Incoming filtering
- Add accounts to allow list in Spam Experts
- Are viruses blocked too by the spam-filter?
- How does incoming filtering work
- How to exclude a certain email address from being filtered?
- How to setup an incoming spam-filter
- Login to Spamexperts panel directly
- SpamExperts: Which MX records should I use?
- Testing your mailserver when using SpamExperts
- What are domain aliases in SpamExperts?
- What to do when I receive spam?
- Which IP addresses should be whitelisted on a mail server?
- 🇪🇸 ¿Cómo configurar el filtro de entrada de spam?
Add accounts to allow list in Spam Experts
Question
How to add accounts to allow list in Spam Experts?
Answer
There are two allow lists - Sender allow list and Recipient allow list.
Note: This article assumes that the user already knows the ways to access their Spam Experts control panel, in case you have doubts or do not know how to see the aforementioned menu, we recommend you visit this article where we detail how to configure your service by Spam Experts.
What is Sender allow list, and how to manage it?
Incoming mail received from senders listed in the Allow list will always be allowed, regardless of the message classification.
Go to Incoming - Protection Settings > Sender allow list
The above window will be displayed, you just need to click on Add sender to allow list option.
In "local-part" add the name of the email to be added and in "address" the domain name.
For example. If you need to add an email called victor@gmail.com, then the configuration would be as follows.
Local-part
Victor
Address
gmail.com
Note: It is important to check the option “Apply to both”
Once this is done, press the "Save" button.
What is Recipient allow list, and how to manage it?
Incoming mail sent to recipients listed in the Recipient Allow list will always be allowed, regardless of the message classification. This is generally not recommended for normal mailboxes.
Go to Incoming - Protection Settings > Recipient Allow list
Note: This page lists read-only rules, which are set by a higher level admin.
Are viruses blocked too by the spam-filter?
Question
Are viruses been blocked by the Spam-filter?
Answer
Viruses, malware and other online threats are often been spread via email. Therefore it is essential that emails are scanned for viruses before they reach users' mailboxes. Spamexperts actively blocks both spam and malicious attachments such as viruses, malware, ransomware, spyware and so on.
The additional anti-virus measures include a sequential combination of different technologies to protect clients against malware. This includes the open-source ClamAV antivirus framework, which is enhanced with additional data-sets specialized in detecting zero-day email viruses provided by several external partners.
For additional explanation of the virus protection by Spamexperts you can visit the follow Link
How does incoming filtering work
Question
What is incoming email filtering and how does it works?
Answer
Email filtering separates legitimate email from unsolicited bulk email with the help of advanced
algorithms and spam pattern detection methods.
It works by Re-routing the email through filters.
Spamexperts incoming spam filter is a gateway solution.
Activation is done via a simple DNS adjustment. Once the MX-records are changed, all inbound email goes to the Spamexperts system first, where it is filtered and then relayed to the unchanged destination mail servers of your clients.
Deployment
The actual message filtering is done in the highly redundant Spamexperts Hosted Cloud.
This solution is fully managed, maintained, and 24/7/365 monitored by Spamexperts.
Filtering work flow:
The filtering of e-mails is done on two levels.
- At the SMTP level, the validity of the sending mail server is checked. The e-mail data stream is collected until the RCPT TO command. This way, the e-mail can be logged, but the usage of resources is minimized.
- If there is no reason to mark the sender as 'suspected', the e-mail is sent to the next validation step immediately.
- If the sender is known as a malicious source, the e-mail is blocked immediately; the sender receives a 5xx code with explanation. This is a permanent reject.
- If there is no reason to entitle the sender as malicious, but the sender is trusted neither, a grey-listing algorithm will temporarily block the e-mail (temporarily rejected).
- An RFC-compliant mail server will retry; at the first retry after 10 minutes the e-mail will be accepted by the Spamexperts filters, and the e-mail will be forwarded to the next validation step.
- At the SMTP level, the validity of the sending mail server is checked. The e-mail data stream is collected until the RCPT TO command. This way, the e-mail can be logged, but the usage of resources is minimized.
- At the DATA level, the complete e-mail is loaded and verified. Advanced statistical algorithms are used to qualify the e-mail. Because multiple of those algorithms are used, the risk of an incorrect reject (false positive) is almost zero - the logs of Spamexperts show that this only happens in 0,001% of all cases.
E-mail that is blocked on the DATA level is put into the quarantine mailbox and can be released from there. E-mail that is blocked on the SMTP level cannot be recovered: the e-mail was simply not received completely.
How to exclude a certain email address from being filtered?
Question
How to prevent an email from being filtered?
Answer
By configuring allow or block list filtering rules for outgoing or incoming filters the emails in the configuration will be accepted or sent without the need for the filter to check it.
This is very useful when there is an abuse e-mail address that for example should receive all e-mails.
In this case, add abuse@yourcompany.com to the recipient allow list.
The steps for the configuration can be found on the following URLS of Spamexperts knowledge base for Allow list/Block list and the incoming and outgoing filter rules.
Allow list/Block list
Allow list/Block list filtering rules:
- Add incoming allow list filtering rule
- Add incoming block list filtering rule
- Add outgoing block list filtering rule
How to setup an incoming spam-filter
Question:
How to order and configure an incoming spam filter?
Answer:
In order to set up an incoming filter on domains, first one needs to have a domain.
It does not matter if the domain is with Openprovider or with another registrar.
Step-by-step guide:
1) Log into the Openprovider control panel and navigate to Spam filtering (SpamExperts) > Order new filter.
2) On the next screen:
- Enter the domain name
- Select the desired filter (Incoming filter / Outgoing filter / E-mail archiving)
- Enter the mail-server host address
3) Click Save
Now the incoming filter for the domain has been created but, not yet configured.
4) Add MX records to the DNS zone of the domain.
If the domain is with Openprovider and is also using Openprovider's NS, the following MX records will be automatically added by our system to the DNS zone.
Otherwise, you will have to add them manually.
- mx.spamexperts.com (with priority 100)
- fallbackmx.spamexperts.eu (with priority 200)
- lastmx.spamexperts.net (with priority 300)
Be sure to never add other MX record(s) together with the Spamexperts records: this will result in only partial filtering of the e-mail, and not remove spam completely!
In case a DNS zone isn't created yet for the domain and if you would like to use Openprovider DNS service, please refer to the article.
In case the DNS zone is with Openprovider, navigate to DNS management > DNS zones overview and click on the domain in the list.
Once the DNS zone details page is opened, click on the Details tab and Enable the SpamExperts checkbox. Once the page is refreshed the MX records will appear automatically added into the zone.
5) To configure the mail server to accept the spam-filter connections and treat them as 'trusted'.
This can be done by whitelisting the domain-name delivery.antispamcloud.com in the mail server.
6) In some cases SpamExperts server also needs to be added to the SPF record of the domain DNS zone.
In order to do this, please add the following SPF record with the content below:
"v=spf1 include:spf.antispamcloud.com -all"
Or add include:spf.antispamcloud.com -all to the existing SPF record.
For more information about the incoming spam filter can be found in the knowledge base of SpamExperts.
Login to Spamexperts panel directly
Question
Is it possible to log in to Spamexperts control panel directly?
Answer
When creating a spam filter with Openprovider the credentials for direct access to the Spamexperts control panel can be found in the Openprovider panel.
The following links can be used to log in directly to the Spamexperts panel.
Save the link in the browser so that it can be found without accessing first the Openprovider panel. Be sure to enter the link as HTTPS, otherwise, the security may give an error about cookies not being enabled.
Note: One can create login credentials also on user level, allowing the end customer to log in to the Spamexperts control panel directly.
To create login credentials for a mailbox user, first one need to log into Spamsxperts control panel and scroll down to the bottom of the menu. Search for Users & permissions > Manage email users on menu item and click on it, (see example below). Then one will be able to add email user for a domain.
Such users will have limited access to Spamexperts control panel allowing them to view their own logs, manage emails moved to quarantine and change some minor settings.
NOTE: Due to security setting from Spamexperts, always use HTTPS to log in. If you try to login to Spamexperts directly via HTTP, you will get a message that the browser doesn't support cookies.
Also, users only have domain level access and it comes with certain restrictions compared to admin level access - which is managed by Openprovider. Some options like editing Email Scout Report (ESR) templates, enabling domain-level reporting etc... won't be available for users.
SpamExperts: Which MX records should I use?
Question:
Which MX records should I use for SpamExperts incoming filtering?
Answer:
To use the SpamExperts incoming spam filtering service, you need to update MX records for your domain in your DNS zone to the following:
| Type | Priority |
TTL (recommended) |
Value |
| MX | 10 | 300 | mx.spamexperts.com |
| MX | 20 | 300 | fallbackmx.spamexperts.eu |
| MX | 30 | 300 | lastmx.spamexperts.net |
Important: You must make sure you remove old MX records so that all emails are filtered through the Spam Experts cloud. Spammers actively try different MX records (such as the highest numbered priority) to bypass spam filters.
The priorities are incremental. Because the mail servers have been set up using the Round Robin method, the load will be distributed evenly about the servers. Differing priorities is one of the algorithms SpamExperts uses to distinguish spam from legal e-mail.
If you still use our solution where you have a bundle of domains instead of separate domains, you will need to use the following MX records;
- primary.mail.registrar.eu (priority 10)
- fallback.mail.registrar.eu (priority 20)
Testing your mailserver when using SpamExperts
Question:
What to do if suddenly the SpamExperts cluster gets stuck.
Answer:
If the SpamExperts cluster gets stuck, there might be a problem with your (customers) mail-server where the mail gets delivered in the end.
You can test this yourself by simulating a mail-delivery to this mailserver.
In a Windows cmd-shell or on a UN*X/Linux/Mac console, type the following commands.
Below is an example, you can use your own data at underlined places:
Command-shell> telnet mail.mycustomer.be 25
220 MICROSOFT EXCHANGE 0.1 ESMTP Mail Server Ready
(You should receive a 220-response)
Command-shell> helo myrandomname
250 HELO 85.159.97.15 , Nice to meet you!
(You should receive a 250 response)
Command-shell> mail from: myownmail@weprovideyoumail.be
250 Ok
(You should receive a 250 response)
Command-shell> rcpt to: info@mycustomer.be <--- Enter a valid mail-address where mail should be received
250 Ok
(You should receive a 250 response)
Command-shell> data
354 End data with .
(Server gives a 354 message, accepting the mail)
You can quit now, or actually type data to send a mail. End it with a single dot (.) on a line and enter to send it.
If you get other responses or no response at all, there might be a problem with the mailserver.
What are domain aliases in SpamExperts?
Question
What are domain aliases in SpamExperts?
Answer
You can configure an unlimited number of domain aliases for a domain filter. All email traffic sent to these aliases will be filtered. Spam messages will stay quarantined in SpamExperts, and all legitimate email will be delivered to the main domain.
Domain aliases do not have separate access to the Domain Level Control Panel. Since all SMTP traffic to the domain alias is rewritten to the main domain, any changes/lookups on the main domain will simply include the alias domain traffic as if it was sent directly to the main domain. If you are searching for a specific email sent to a domain alias using the Log Search, the recipient will therefore show as user@maindomain.
Note: When adding a domain alias, the MX-records are not updated automatically and have to be set manually to the same MX-records as the main domain.
Example case:
-
You configured the filter for example.com, using mail server mail.example.com
-
For this domain, you add otherdomain.com as an alias
-
An email sent to info@otherdomain.com will be examined by SpamExperts filter and delivered to info@example.com
-
The To field in the email header will show the original e-mail address
Aliasses
Domain aliases do not have separate access to the Domain Level Control Panel.
Since all SMTP traffic to the domain alias is rewritten to the main domain, any changes/lookups on the main domain will simply include the alias domain traffic as if it was sent directly to the main domain.
If you are searching for a specific email sent to a domain alias using the Log Search, the recipient will therefore show as user@maindomain.
Note: When adding a domain alias, the MX-records are not updated automatically and have to be set manually to the same MX-records as the main domain.
What to do when I receive spam?
Question:
What can I do when I receive spam?
Answer:
First check whether the e-mail is filtered by SpamExperts. If so, you will find a line in the e-mail headers that starts with X-SpamExperts-Class. Is this line not present? The the spam filter was not used. Possible causes can be:
You configured SpamExperts less than 48 hours ago; the DNS system uses caching mechanisms that store some data locally to prevent overload of the nameservers. This might result in temporarily outdated data.
- Check whether only the SpamExperts MX records have been added in your DNS zone, and no other MX records. Check this by going to the Openprovider reseller control panel, menu DNS management>DNS checks.
- Some spammers remember old mail servers for a long time. That can cause old mail servers to be used long after you changed them to SpamExperts.
- Sometimes spammers just try to be lucky by using an ordinary hostname like mail.yourdomain.com to send spam, so that the official MX records are bypassed.
If X-SpamExperts-Class is included in the headers, but the value is whitelisted, then you or the e-mail user whitelisted the sender. Other values for this field are ham or unsure; in those cases, SpamExperts was not sure enough to categorize the e-mail as spam.
Note that an expired (non-renewed) bundle will automatically whitelist 'all' senders! See for more information our article about expiration of a spam filter bundle.
When a spam message has been delivered despite of the filtering, you can train the spam filter by the button Report spam in the SpamExperts control panel. Here, you can upload the original e-mail in .txt or .eml format. The Microsoft Outlook .msg format cannot be used!
Which IP addresses should be whitelisted on a mail server?
Question
Which IP addresses should I whitelist on my mail servers to accept filtered incoming mail traffic from SpamExperts?
Answer
That depends on solution you use.
1. Public domain cloud
2. Bundled-solution
SpamExperts public cloud (per domain filters)
In order to accept messages from the SpamExperts public cloud (antispamcloud.com) filtering servers, emails coming from "delivery.antispamcloud.com" host should be explicitly allowed on your mail server. This hostname contains all active IP addresses used to send email from SpamExperts public cloud. Alternatively it is possible to allow traffic from any IP address with the PTR record *.antispamcloud.com.
Please make sure your firewall rules do not block port 53.
In case if allowing emails based on hostname is not an option it is possible to configure destination mail server to receive emails on alternative port, such as for instance port 2525 instead of the default 25. If you want to configure non-default port for mail delivery on your destination server it can be configured via destination route for the domain in Openprovider control panel (e.g. like mail.mydomain.com:2525).
If neither approach above is acceptable SpamExperts public cloud IPs could be explicitly whitelisted. Full list of IPs of SpamExperts public cloud is available via link.
SpamExperts cloud hosted by Openprovider (bundles)
For customers who use SpamExperts bundles in Openprovider the list of IPs is different from the SpamExperts public cloud.
In order to accept incoming mails from Openprovider SpamExperts hosted environment, the next IP addresses needs to be allowed on the destination mail server.
| IPv4 | IPv6 |
65.108.53.141 |
2a01:4f9:c011:a01e::1 |
37.27.16.104 |
2a01:4f9:c011:a925::1 |
65.21.183.151 |
2a01:4f9:c012:98aa::1 |
65.109.233.174 |
2a01:4f9:c012:8abf::1 |
65.108.241.80 |
2a01:4f9:c012:57ad::1 |
65.108.214.134 |
2a01:4f9:c011:a2ef::1 |
95.217.174.147 |
2a01:4f9:c01d:857::1 |
34.249.79.17
|
2a05:d018:c9d:b900:1e69:2691:fe7d:661c
|
54.195.120.9
|
2a05:d018:c9d:b900:c397:e98f:a61f:cb87
|
54.194.42.112
|
2a05:d018:c9d:b900:c8bd:65ce:f2e5:d378
|
🇪🇸 ¿Cómo configurar el filtro de entrada de spam?
Configurar el filtro de spam es sencillo. Solo hay que seguir estos pasos:
1. En el panel de control, clicar en "Filtros de Spam / añadir nuevo filtro".
2. En la siguiente pantalla, añade el dominio, selecciona "filtro de entrada" y añade el servidor de correo. Clica en guardar.
3. Añade los siguientes registros mx a tus DNS:
mx.spamexperts.com (prioridad 10)
fallbackmx.spamexperts.eu (prioridad 20)
lastmx.spamexperts.net (prioridad 30)
4) Ahora configure el servidor de correo para que acepte las conexiones del filtro de spam como de confianza. Esto se puede hacer mediante la lista blanca del dominio delivery.antispamcloud.com en el servidor de correo.
También se puede hacer mediante la lista blanca de las direcciones ip del antispam. Puedes encontrarlos aquí:
Por favor asegúrate de suscribirte a la rss feed si utilizas el sitio web para saber cuando un dirección IP se agrega a esta lista.
5) En algunos casos Spamexperts también necesita ser añadido al registro spf del dominio.
Para ello, añada los siguientes registro SPF:
- "v=spf1 a:683.submission.antispamcloud.com -all"
o
- a:683.submission.antispamcloud.com al spf ya existente