Incoming filtering

Add accounts to allow list in Spam Experts

Question

How to add accounts to allow list in Spam Experts?

Answer

There are two allow lists - Sender allow list and Recipient allow list.

Note: This article assumes that the user already knows the ways to access their Spam Experts control panel, in case you have doubts or do not know how to see the aforementioned menu, we recommend you visit this article where we detail how to configure your service by Spam Experts.

What is Sender allow list, and how to manage it?

Incoming mail received from senders listed in the Allow list will always be allowed, regardless of the message classification.

Go to Incoming - Protection Settings > Sender allow list

embedded-image-mwsexc97.png

embedded-image-x9m51hf1.png

The above window will be displayed, you just need to click on Add sender to allow list option.

embedded-image-njtsg7os.png

In "local-part" add the name of the email to be added and in "address" the domain name.

For example. If you need to add an email called victor@gmail.com, then the configuration would be as follows.

Local-part
Victor

Address
gmail.com

Note: It is important to check the option “Apply to both”

Once this is done, press the "Save" button.

What is Recipient allow list, and how to manage it?

Incoming mail sent to recipients listed in the Recipient Allow list will always be allowed, regardless of the message classification. This is generally not recommended for normal mailboxes.

Go to Incoming - Protection Settings > Recipient Allow list

embedded-image-ojc2zwlx.png

Note: This page lists read-only rules, which are set by a higher level admin.

embedded-image-ispdxm4o.png

Are viruses blocked too by the spam-filter?

Question

Are viruses been blocked by the Spam-filter?

Answer

Viruses, malware and other online threats are often been spread via email. Therefore it is essential that emails are scanned for viruses before they reach users' mailboxes. Spamexperts actively blocks both spam and malicious attachments such as viruses, malware, ransomware, spyware and so on.

The additional anti-virus measures include a sequential combination of different technologies to protect clients against malware. This includes the open-source ClamAV antivirus framework, which is enhanced with additional data-sets specialized in detecting zero-day email viruses provided by several external partners.

For additional explanation of the virus protection by Spamexperts you can visit the follow Link

How does incoming filtering work

Question

What is incoming email filtering and how does it works?

Answer

Email filtering separates legitimate email from unsolicited bulk email with the help of advanced
algorithms and spam pattern detection methods. 

It works by Re-routing the email through filters.

Spamexperts incoming spam filter is a gateway solution.

Activation is done via a simple DNS adjustment. Once the MX-records are changed, all inbound email goes to the Spamexperts system first, where it is filtered and then relayed to the unchanged destination mail servers of your clients. 

Deployment

The actual message filtering is done in the highly redundant Spamexperts Hosted Cloud.

This solution is fully managed, maintained, and 24/7/365 monitored by Spamexperts.

Filtering work flow:

mceclip1.png

The filtering of e-mails is done on two levels.

E-mail that is blocked on the DATA level is put into the quarantine mailbox and can be released from there. E-mail that is blocked on the SMTP level cannot be recovered: the e-mail was simply not received completely.

How to exclude a certain email address from being filtered?

Question

How to prevent an email from being filtered?

Answer

By configuring allow or block list filtering rules for outgoing or incoming filters the emails in the configuration will be accepted or sent without the need for the filter to check it.

This is very useful when there is an abuse e-mail address that for example should receive all e-mails.
In this case, add abuse@yourcompany.com to the recipient allow list.

The steps for the configuration can be found on the following URLS of Spamexperts knowledge base for Allow list/Block list and the incoming and outgoing filter rules.

Allow list/Block list

Allow list/Block list filtering rules: 

How to setup an incoming spam-filter

Question:


How to order and configure an incoming spam filter?

Answer:

In order to set up an incoming filter on domains, first one needs to have a domain.

It does not matter if the domain is with Openprovider or with another registrar.

Step-by-step guide:

1) Log into the Openprovider control panel and navigate to Spam filtering (SpamExperts) > Order new filter.

2) On the next screen:

- Enter the domain name

- Select the desired filter (Incoming filter / Outgoing filter / E-mail archiving)

- Enter the mail-server host address

embedded-image-lcq6u6qz.png

3) Click Save

Now the incoming filter for the domain has been created but, not yet configured.

4) Add MX records to the DNS zone of the domain.

If the domain is with Openprovider and is also using Openprovider's NS, the following MX records will be automatically added by our system to the DNS zone.

Otherwise, you will have to add them manually.

Be sure to never add other MX record(s) together with the Spamexperts records: this will result in only partial filtering of the e-mail, and not remove spam completely!

In case a DNS zone isn't created yet for the domain and if you would like to use Openprovider DNS service, please refer to the article

In case the DNS zone is with Openprovider, navigate to DNS management > DNS zones overview and click on the domain in the list.

Once the DNS zone details page is opened, click on the Details tab and Enable the SpamExperts checkbox. Once the page is refreshed the MX records will appear automatically added into the zone.

embedded-image-azqjtnnu.png

embedded-image-pwknj9ka.png

5) To configure the mail server to accept the spam-filter connections and treat them as 'trusted'.

This can be done by whitelisting the domain-name delivery.antispamcloud.com in the mail server.

6) In some cases SpamExperts server also needs to be added to the SPF record of the domain DNS zone.

In order to do this, please add the following SPF record with the content below:

"v=spf1 include:spf.antispamcloud.com -all"

Or add include:spf.antispamcloud.com -all to the existing SPF record.

For more information about the incoming spam filter can be found in the knowledge base of SpamExperts.

Login to Spamexperts panel directly

Question

Is it possible to log in to Spamexperts control panel directly?

Answer

When creating a spam filter with Openprovider the credentials for direct access to the Spamexperts control panel can be found in the Openprovider panel. 

Domain Account

Bundle Account

mceclip0.png

Note: One can create login credentials also on user level, allowing the end customer to log in to the Spamexperts control panel directly.


To create login credentials for a mailbox user, first one need to log into Spamsxperts control panel and scroll down to the bottom of the menu. Search for Users & permissions > Manage email users  on menu item and click on it, (see example below). Then one will be able to add email user for a domain.

mceclip2.png

Such users will have limited access to Spamexperts control panel allowing them to view their own logs, manage emails moved to quarantine and change some minor settings.

NOTE: Due to security setting from Spamexperts, always use HTTPS to log in. If you try to login to Spamexperts directly via HTTP, you will get a message that the browser doesn't support cookies.

Also, users only have domain level access and it comes with certain restrictions compared to admin level access - which is managed by Openprovider. Some options like editing Email Scout Report (ESR) templates, enabling domain-level reporting etc... won't be available for users.

SpamExperts: Which MX records should I use?

Question:

Which MX records should I use for SpamExperts incoming filtering?

Answer:

To use the SpamExperts incoming spam filtering service, you need to update MX records for your domain in your DNS zone to the following:

Type Priority TTL (recommended)
Value
MX 10 300 mx.spamexperts.com
MX 20 300 fallbackmx.spamexperts.eu
MX 30 300 lastmx.spamexperts.net

Important: You must make sure you remove old MX records so that all emails are filtered through the Spam Experts cloud. Spammers actively try different MX records (such as the highest numbered priority) to bypass spam filters.

The priorities are incremental. Because the mail servers have been set up using the Round Robin method, the load will be distributed evenly about the servers. Differing priorities is one of the algorithms SpamExperts uses to distinguish spam from legal e-mail.

If you still use our solution where you have a bundle of domains instead of separate domains, you will need to use the following MX records;

Testing your mailserver when using SpamExperts

Question:

What to do if suddenly the SpamExperts cluster gets stuck.

Answer:

If the SpamExperts cluster gets stuck, there might be a problem with your (customers) mail-server where the mail gets delivered in the end.

You can test this yourself by simulating a mail-delivery to this mailserver.

In a Windows cmd-shell or on a UN*X/Linux/Mac console, type the following commands.
Below is an example, you can use your own data at underlined places:

Command-shell>  telnet mail.mycustomer.be 25

220 MICROSOFT EXCHANGE 0.1 ESMTP Mail Server Ready

(You should receive a 220-response)

Command-shell>  helo myrandomname

250 HELO 85.159.97.15 , Nice to meet you!

(You should receive a 250 response)

Command-shell>  mail from: myownmail@weprovideyoumail.be

250 Ok

(You should receive a 250 response)

Command-shell>  rcpt to: info@mycustomer.be  <--- Enter a valid mail-address where mail should be received

250 Ok

(You should receive a 250 response)

Command-shell>  data

354 End data with .

(Server gives a 354 message, accepting the mail)

You can quit now, or actually type data to send a mail. End it with a single dot (.) on a line and enter to send it.

If you get other responses or no response at all, there might be a problem with the mailserver.

What are domain aliases in SpamExperts?

Question

What are domain aliases in SpamExperts?

Answer

You can configure an unlimited number of domain aliases for a domain filter. All email traffic sent to these aliases will be filtered. Spam messages will stay quarantined in SpamExperts, and all legitimate email will be delivered to the main domain.

Domain aliases do not have separate access to the Domain Level Control Panel. Since all SMTP traffic to the domain alias is rewritten to the main domain, any changes/lookups on the main domain will simply include the alias domain traffic as if it was sent directly to the main domain. If you are searching for a specific email sent to a domain alias using the Log Search, the recipient will therefore show as user@maindomain.

Note: When adding a domain alias, the MX-records are not updated automatically and have to be set manually to the same MX-records as the main domain.

Example case:

Aliasses

Domain aliases do not have separate access to the Domain Level Control Panel.

Since all SMTP traffic to the domain alias is rewritten to the main domain, any changes/lookups on the main domain will simply include the alias domain traffic as if it was sent directly to the main domain.

If you are searching for a specific email sent to a domain alias using the Log Search, the recipient will therefore show as user@maindomain.

Note: When adding a domain alias, the MX-records are not updated automatically and have to be set manually to the same MX-records as the main domain.

What to do when I receive spam?

Question:

What can I do when I receive spam?

Answer:

First check whether the e-mail is filtered by SpamExperts. If so, you will find a line in the e-mail headers that starts with X-SpamExperts-Class. Is this line not present? The the spam filter was not used. Possible causes can be:

You configured SpamExperts less than 48 hours ago; the DNS system uses caching mechanisms that store some data locally to prevent overload of the nameservers. This might result in temporarily outdated data.


If X-SpamExperts-Class is included in the headers, but the value is whitelisted, then you or the e-mail user whitelisted the sender. Other values for this field are ham or unsure; in those cases, SpamExperts was not sure enough to categorize the e-mail as spam.

Note that an expired (non-renewed) bundle will automatically whitelist 'all' senders! See for more information our article about expiration of a spam filter bundle.

When a spam message has been delivered despite of the filtering, you can train the spam filter by the button Report spam in the SpamExperts control panel. Here, you can upload the original e-mail in .txt or .eml format. The Microsoft Outlook .msg format cannot be used!

Which IP addresses should be whitelisted on a mail server?

Question

Which IP addresses should I whitelist on my mail servers to accept filtered incoming mail traffic from SpamExperts?

Answer

That depends on solution you use.
1. Public domain cloud
2. Bundled-solution

SpamExperts public cloud (per domain filters)

In order to accept messages from the SpamExperts public cloud (antispamcloud.com) filtering servers, emails coming from "delivery.antispamcloud.com" host should be explicitly allowed on your mail server. This hostname contains all active IP addresses used to send email from SpamExperts public cloud. Alternatively it is possible to allow traffic from any IP address with the PTR record *.antispamcloud.com.

Please make sure your firewall rules do not block port 53.

In case if allowing emails based on hostname is not an option it is possible to configure destination mail server to receive emails on alternative port, such as for instance port 2525 instead of the default 25. If you want to configure non-default port for mail delivery on your destination server it can be configured via destination route for the domain in Openprovider control panel (e.g. like mail.mydomain.com:2525). 

If neither approach above is acceptable SpamExperts public cloud IPs could be explicitly whitelisted. Full list of IPs of SpamExperts public cloud is available via link.

SpamExperts cloud hosted by Openprovider (bundles)

For customers who use SpamExperts bundles in Openprovider the list of IPs is different from the SpamExperts public cloud. 

In order to accept incoming mails from Openprovider SpamExperts hosted environment, the next IP addresses needs to be allowed on the destination mail server.

IPv4 IPv6
65.108.53.141
2a01:4f9:c011:a01e::1
37.27.16.104
2a01:4f9:c011:a925::1
65.21.183.151
2a01:4f9:c012:98aa::1
65.109.233.174
2a01:4f9:c012:8abf::1
65.108.241.80 
2a01:4f9:c012:57ad::1
65.108.214.134
2a01:4f9:c011:a2ef::1
95.217.174.147
2a01:4f9:c01d:857::1
34.249.79.17
2a05:d018:c9d:b900:1e69:2691:fe7d:661c
54.195.120.9
2a05:d018:c9d:b900:c397:e98f:a61f:cb87
54.194.42.112
2a05:d018:c9d:b900:c8bd:65ce:f2e5:d378

🇪🇸 ¿Cómo configurar el filtro de entrada de spam?

Configurar el filtro de spam es sencillo. Solo hay que seguir estos pasos:

1. En el panel de control, clicar en "Filtros de Spam / añadir nuevo filtro".

2. En la siguiente pantalla, añade el dominio, selecciona "filtro de entrada" y añade el servidor de correo. Clica en guardar.

3. Añade los siguientes registros mx a tus DNS:

mx.spamexperts.com (prioridad 10)

fallbackmx.spamexperts.eu (prioridad 20)

lastmx.spamexperts.net (prioridad 30)

4) Ahora configure el servidor de correo para que acepte las conexiones del filtro de spam como de confianza. Esto se puede hacer mediante la lista blanca del dominio delivery.antispamcloud.com en el servidor de correo.

También se puede hacer mediante la lista blanca de las direcciones ip del antispam. Puedes encontrarlos aquí:

Http://noc.spamexperts.net/

Por favor asegúrate de suscribirte a la rss feed si utilizas el sitio web para saber cuando un dirección IP se agrega a esta lista.

5) En algunos casos Spamexperts también necesita ser añadido al registro spf del dominio.

Para ello, añada los siguientes registro SPF: 

- "v=spf1 a:683.submission.antispamcloud.com -all"

o

- a:683.submission.antispamcloud.com al spf ya existente