<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Many SPAM with Sophos Email Appliance</title><link>https://community.sophos.com/email-appliance/f/discussions/108494/many-spam-with-sophos-email-appliance</link><description>Hi, 
 I&amp;#39;m in a new Company that has Sophos Email Appliance like a SPAM control (I haven&amp;#39;t use this product yet) . In these days my collegues ask me why we receive many SPAM. I&amp;#39;v checked the configuration of VEA and there is an high spam rule yet, but</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Many SPAM with Sophos Email Appliance</title><link>https://community.sophos.com/thread/389943?ContentTypeID=1</link><pubDate>Tue, 20 Nov 2018 02:01:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:6f111774-6134-4e05-b514-6c32b1a9630b</guid><dc:creator>Riccardo Campagnaro</dc:creator><description>&lt;p&gt;Thank you for the response , Red_Warrior!&lt;/p&gt;
&lt;p&gt;I&amp;#39;m checking the spam rules, in anycase i put the ips of these emails in blacklist.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Bye&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Many SPAM with Sophos Email Appliance</title><link>https://community.sophos.com/thread/387953?ContentTypeID=1</link><pubDate>Wed, 31 Oct 2018 11:39:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4f4e640d-c444-4ec5-88ce-b0ca16bf0843</guid><dc:creator>Red_Warrior</dc:creator><description>&lt;p&gt;Hi Riccardo,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I did up a best practice kb for spam rules, please have a look here :&amp;nbsp;&lt;a href="/kb/en-us/120802"&gt;https://community.sophos.com/kb/en-us/120802&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Another thing to note is the appliance has a powerful feature called delay queue, this feature does require 10.5 days in collect mode before it can be activated.&amp;nbsp; It is specifically designed to detect snowshoe spam.&lt;/p&gt;
&lt;p&gt;Other factors that may cause issues are : if the firewall is not redirecting port 25 directly to the appliance,&amp;nbsp; any upstream email appliances or load balancers.&amp;nbsp; These devices can prohibit the MTA from connecting to the appliance directly.&amp;nbsp; &amp;nbsp;When this happens blacklisted ips may not be detected by the blocker service.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Ensure the appliance is not been filtered by a webfilter as it performs real-time dns look ups and frequent updates that may be blocked.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;you can also submit samples direct to labs with the outlook plugin or by creating a new email, drag and drop the spam as a .eml attachment into a new message and send it to is-spam@labs.sophos.com .. this is an automated emailbox that tracks spam.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>