This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Anti-Spam Filtering Chinese Characters

I am wondering if there is a way to filter out spam that is making it to users inboxes, that has Chinese (or some Asian country's characters)?  We have been receiving so much of it lately, and none of it has top level designations of .cn, .hk, etc.  More or less the emails contain the following: 谢谢您的信賴與支持.  I have been unable to figure out a regex to block all this.



This thread was automatically locked due to age.
  • Please any help with this.... I am receiving these types of emails like crazy and they are not being blocked by Sophos because of all the foreign language writing characters.  Need a solution to blocking these emails for good.

  • Mike, show us the originating IP and subject for about a half-dozen.  You should be able to find them using Mail Manager.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Good Morning Bob,

     

      One unfortunate thing is that the originating IP addresses are the mailhop IP addresses (52.58.7.12054.148.229.97) that I use for all the email, at least what I am seeing in Mail Manager.  But I can easily provide subject lines.

    Re:administrator

     回复:administrator

    转发:生产计划与物料控制PMC

    Re:部门经理技能提升078

    回复:生产计划与物料控制282

    Re:如何从技术走向管理2010329481

    Re:怎样留驻核心人才737

     

    Thanks,

     

    Michael Mastro

     

  • I'd be tempted to change your MX record to point at your UTM directly as I doubt that Mailhop's anti-spam is any better than the UTM's.  Also, since I'm not seeing this problem with others, I wonder if you're "fooling" the SMTP Proxy into delivering those emails because they're coming from Mailhop.

    If you want to quarantine these emails, you could make some Expressions like 回, 与 and 生.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Good Evening Bob,

     

       I have created an expression for each of those characters.... well I hope that I created the expressions correctly.  I essentially put each of the characters on it's own line in the expressions box of the Anti-Spam tab.

       As for my MX records they point directly at my Exchange Servers, internal to the network, my MX record on DynDNS points to the Mailhop, but that is mainly because of the non-standard port configuration.  Everything else points to my UTM.  Not sure if I would receive email if I pointed it to the UTM instead of Mailhop.

     

    Thanks,

    Michael Mastro

  • I didn't follow your description of "my MX records" and "Everything else points to my UTM," so I can't be sure, but I've not seen a situation where an external service was necessary to get mail through the SMTP Proxy to Exchange.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA