How to block incoming mail with internal domain as sender

Hi all,
Ironport accept incoming mail to internal domains defined in the RAT without verify the sender domain is the same internal domain.
To avoid this I have used a message filter to drop those mails. I can't use the bounce command to avoid to be considered a spammer.
Is there a way to reject those mails with a 5xx error message?
Thanks in advance.
Regards,
Andrea

Securegroup,
jloehler is absolutely correct, when I configure appliances (personally I use a 1 listener config) I set the Default Mailflow Policy to Use the Exception Table ("On") and insure that all incoming mail policies (anything with the ACCEPT action) is set to "Use Default" for this parameter. Then I double check to insure that the RELAY policy is set to "Off" because you don't want to reject outbound messages due to the Exception Table.
Once I've verified that the RELAY is off and Inbound policies are "On" I then populate my exception table with all the internal domains and specify the reject action. Now a quick take away is that the Exception Table only performs the rejection based on the SMTP MAIL FROM not the "From:" header internal to the message itself.
Now with all that said it never fails that there is some internal group that uses 3rd party marketing which spoofs the internal domains so I usually create a new incoming mail flow policy with the Exception Table turned "Off" and create a Sender Group call DOMAINSPOOFLIST which are IPs and Domain names that I allow to spoof internal e-mail addresses with the new mail policy assigned to it.
And that's it.
Sincerely,
Jay Bivens
IronPort Systems

Similar Messages

  • How to delete all mails with one klick?

    It's annoying to delete every single mail.
    How to delete all mails with one klick, like in the paperbasket?
    Thanks

    If the emails have been previously deleted (I.e. in the trash folder), tap Edit at the top of the list. You should see a delete all button at the bottom. If the messages are in a standard folder, they need to be handled one at a time.

  • How to configure bt mail with icloud?

    how to configure bt mail with icloud?

    iCloud does not handle any mail systems except for its own. BT is not an iCloud mail system, so you can't.

  • SharePoint 2013 : Incoming Mail with NLB

    I am trying to configure Incoming Email and I have (2) of each WFE & APP Servers
    Based on Q&A link below
    http://social.technet.microsoft.com/Forums/sharepoint/en-US/f9f1d254-0f9e-4eec-a1c7-a94252668680/sharepoint-2013-incoming-mail-with-nlb?forum=sharepointgeneral
    Note that the SPLockJobType will be changed to Job in the December 2013 CU for load balancing purposes.
    http://sharepoint.nauplius.net/2013/08/update-on-incoming-email-job-lock-type-change-between-sharepoint-2010-and-2013/
    It is not recommended to run Incoming Email on more than one SharePoint 2013 server due to a synchronization issue Microsoft identified (hence the job lock type change).
    My question: is the patch part of SharePoint Cumulative Update 15.0.4551.1511 - if not then I will apply it separately (do I apply to all the servers and would I have to run SharePoint Products and Configuration) ?
    Thanks
    Davinder

    The patch is part of the December 2013 CU. You can use Incoming Email in a load balanced or high availability MX/SMTP routing given you have the Dec 2013 CU installed on SharePoint 2013.
    Trevor Seward
    Follow or contact me at...
    &nbsp&nbsp
    This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • How to block incoming call on iphone

    how to block incoming call on iphone

    Contact your carrier & see if they offer call blocking...some do, some don't. There is no other way to block calls on any cell phone.

  • How to sync your mail with yahoo

    does anyone know how to synck your mail with yahoo mail?

    Hello bttrcup and welcome to the Palm forums.
    The easiest way that I know to setup everything for Yahoo on your new Pixi is to simply add your Yahoo email account to the email application.  When you do, webOS' Synergy will also setup your calendar, contacts, and IM to sync with your Yahoo account.
    This is how I've setup my Sprint Pre to sync with my Yahoo account.  I have to admit that I don't use my Yahoo account so I only log into it when I'm troubleshooting something like this.
    Hope that helps.
    Alan G

  • Mail with multiple gmail accounts sending messages from wrong email, other than the one i select

    mail with multiple gmail accounts sending messages from wrong email, other than the one i select:
    i'm using mail on osx 10.7 with multiple gmail accounts. when i create an email, i check to be sure i'm sending/replying from the correct account. after i send it, somehow it actually sends it from a different account, other than the one i've selected "from." this is evidenced by the reply email i receive. how can i fix this?
    in preferences, i have "send new messages from : account of selected mailbox"

    From the Mail menu bar, select
              Mail ▹ Preferences...
    The Mail preference dialog opens. Select the Composing tab from the row of icons at the top. From the menu labeled
              Send new messages from:
    choose
              Account of selected mailbox
    Note that this setting may have no effect if you start a new message while a VIP or smart mailbox is selected in the mailbox list. Those are saved searches, not actual mailboxes.
    If the problem remains, select the Accounts tab in the preference dialog, then select the affected account in the list on the left.
    In the Account Information pane, select the correct server in the menu labeled
              Outgoing Mail Server (SMTP)
    If there's only one server in the menu, select
              Edit SMTP Server List...
    and add a new server with the correct settings. If you're not sure how to do that, try the Mail Settings Lookup.
    Another possibility is that the wrong card in your address book is selected as yours. Select your card in the Contacts application. Then select
              Card ▹ Make This My Card
    from the menu bar.

  • Mail in Yosemite puts incoming mails in spam, even the sender is in my contacts.

    mail (Yosemite) puts incoming mails in spam, even the sender is in my contacts.

    Hello martinamm,
    Thanks for using the Apple Support Communities. I understand that you have some mail that is automatically being filtered to spam, even though the contacts are in your address book. The following resource provides a few more steps you can attempt to resolve this:
    Mail (Yosemite): If junk mail filters aren’t working correctly
    http://support.apple.com/kb/PH19190
    If messages are incorrectly marked as junk
    There are several ways you can prevent Mail from incorrectly marking legitimate messages as junk.
    - Tell Mail that a message is legitimate by marking it as not junk. Click Not Junk in the banner of the message; or select the message, then click the Not Junk button in the Mail toolbar.
    - Add the sender to the Contacts app. For more information, see Save addresses, events, passes, and more.
    - Review your junk mail settings in Mail preferences, as well as any rules you might have created to handle junk mail, and make changes as necessary.
    Cheers,
    Matt M.

  • I have an iphone 4s. able to receive all the incoming mails but not able to send mails through this iphone 4s. please help.

    I have an iphone 4s. able to receive all the incoming mails but not able to send mails through this iphone 4s. please help.

    delete and reinstall the email account.

  • Incoming Sharepoint Mail: External/Internal Domain Environment

    We have setup Incoming Sharepoint 2010 Mail both on Sharepoint side and on the Exchange 2007 side (Send Connector setup). And we have no problem delivering mail from Exchange to Sharepoint.
    We have an External/Internal Domain setup.
     Our Windows DNS does not own the “A” record for our External domain Name @external.Domain.com. 
    All mailboxes/mail-enabled contacts/UDG’s/USGS are stamped with our External domain Name: @external.Domain.com because within Exchange an accepted domain (Internal Relay Type) was created for @external.Domain.com.
    Sharepoint is part of our Internal Windows domain. Sharepoint mail-enabled contacts are created as
    [email protected]
    Per Incoming mail technote: we created Active Directory Org Unit for Share Point mail-enabled contacts. These contacts replicated to Exchange Recipient Management Console and then of course
    to the Outlook Global Address List; however, the contacts are not a routable address because they are stamped @windows.Internal.Domain.com.  If we add @external.Domain.com which is a routable address, mail is delivered to the Sharepoint Site.
    Q. One thing we do not want is within our Outlook Global Address List, to show two SMTP domain names, i.e., @windows.Internal.Domain.com and @external.Domain.com this would be
    too confusing for our users. Also changing each mail-enabled contact to the routable address (@external.Domain.com would be a nightmare. Any suggestions or assistance would be greatly appreciated?

    It doesn't need to be a nightmare, you simply have to create a Recipient Update Policy and apply it to the OU containing your contacts/DLs. You also need to configure SharePoint to use external.domain.com instead of the internal domain.
    See http://thesharepointfarm.com/2013/02/a-practical-guide-to-implementing-incoming-email-using-the-sharepoint-directory-management-service/
    for more info on how this is done.
    Trevor Seward
    Follow or contact me at...
    This post is my own opinion and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • Block and Unblock the .zip and .rar files based on doamin or user account base on incoming mails with ironport email security.

    Hi All,
    Request you all to help me out in blocking/dropping only the attachments with the extension .rar and .zip in incoming mails for particular users or domains.
    as of now I have did for all the domains or users.However, I want to unblock it only for some particular/specific users and for rest it should block.
    kindly help me with the steps to do the configuration.
    Thanks a ton in advance
    Regards,
    LRN

    It sounds like you just need to use different incoming mail policies per group of individuals you want to block/drop .rar and .zip and those which you don't want this to happen.
    The fact that you want a specific group to be allowed receipt of these and everyone else should have these blocked I would recommend creating an additional incoming mail policy that does NOT have a content filter that performs this blocking.  Add the appropriate users to this incoming mail policy.  Then create a incoming content filter that does this dropping of .rar and .zip files and apply this to the Default Incoming Mail Policy.
    The content filter in this situation would not need a condition, just a action of strip attachments by file info , filename contains  .rar or .zip
    Here is a useful regex for the content filter action:  (?i)\.(zip|rar)
    Hope this helps!
    Steve

  • How to setup Autodiscovery for .local internal domains with Exchange 2013

    Hi,
    I need to know about how i set autodiscovery in local domain.I have local domain eg
    abc.local and domin which i received the emails externally is  xyz.com.
    I have deployed Exchange2013 recently with same above scenario inbound and outbound mails are working fine using OWA.But outlook clients cannot connect to Exchange server with in the LAN. 
    Please help me out how set auto discovery in local domain and another help i need how i configure the self sign certificate in this scenario.   

    You cannot use a self signed cert for RPC/HTTP connections (which is how the Outlook client is connecting exchange2013). Please check this http://social.technet.microsoft.com/Forums/exchange/en-US/aed4ede9-57c3-44c3-90b4-bdfb3a7f017d/exchange-2013-self-signed-certs-and-outlook-client-access?forum=exchangesvrgeneral 
    But you can use a certificate from an internal CA which you can install in your network issue a certificate for exchange. Please check this it will help you manage internal certificates for a PC and for a domain.  http://technet.microsoft.com/en-us/library/cc754841.aspx
    You dont need to configure autodiscover for internal domain added clients. If you have clients on the network which are not members of the domain, using Exchange, this could be Windows, MACs or mobile devices, then you should ensure that autodiscover.example.com
    resolves internally to the Exchange server via a split DNS system. http://exchange.sembee.mobi/network/split-dns.asp
    Please configure your external and internal URLs as well
    http://www.mustbegeek.com/configure-external-and-internal-url-in-exchange-2013/
    I recommend to buy a 3rd party certificate as it may create issue for external clients e.g.Outlook anywhere
    Thanks, MAS
    Please mark as helpful if you find my comment helpful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you.

  • Block incoming mail (spam) overnight?

    G5   Mac OS X (10.4.6)  
    I've noticed that 95% of my spam is delivered to me between 12 am and 8 am. Since friends and collegues rarely send me email during those hours, I was wondering if there is a way to disable Mail during those hours and thereby block the emails from ever making it to my inbox.
    I've looked through rules and tried unchecking the "enable this account" box in Preferences but have not found anything that works. Any ideas?
    Best,
    Lea

    Securegroup,
    jloehler is absolutely correct, when I configure appliances (personally I use a 1 listener config) I set the Default Mailflow Policy to Use the Exception Table ("On") and insure that all incoming mail policies (anything with the ACCEPT action) is set to "Use Default" for this parameter. Then I double check to insure that the RELAY policy is set to "Off" because you don't want to reject outbound messages due to the Exception Table.
    Once I've verified that the RELAY is off and Inbound policies are "On" I then populate my exception table with all the internal domains and specify the reject action. Now a quick take away is that the Exception Table only performs the rejection based on the SMTP MAIL FROM not the "From:" header internal to the message itself.
    Now with all that said it never fails that there is some internal group that uses 3rd party marketing which spoofs the internal domains so I usually create a new incoming mail flow policy with the Exception Table turned "Off" and create a Sender Group call DOMAINSPOOFLIST which are IPs and Domain names that I allow to spoof internal e-mail addresses with the new mail policy assigned to it.
    And that's it.
    Sincerely,
    Jay Bivens
    IronPort Systems

  • How to block the undeliverable message internally?

    How to block undeliverable message internally in case the internal sender sent email to one oversize internal recipient?
    Thanks a lot

    Exchange 2010/Outlook 2010
    Sorry for posting in such an old thread, but I have a similar issue:
    We have a mailing list account that receives thousands of Undeliverable messages every day.
    Could I use ECS to tell Exchange to Reject Messages From "MicrosoftExchange[long string]@domain.com?
    What would happen to the Undeliverable messages? Are there any problems with this?
    Thank you!
    -R
    Edit: that solution did not block the DSNs.
    I also tried creating a transport rule to delete all e-mail going to that account, but that only worked for personal e-mails, not DSNs.
    One solution I was able to come up with was to set a mail rule that sends everything to a subfolder. This will prevent the mailbox from hitting the "100,000 items in critical path folders" best practice.
    The second solution I am testing is to create a Mailbox Retention Policy to permanently delete all items older than 7 days.

  • Drop incoming mail from specific domain.

    Is this possible and if so how do I configure?
    I want to be able to drop incoming mail from, lets say, "@bigspammailer.com".  Is there a way to do this?  I have created an "Incoming Mail Policy" but don't know where to apply it.
    What I've tried that has not worked ....
    Incoming Content Filters, created a filter with Condition of "mail-from = = "@myemaildomain.com"$", and an action of "Drop".
    HAT Overview, creating a Sender Group using Mail Flow Policy "BLOCKED" setting SBRS to various settings including "None".
    I've grown exhausted reading through manuals. If you know of a document that directly addresses this issue (assuming it's possible) I'm not opposed to reading it.
    Any help will be greatly appreciated!
    Jim Mc.

    Sender Groups can be used to block messages based on the hostname or IP of the sending machine. It does not look at who the message is "from." To block mail based on the envelope sender you need to use a Filter or the Sender Verification Exception Table.
    Your example of a content filter seemed ok but after you create a filter you need to make sure that it is enabled for the incoming mail policy. Create your filter and then select Mail Policies -> Incoming Mail Policies. Under the column called Content Filters you will need to
    1) turn content filters on (default is off)
    2) enable the specific content filter that you just created
    You can also enter it in the Sender Verficiation Exception Table. You need to enable it under your ACCEPTED policy under Mail Policies -> Mail Flow Policies. There is a radio button all the way at the bottom for the exception table. Once you have it enabled then you can select Mail Policies -> Exception Table and add @domain.com to always reject.

Maybe you are looking for