SearchSecurity.com)
    spam cocktail  (SearchSecurity.com)
    spam filter  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts