Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Email Protection Best Practice

Hi community,

after playing with the settings I think spam filtering works pretty good right now on our XGv17 and I'd like to discuss the settings and set up something like a best practice. Especially the list of RBL services could be expanded.

Currently I work with the following settings:

 

-> General settings

SMTP Deployment Mode:

Device acts as a Mail Transfer Agent (MTA)

 

SMTP Settings:

Verify Sender’s IP Reputation: true

Confirm Spam Action: Drop

Probable Spam Action: Accept

 

Malware Protection:

Primary Anti-Virus Engine: Sophos

 

Advanced SMTP Settings

Reject invalid HELO or missing RDNS: true

Do strict RDNS checks: false

Scan Outgoing Mails: true

 

 

-> Policy

Spam Protection:

Check for Inbound Spam: true

Check for Virus Outbreak: false (don't know what it does)

Check for Outbound Spam: true

Use Greylisting: false (currently not working as it should with 17 MR5)

Check for RBL: true

Recipient Verification: With Callout

 

Malware Protection:

Scanning: Dual Anti-Virus

Selected Antivirus Action: Drop

Notify Sender: false

Quarantine unscannable content: true

Detect zero-day threats with Sandstorm: false (no licence)

 

File Protection:

currently off

 

Data Protection:

currently off

 

-> RBL Services

bl.spamcop.net

zen.spamhaus.org

dnsbl-1.uceprotect.net

 

-> RBL Services I wouldn't recommend (false positives)

dnsbl.sorbs.net



This thread was automatically locked due to age.
  • Gave strict RDNS checks a try during the last hours but even companies you would think of they know how to set up a mail system seem to have poorly configured systems.

    I'd have to spend hours of scanning mail logs and whitelisting their domains, so I turned it off again.

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.