This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Email Protection Best Practice

Hi community,

after playing with the settings I think spam filtering works pretty good right now on our XGv17 and I'd like to discuss the settings and set up something like a best practice. Especially the list of RBL services could be expanded.

Currently I work with the following settings:

 

-> General settings

SMTP Deployment Mode:

Device acts as a Mail Transfer Agent (MTA)

 

SMTP Settings:

Verify Sender’s IP Reputation: true

Confirm Spam Action: Drop

Probable Spam Action: Accept

 

Malware Protection:

Primary Anti-Virus Engine: Sophos

 

Advanced SMTP Settings

Reject invalid HELO or missing RDNS: true

Do strict RDNS checks: false

Scan Outgoing Mails: true

 

 

-> Policy

Spam Protection:

Check for Inbound Spam: true

Check for Virus Outbreak: false (don't know what it does)

Check for Outbound Spam: true

Use Greylisting: false (currently not working as it should with 17 MR5)

Check for RBL: true

Recipient Verification: With Callout

 

Malware Protection:

Scanning: Dual Anti-Virus

Selected Antivirus Action: Drop

Notify Sender: false

Quarantine unscannable content: true

Detect zero-day threats with Sandstorm: false (no licence)

 

File Protection:

currently off

 

Data Protection:

currently off

 

-> RBL Services

bl.spamcop.net

zen.spamhaus.org

dnsbl-1.uceprotect.net

 

-> RBL Services I wouldn't recommend (false positives)

dnsbl.sorbs.net



This thread was automatically locked due to age.
  • Gave strict RDNS checks a try during the last hours but even companies you would think of they know how to set up a mail system seem to have poorly configured systems.

    I'd have to spend hours of scanning mail logs and whitelisting their domains, so I turned it off again.

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.