Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


November 02, 2006

Going Live with Exchange 2007, Part 2

RSS
Subscribe to Windows IT Pro | See More Exchange Server and Outlook Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Last week, I started writing about my experience moving my (admittedly small) production Exchange environment to Exchange Server 2007 ("Going Live with Exchange 2007, Part 1," October 26, 2006, http://www.windowsitpro.com, InstantDoc ID 94029). I mentioned that I still had work to do on antispam protection. As shipped, Exchange 2007 does a better job blocking spam to my network than a basic Exchange 2003 installation with Microsoft Exchange Intelligent Message Filter, but it doesn't do as well as Vamsoft's ORF Enterprise Edition.

Shortly after submitting last week's column, I added some IP blacklist providers to my Exchange 2007 configuration. You might recall that the message protection and hygiene features in Exchange 2007 are implemented as a set of agents that run either on the Hub Transport or Edge Transport server. You use the Anti-spam tab of the server Properties page to adjust the properties used for the IP Block List Providers object; you can also adjust other properties, such as the settings used for sender and recipient filtering and for Sender ID.

I added two DNS blacklists: AbuseAT (http://cbl.abuseat.org) and Spamhaus (http://www.spamhaus.org/). There are many other popular services out there—why did I pick these two?

  • I chose AbuseAT because its Composite Blocking List records only hosts that have attempted to send messages in a way that indicates the host is infected or compromised.
  • I chose Spamhaus because it's a large, well-known service that combines two separate lists (SBL is a list of spammers; XBL is a list of compromised IP addresses from which viruses, worm traffic, or spam originates).

There are many other blacklists, some much more aggressive than others. For example, the Spam and Open-Relay Blocking System (SORBS) list includes large ranges of addresses that belong to dial-up ISPs, which shouldn't generally be sending SMTP mail. But it also includes large blocks of addresses assigned to cable-modem and DSL providers. Even though I have a business cable-modem account, if my local provider's IP address were to show up in SORBS, I'd have a hard time exchanging mail with the rest of the world. In my opinion, SORBS is a little too quick to block addresses, which is why I don't use this blacklist.

Choosing a blacklist is tricky; your best bet is to start with one or two list providers and see whether your spam level drops. I saw a dramatic decrease in the amount of spam reaching my servers after I added the AbuseAT and Spamhaus lists. I've gone from getting 15–20 spam messages per account per day to one or two, and I haven't found any false positives generated by the Realtime Blackhole Lists (RBLs). Your own mileage may vary, which is why it's important to test the RBLs you choose to ensure that they don't drop legitimate messages.

Next week, I'll be writing about the fall Microsoft Exchange Connections show—look for a report on what's new and cool on the show floor, as well as highlights of the keynotes and other presentations. If you're going to be in Las Vegas for the show, look for me Wednesday morning in session or throughout the show in the exhibit area.

End of Article



Reader Comments
Love the idea of having an Exchange server at home, for non-profit, non-commercial, educational purposes, hosting a few domains and gaining experience that way... Will Microsoft allow me to run say, an MSDN subscription version of Exchange for this purpose, without paying for the license?
(btw: I had to try five times before I got reproducable characters in the verification image below! A little strict, are we? :)

Snowdon November 07, 2006 (Article Rating: )


Yikes! I have no idea. As far as I know, the MSDN license is only good for non-commercial development use; I don't honestly know if you'd qualify or not. (and yes, I share your pain with the verification box-- sometimes it throws in non-ASCII characters for no good reason).

paulrobichaux November 13, 2006 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...


Related Articles Using the Microsoft Exchange 2007 Anti-Spam Migration Tool

Exchange Server and Outlook Whitepapers Email Controls and Regulatory Compliance

Take Control of Your Email: Understand the Business Reasons for Email Storage Management

Related Events Bail Out Your Exchange Environment

Continuous Application Virtualization: An Answer to Exchange Recovery Problems

Check out our list of Free Email Newsletters!

Exchange Server and Outlook eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

The Expert's Guide for Exchange 2003: Preparing for, Moving to, and Supporting Exchange Server 2003

Related Exchange Server and Outlook Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Exchange & Outlook UPDATE eNewsletter
News, strategies, products, and developments in Exchange Server and Outlook messaging.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement