<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Report as Spam</title><link>https://community.sophos.com/email-appliance/f/discussions/108906/report-as-spam</link><description>We are relatively new to using the SEA and our end-users complain about continuing to get emails from senders they have marked as &amp;quot;Report as Spam&amp;quot; (RAS). From my understanding, marking an email RAS doesn&amp;#39;t mean for certain that going forward the email</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Report as Spam</title><link>https://community.sophos.com/thread/389769?ContentTypeID=1</link><pubDate>Fri, 16 Nov 2018 15:35:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:822c249c-ed57-4d6b-82a6-7dd9054ae20c</guid><dc:creator>Red_Warrior</dc:creator><description>&lt;p&gt;There are 2 reasons to run puremessage for exchange with an email appliance.&lt;/p&gt;
&lt;p&gt;#1 it offers anti-virus mail box scanning after the message has arrived to the mail box.&amp;nbsp; (ie if a virus is 0 day at the SEA and a detection comes out 3hrs later, store scanning would quarantine those messages after the fact)&lt;/p&gt;
&lt;p&gt;just make sure you install the AV only version, its best NOT to install the full version with anti-spam as this well because this will give you 2 quarantines to manage.. (major pita)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;#2 puremessage can scan mail destined to other internal email boxes.&amp;nbsp; &amp;nbsp;so if you wanted to spam scan between mail boxes, or have key word filters you could do that with all mail been delivered internally.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I highly recommend an AV only install on the mailbox servers as this will give you some extra protection in the event a virus is 0 day at the smtp gateway and later detected.. if the mailbox server trys to serve an email with a virus .. it would be blocked.&amp;nbsp; &amp;nbsp;in the AV/AS game.. every second counts.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Report as Spam</title><link>https://community.sophos.com/thread/389747?ContentTypeID=1</link><pubDate>Fri, 16 Nov 2018 13:32:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:70308d65-96d9-4416-9412-7719bc0d623d</guid><dc:creator>LRSpartan</dc:creator><description>&lt;p&gt;Thank ya again RW. I will take a deeper look at your response.&lt;/p&gt;
&lt;p&gt;Quick question, would there be any benefit of us installing&amp;nbsp;PureMessage on our Exchange server? More specifically, can a user block an email in PureMessage? Click a button or whatever. So while something might get passed the SEA, PM would see the block and stop it.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Report as Spam</title><link>https://community.sophos.com/thread/389736?ContentTypeID=1</link><pubDate>Fri, 16 Nov 2018 12:16:17 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:284fce4c-9697-4fbb-9766-ca0363d87928</guid><dc:creator>Red_Warrior</dc:creator><description>&lt;p&gt;interesting problem and very unique usecase.&amp;nbsp; You may need to think outside the box a bit.&lt;/p&gt;
&lt;p&gt;couple notes on your categories.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;VR: Virus&lt;/strong&gt; - done via antivirus rules under threat protection, the appliance at best will automatically quarantine a virus as such, in turn only an administrator can release it. or the sample is destroyed.. there is no scenario where a non administrator can allow a virus nor can you disable AV scanning.&lt;br /&gt;&lt;strong&gt;BC: Blocked by Customer&lt;/strong&gt; - done via the portal, a user would need to specifically say block x domain.. per-user block lists are run against any message addressed to a user that has a list.. there is no way to automate this via a 1 touch solution (i would recommend a feature request) otherwise policy would have to be created in the admin ui.&lt;br /&gt;&lt;strong&gt;DM: Direct Marketing&lt;/strong&gt; - this is covered via a bulk mail rule.. simply create a rule under additional policy for bulk mail and delete it&lt;br /&gt;&lt;strong&gt;FD: Fraud&lt;/strong&gt; - fraud messages are covered under anti spam rules and will automatically trigger a high spam rule to ensure it is deleted&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;FG:&lt;/strong&gt; From a Foreign Domain - not specicially covered but if you wanted to make a rule to drop all mail from Russia .. see my kb here and add as many countries as you wish :&amp;nbsp;&lt;a href="https://community.sophos.com/products/email-appliance/f/email-appliance-hardware-or-virtual/101835/country-specific-blocking/370052#370052LS:"&gt;community.sophos.com/.../370052&lt;/a&gt; List-Server - you could create a list of servers / mtas or domains with regular expressions.. see below for links and samples.NL: Newsletter - covered under bulk mail&lt;br /&gt;&lt;strong&gt;SP: Spam&lt;/strong&gt; - as rules&lt;br /&gt;&lt;strong&gt;VA: Virus Alert&lt;/strong&gt; - we do not alert, we automatically quarantine / destroy viruses on sight&lt;br /&gt;&lt;strong&gt;YG: Yahoo Groups&lt;/strong&gt; - you may need an allow rule for this specific domain..&amp;nbsp;&lt;br /&gt;&lt;strong&gt;CL: Chain Letter&lt;/strong&gt; - covered under AS rules.&lt;/p&gt;
&lt;p&gt;the report as spam does &lt;strong&gt;not append rules to the appliance&lt;/strong&gt;, it sends the email to labs where it is automatically added to data updates.. those updates are pushed out and mail is dropped as spam.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;some things you could try ..&amp;nbsp; (I do NOT recommend ANY of these options)&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;create a rule to drop &lt;strong&gt;ALL&lt;/strong&gt; mail and create a rule to exclude white listed domains. ie: **@**.com or **@**.net etc.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;you could also create outbound rules to append X-headers on sent mail, then create a rule to look for that header&lt;/p&gt;
&lt;p&gt;your exclusions would go above your delete all mail.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;keep in mind, there is NO recycle bin.. destroyed&amp;nbsp;mail is gone forever.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;as you pointed out the more policy you have, the slower mail is processed as each message that is accepted is compared line by line, this drop all policy aims to reduce policy by only searching for the white-listed domains.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;if there is other more specific issues or rules you need to make, you can do so, but there is no way for the appliance to magically figure out who wants what mail, and it can only identify items as bulk mail and spam based on the universally accepted criteria of such .. ie: blacklists, known bulk mailers and similar.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;in regards to regular expressions have a look here under the pmx documentation for accepted regex&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.sophos.com/msg/pmx/help/en-us/msg/pmx/concepts/AdmDevRegex.html"&gt;https://docs.sophos.com/msg/pmx/help/en-us/msg/pmx/concepts/AdmDevRegex.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;some notes:&lt;/p&gt;
&lt;p&gt;**@**.com would drop all mail from any domain.com&lt;/p&gt;
&lt;p&gt;or **@subdomain.mydomain.com$&amp;nbsp; would mean it must end in this exact domain.&lt;/p&gt;
&lt;p&gt;* means 1 word.. ** means any number of words&lt;/p&gt;
&lt;p&gt;do NOT use sub-string matches with wild cards.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Report as Spam</title><link>https://community.sophos.com/thread/389729?ContentTypeID=1</link><pubDate>Fri, 16 Nov 2018 09:36:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e5c59c2f-d9d2-47c1-a0f9-81448b4f5245</guid><dc:creator>LRSpartan</dc:creator><description>&lt;p&gt;Hi RW!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I always appreciate your help! I think I am mis-communicating about our user&amp;#39;s experience. To us, spam is basically any email that we do not want. It is unsolicited, and therefore we do not want it. So what we call spam might not technically be spam or bulk as defined by the SEA.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Our old provider had the following categories they checked. If it was any of these, it quarantined or discarded them. Please don&amp;#39;t take this wrong, but we went from having maybe one or two emails per user per week come through that should have been stopped to now twenty or thirty a day per user.&lt;/p&gt;
&lt;table width="600"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td width="200"&gt;
&lt;p&gt;&lt;strong&gt;Types:&lt;/strong&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td width="200"&gt;
&lt;p&gt;&lt;strong&gt;VR&lt;/strong&gt;: Virus&lt;br /&gt; &lt;strong&gt;BC&lt;/strong&gt;: Blocked by Customer&lt;br /&gt; &lt;strong&gt;DM&lt;/strong&gt;: Direct Marketing&lt;br /&gt; &lt;strong&gt;FD&lt;/strong&gt;: Fraud&lt;/p&gt;
&lt;/td&gt;
&lt;td width="200"&gt;
&lt;p&gt;&lt;strong&gt;FG&lt;/strong&gt;: From a Foreign Domain&lt;br /&gt; &lt;strong&gt;LS&lt;/strong&gt;: List-Server&lt;br /&gt; &lt;strong&gt;NL&lt;/strong&gt;: Newsletter&lt;br /&gt; &lt;strong&gt;SP&lt;/strong&gt;: Spam&lt;/p&gt;
&lt;/td&gt;
&lt;td width="200"&gt;
&lt;p&gt;&lt;strong&gt;VA&lt;/strong&gt;: Virus Alert&lt;br /&gt; &lt;strong&gt;YG&lt;/strong&gt;: Yahoo Groups&lt;br /&gt; &lt;strong&gt;CL&lt;/strong&gt;: Chain Letter&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Then the second issue is even if we mark it as spam and don&amp;#39;t want to see it again, that is not happening automatically. I am having to go in to a rule and add each host name and I am doing that for our entire domain. So if someone wants some direct marketing material from some store but someone else has said it is spam, then the one wanting it will not get it. There is no easy automatic way to ban email at the user level. The web portal is to cumbersome on a good day.&lt;/p&gt;
&lt;p&gt;Example of rule that I have built for emails that we identify as spam. This is a manual process and impacts the entire domain. I suspect it will really hurt performance as it grows.&lt;/p&gt;
&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-discussions-components-files/12/pastedimage1542382478273v1.png"&gt;&lt;img src="/resized-image/__size/320x240/__key/communityserver-discussions-components-files/12/pastedimage1542382478273v1.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So that is my problem. We define spam differently and there is no easy automated way to block email. Yes, the RAS button removes the email, but it isn&amp;#39;t communicate back to our appliance and blocking it regardless if Sophos thinks it is spam or not. All to often, our users click the RAS and the emails keep pouring in. The web portal way to block is inefficient. Our old provider put a link at the bottom of the email if we wanted to block it. Click on it and it was blocked.&lt;/p&gt;
&lt;p&gt;We like some many other features of the SEA but blocking unwanted emails has become an issue for us. I figure there is much that can be done now, but I just wanted to make sure I wasn&amp;#39;t missing some feature that would be more like our old experience.&lt;/p&gt;
&lt;p&gt;Thank you,&lt;/p&gt;
&lt;p&gt;John&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Report as Spam</title><link>https://community.sophos.com/thread/389725?ContentTypeID=1</link><pubDate>Fri, 16 Nov 2018 08:49:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:e2dc7f1b-e5d6-4fc3-a587-1364ba1f5298</guid><dc:creator>Red_Warrior</dc:creator><description>&lt;p&gt;Hi John &lt;/p&gt;
&lt;p&gt;If you are deleting medium and high spam then what you are probally having issues with is bulk mail. &amp;nbsp;I would create a policy for bulk and set the action to tag subject or if you really wish delete.&lt;/p&gt;
&lt;p&gt;Please note that setting medium and bulk mail to delete is not recomended.&lt;/p&gt;
&lt;p&gt;In the case of the applaince , the only thing in your quarantine would be virus or if you have rules that quarantine mail.&lt;/p&gt;
&lt;p&gt;If you wish to install the outlook plugin that will gove you 1 touch spam submission and remove the message.. again tho if your deleting spam than chances are what is arriving is either not spam, bulkmail or unknown spam.&lt;/p&gt;
&lt;p&gt;If you are getting spam in thr inbox with it set to delete you may wish to ensure your settings match my kb on recomended spam settings .. other things that can cause fp or unidentified spam scores are pix mailguard, upstream load balancers and other ips products that block mta’s from connecting to the appliance.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://community.sophos.com/kb/en-us/120802"&gt;community.sophos.com/.../120802&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>