GRAYWALL. Introduction. Installing Graywall. Graylist Mercury/32 daemon Version 1.0.0



Similar documents
Migration Manual (For Outlook Express 6)

Policy Patrol 7 Upgrade Guide

Migration Manual (For Outlook 2010)

Core Protection Suite

Feature Comparison Guide

How to use ArGoSoft Mail Server.NET Freeware

Transferring Your Internet Services

MailFoundry User Manual. Page 1 of 86. Revision: MF Copyright 2007, Solinus Inc. All Rights Reserved. Page 1 of 86

Enhanced Spam Defence

A D M I N I S T R A T O R V 1. 0

Resolving problems with SMTP Security Server and CVP operating in Check Point NG

SpamPanel Reseller Level Manual 1 Last update: September 26, 2014 SpamPanel

SMTP Settings. Magento Extension User Guide. Official extension page: SMTP Settings. User Guide: SMTP Settings

ESET Mail Security 4. User Guide. for Microsoft Exchange Server. Microsoft Windows 2000 / 2003 / 2008

POP3 Connector for Exchange - Configuration

Funkwerk UTM Release Notes (english)

Securepoint Security Systems

FortiMail Filtering Course 221-v2.0. Course Overview. Course Objectives

AntiSpam QuickStart Guide

FortiMail Filtering Course 221-v2.2 Course Overview

Anti Spam Best Practices

ORF ENTERPRISE EDITION 1. Getting the Most Out of ORF

Mail Sentinel. Feature Guide. Mail Sentinel Anti-Spam & Mail Sentinel Anti-Virus

Collateral Damage. Consequences of Spam and Virus Filtering for the System. Peter Eisentraut 22C3. credativ GmbH.

Installing Policy Patrol with Lotus Domino

Guide to Pro Spam Remove

Installing GFI FAXmaker

Web. Anti- Spam. Disk. Mail DNS. Server. Backup

Security perimeter white paper. Configuring a security perimeter around JEP(S) with IIS SMTP

Visendo Suite a reliable solution for SMBs

8.6. NET SatisFAXtion Gateway Installation Guide. For NET SatisFAXtion 8.6. Contents

User Guide Online Backup

XGENPLUS SECURITY FEATURES...

Avira Managed Security AMES FAQ.

Serial Deployment Quick Start Guide

Barracuda Spam Firewall User s Guide

Hosted CanIt. Roaring Penguin Software Inc. 26 April 2011

V2.4. JEP(S) Administrator manual. Spam filter for Exchange and IIS SMTP

PineApp Daily Traffic Report

Mail Server Scenarios and Configurations

Government of Canada Managed Security Service (GCMSS) Annex A-5: Statement of Work - Antispam

OR Filter 3.2 Manual. Draft. Copyright 2003, Martijn Jongen. All Rights Reserved Version : Ref. nr. : MhJ/ By : M.

SME- Mail to SMS & MMS Gateway with NowSMS Quick Start Guide

Objective This howto demonstrates and explains the different mechanisms for fending off unwanted spam .

SPAMfighter SMTP Anti Spam Server

Upgrading a computer to Windows 10 with PetLinx

Password Management Help

Introduction of the S25R anti-spam system

Guardian Digital Secure Mail Suite Quick Start Guide

MailGuard and Microsoft Exchange 2007

1 Functionalities of iq.suite Update Manager Installation New Installation Update Installation Configuration...

Installing Policy Patrol in a cluster

CHANGES IN GECS 3.50 PACKAGES

How to set up the Alert to send the result of the backup by .

Frequently Asked Questions for New Electric Mail Administrators 1 Domain Setup/Administration

MDaemon configuration recommendations for dealing with spam related issues

You can attach accounts to this domain name (eg. or which also increases your corporate branding.

ETH Zürich - Mail Filtering Service

User Guide. ThreatTrack Security Product Manual

Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice.

Fax and . Fax & Monitor Application

Microsoft Exchange 2003

Fus - Exchange ControlPanel Admin Guide Feb V1.0. Exchange ControlPanel Administration Guide

Avira Managed Security (AMES) User Guide

ExchangeDefender. Understanding the tool that can save and secure your business

Core Filtering Admin Guide

BACKSCATTER PROTECTION AGENT Version 1.1 documentation

Security. Help Documentation

Comodo KoruMail Software Version 4.0

EFFECTIVE SPAM FILTERING WITH MDAEMON

Filtering Admin Guide. Guide to Administrative Functions of Spam and Virus Filtering Service

Configuring MDaemon for Centralized Spam Blocking and Filtering

Sophos for Microsoft SharePoint startup guide

Symantec Mail Security for Domino

INLINE INGUARD GUARDIAN

MailFoundry Users Manual. MailFoundry User Manual Revision: MF Copyright 2005, Solinus Inc. All Rights Reserved

8.7. NET SatisFAXtion Gateway Installation Guide. For NET SatisFAXtion 8.7. Contents

Release Notes. for Kerio Connect 8.0.0

PureMessage for Microsoft Exchange Help. Product version: 4.0

Installation Guide For Choic Enterprise Edition

Quick Start Policy Patrol Mail Security 9

MDaemon Vs. Microsoft Exchange Server 2013 Standard

SpamPanel Level Manual Version 1 Last update: March 21, 2014 SpamPanel

Celframe - Easy Linux - Lesson 8 - Server

Dell KACE K1000 Management Appliance. Service Desk Administrator Guide. Release 5.3. Revision Date: May 13, 2011

Configuring Security for SMTP Traffic

1 Introduction About this manual Terms and conventions used in this manual 12

Setting up Microsoft Office 365

K12 Spam Management Blocked s from parents

CPanel User Guide DOCUMENTATION VERSION: 1.2

IceWarp Unified Communications. AntiVirus Reference. Version 10.4

eprism Security Appliance 6.0 Release Notes What's New in 6.0

Quick Start Policy Patrol Mail Security 10

NovaBACKUP Storage Server User Manual NovaStor / April 2013

Configuration of a Load-Balanced and Fail-Over Merak Cluster using Windows Server 2003 Network Load Balancing

Setting up Microsoft Office 365

How to deploy Arkeia Network Backup v10 on Windows Server 2008 and later with a domain

Transcription:

GRAYWALL Graylist Mercury/32 daemon Version 1.0.0 Introduction Graywall is a program that adds a graylist (or greylist) feature to the Mercury/32 SMTP server. It uses the Mercury/32 API facility that has been introduced in version 4.51. You must have at least this version of Mercury/32 to run Graywall! Information about graylisting in general can be found at: http://en.wikipedia.org/wiki/greylist. We recommend that you read this first. Note that graylisting techniques can only be used when e-mail is delivered by SMTP; hence Graywall can only be used in conjunction with Mercury s SMTP server, MercuryS. (However, Graywall s companion product, Spamhalter, can be used for both SMTP and POP3 e-mail delivery, so, with a Mercury system which collects e-mail using SMTP, best spam protection will be achieved by using both products.) The basic features of Graywall are as follows. - It accepts some incoming SMTP sessions and rejects others according to certain conditions. - Authorized connections, or connections from specified IP addresses, are not affected by Graywall. - Graywall is compatible with the sending of SMTP mail by server farms. - Graywall is compatible with the reverse delivery test used by some systems as an anti-spam test (for example, Sourceforge.net). - Servers which successfully pass mail through are whitelisted by Graywall for the specific mail domain, and subsequent messages are not delayed by Graywall. What defeats Graywall? - Backup mail servers. If an e-mail sent directly to your Mercury system is initially rejected by Graywall and is consequently re-sent by one of your ISP s backup servers/relays, then all these backup servers must also be protected by graylisting. - Forwarding e-mail accounts. If your incoming external e-mail is forwarded on to you by another server (rather than being sent to you directly as a result of MX records for your domain), the forwarding server will always try to re-send any message including spam. The retrying of forwarded mail will defeat Graywall. Installing Graywall Installing Graywall is simple. In fact, installing (or upgrading to) Mercury 4.51 will optionally install Graywall for you. Otherwise you should proceed as follows (Stage 4 is also needed if Mercury has installed Graywall for you).

1) Stop your Mercury/32 system. 2) Run the Graywall installer. 3) Start Mercury/32. 4) Use Configuration Graywall to configure the system. Uninstalling Graywall You can uninstall Graywall using Control Panel Add/Remove Programs in the same way that you uninstall any other application. Graylisting in depth Please read http://en.wikipedia.org/wiki/greylist before studying this section. If an incoming SMTP connection does not come from a defined IP address known to Graywall, or if the sender is not in the Graywall whitelist, or the sender s domain is unknown, then Graywall inspects a triplet consisting of the sender s reduced IP address, the sender s e- mail address and the receiver s e-mail address. From this information is computed a hash code. Graywall then searches its internal database for this hash code. Messages are allowed through if the previous delivery attempt occurred within the time interval defined in Graywall s configuration menus. Graywall then opens up delivery for this group of servers and for the sender s mail domain. Subsequent delivery attempts from this server or a similar one with the same sender s mail domain are allowed. If the previous delivery attempt is not found in Graywall s database, or this delivery attempt is not with a defined timescale, then the SMTP session is refused, and a temporary server error is sent back in an e-mail to the originator. Because this is not hard error, all correctly written mail servers should try to deliver the message again later. However most of spam tools or viruses will not try to deliver it again. This is the basis of graylisting. Information about allowed servers and mail domains expires after a defined period of inactivity. Statistics Graywall stores usage statistics in a file called graystat.txt file within the Graywall data directory. The statistics file contains the following information. From Statistics are counted from this point. All count of all detected SMTP sessions. Whitelisted This number of SMTP sessions have been opened by previous successful graylisting. WhitePercent The Whitelisted count as a percentage of the All count. New A count of new (ie not seen before) delivery attempts.

OK A count of SMTP sessions that have been allowed by Graywall because they have retried delivery within the specified time limits. OKPercent The OK count as a percentage of the New count. Here you can see the efficiency of graylisting! Here is an example of a graystat.txt statistics file [stat] from=29.6.2007 15:04:34 all=167485 ok=8809 new=90996 whitelisted=44503 whitepercent=26,57% okpercent=9,68%

Graywall Configuration screens: The [section] item are the items in the graywall.ini file. General Switch Enables the Graywall daemon [Graywall] Enabled

Data directory Select the directory in which Graywall s database and statistics file are stored. By default this is the Graywall subdirectory of your existing Mercury/32 directory. The directory name must end with a trailing backslash! [Graywall] GrayDataDir Graylist timeouts Minimum retry time in minutes for unlocking a delivery Delivery is unlocked only if the next delivery attempt is detected at least this time interval after first delivery attempt. [Graywall] unlock Unlock request expiration time in minutes Each delivery request is registered in Graywall s database. A lot of these requests are not retried later. Registered requests are deleted from the database after this time value. [Graywall] expire Successful unlock expiration time in minutes Opened servers (having a locked specified mail domain) are removed from the database after this time of inactivity and must be graylisted again in future. [Graywall] whiteexpire

Logfile File for Graywall logging. You can use the same name special characters in the name as can be used for log file names in Mercury. [Graywall] logfile If Debug mode is checked, Graywall writes debugging information to your logfile. [Clamwall] Debug SMTP When Graywall rejects an SMTP session, this description of the SMTP error is used in the e- mail sent back to the originator. [Graywall] SmtpText

Local SMTP connections recognition SMTP connections from local IP addresses are not graylisted at all. You can specify here your Local IP addresses as IP networks. For example: 10.0.0.0/8, 192.168.0.0/16, 172.16.1.1/32 You can also use this feature for whitelisting specific servers on the Internet. [Graywall] LocalIP Exclude from processing You can exclude senders addresses from graylisting. But be careful, because spammers often forge sender s addresses! You can use wildcards here. Excluded addresses are stored in gwexlist.txt file within your Graywall data directory.