Collapse AllExpand All
  • about
    • anti-DoS [1]
    • digital certificates [1]
    • HTTPS inspection [1]
    • LDAP user identification [1]
    • Local user identification [1]
    • product license [1] [2]
    • security settings [1]
  • about product [1]
  • accounts
    • adding [1]
    • administrator, deleting [1]
  • action
  • action profiles [1]
  • activation code [1]
  • ActiveUpdate [1]
  • adding
    • accounts [1]
    • action profiles [1]
    • application objects [1]
    • bandwidth rules [1]
    • IPsec connections [1]
    • NAT rules [1] [2]
    • OSPF area [1]
    • policy rules [1] [2]
    • rules [1]
    • schedule objects [1]
    • service objects [1]
    • static route [1]
    • tabs [1]
    • user id policies [1]
    • VLAN subinterfaces [1]
    • VPN site-to-site policies [1]
  • address objects [1] [2] [3]
  • administration [1]
    • about [1]
    • language settings [1]
    • overview [1]
    • support [1]
    • system settings [1]
    • system settings, general [1]
  • administrator
    • accounts, deleting [1]
  • Administrator's Guide [1]
  • advanced
    • IPsec configuration [1]
  • advanced settings
  • Advanced Threat Scan Engine [1]
  • Advanced Threat Scan Engine (ATSE)
    • scan engine [1]
  • alerts:
    • notifications [1]
  • anti-DoS
    • about [1]
    • exceptions
    • flood protection
      • configuration [1]
  • anti-malware [1]
    • anti-malware profiles [1]
    • file extension [1]
  • anti-malware pattern files [1]
  • anti-malware protocol pattern files
    • pattern files
      • anti-malware protocol [1] [2]
  • anti-spam
    • anti-spam profiles [1]
    • security settings [1]
  • anti-spam profiles
    • configuring [1]
      • content settings [1]
    • disabling [1]
    • enabling [1]
    • modifying [1]
  • anti-spam protocol pattern files [1]
  • anti-virus pattern files [1]
  • application
  • application control
    • notifications [1]
  • application control notifications [1]
  • application objects [1]
  • approved list
  • area OSPF [1]
  • ATSE [1]
  • audit logs
  • authentication
    • captive portal [1]
    • LDAP, advanced [1]
    • LDAP, basic [1]
    • LDAP, configuring [1]
    • user [1]
  • authentication method
  • backup [1]
  • bandwidth control
    • network settings [1]
    • policy settings [1]
    • widgets [1]
  • bandwidth summary
  • best practices
  • blocked list
  • blocked URL
    • notifications [1]
  • blocked URL notifications [1]
  • bridge
  • CA [1] [2] [3]
  • cache server [1]
  • captive portal [1]
  • certificate authority
  • certificate failure notifications [1]
  • changing
    • NAT rules [1]
  • changing bridge settings [1]
  • client
    • SSL VPN, installation [1]
  • client certificate failure
    • notifications [1]
  • client certificate failure notifications [1]
  • clients
    • viewing mobile VPN [1]
    • viewing PPTP VPN [1]
    • viewing SSL VPN [1]
  • cloud-based services [1]
  • codes
    • routing table [1]
  • community [1]
  • components
  • component version [1]
  • configuring
    • address objects [1]
    • alerts for security violations [1] [2]
    • application control notifications [1]
    • blocked URL notifications [1]
    • bridge [1] [2]
    • captive portal [1]
    • console settings [1]
    • DDNS client [1]
    • deployment [1]
    • DNS forwarding [1]
    • file extension notifications [1]
    • IPS violation notifications [1]
    • LDAP, basic and advanced [1]
    • malware notifications [1]
    • notifications for scheduled updates [1] [2]
    • proxy settings [1]
    • routing [1]
    • server certificate failure notifications [1] [2]
    • SMTP notifications [1]
    • SSL VPN advanced settings [1]
    • SSL VPN IP address pools [1]
    • SSL VPN local networks [1]
    • system resource warnings [1]
    • system settings [1]
    • time and date settings [1]
    • URL filtering notifications [1]
    • user notifications [1]
    • WRS notifications [1]
    • zone objects [1]
  • configuring:
    • PPTP VPN general settings [1]
  • configuring general settings [1]
  • connections
  • console certificate [1]
  • console settings [1]
  • console timeout [1]
  • cryptography
  • custom
  • customizing
  • dashboard
  • DDNS
  • DDNS client [1]
  • dead peer detection [1]
  • debugging
  • debug mode
    • enabling PPTP VPN [1]
  • Deep Discovery Advisor [1]
    • about [1]
    • Virtual Analyzer [1]
  • deep packet inspection [1]
  • deleting
    • action profiles [1]
    • address objects [1]
    • administrative accounts [1]
    • application objects [1]
    • NAT rules [1]
    • OSPF area [1]
    • services objects [1]
    • static route [1]
    • tabs [1]
    • zone objects [1]
  • denial of service attack [1]
  • deployment
  • Deployment Guide [1]
  • Deployment Modes
    • Bridge mode [1]
    • Bridge Mode [1]
    • Monitoring mode [1]
    • Monitoring Mode [1]
    • Routing mode [1]
    • Routing Mode [1]
  • detection
    • dead peer [1]
  • devices
    • management, accounts [1]
  • DHCP
    • advanced settings [1]
    • interface configuration [1]
    • lease time [1]
    • modifying services [1]
    • modifying settings [1]
    • static mapping [1]
    • viewing services [1]
    • viewing settings [1]
  • DHCP services [1]
  • diagnosis
    • files [1]
    • trace traffic [1]
    • traffic tracing [1]
    • troubleshooting
      • traffic tracing [1]
  • diagnostic:
  • diagnostic files
    • generating [1]
  • diagnostics
    • about [1]
    • network packet capture [1]
    • packet capture [1]
  • digital certificates
    • about [1]
    • adding new [1]
    • certificate authority
    • changing status [1]
    • deleting [1]
    • managing [1]
    • viewing [1]
  • displaying
    • list of users [1]
  • DNS [1] [2]
    • configuring forwarding [1]
    • forwarding configuration [1]
    • forwarding settings [1]
  • DNS forwarding configuration [1]
  • DNS servers [1] [2]
  • documentation set [1]
  • DoS attack
    • ICMP/Ping flood [1]
    • TCP SYN flood [1]
    • UDP flood [1]
  • Downloading
    • product patches [1]
  • dynamic domain name system service [1]
  • dynamic source translation [1]
  • Dyn DNS [1]
  • editing
    • action profiles [1]
    • schedule objects [1]
  • editing interfaces [1]
  • Email Reputation
  • email reputation services [1]
  • email reputation technology [1]
  • enabling
  • encapsulated security payload
  • encryption level
  • End user
    • settings, global [1]
  • entity risk summary
  • error messages
  • example
    • IPsec NAT configuration [1]
    • IPsec office configuration [1]
    • site-to-site VPN [1] [2]
  • experience improvement
  • expiration
  • false positive [1]
  • file extension
    • notifications [1]
    • types to scan [1]
  • file extension notifications [1]
  • file extension verification [1]
  • FreeDNS [1]
  • general system settings [1]
  • generating
    • manual reports [1]
  • getting started
  • global log settings [1]
  • hardware monitor
  • HTTPS inspection
    • about [1]
    • adding exceptions [1]
    • settings [1]
  • ICMP [1]
  • IKE [1] [2]
  • IKE debugging [1]
  • incremental updates [1]
  • inline mode [1]
  • installing:
    • SSL VPN client [1]
  • integration
  • IntelliTrap [1]
  • interface
  • interface information
  • interfaces [1] [2]
  • Internet Key Exchange [1]
  • introductions
    • notifications [1]
  • IP address pools
  • IPS
    • about [1]
    • categories [1]
    • categories and actions [1]
    • instant message [1]
    • intrusion prevention system [1]
    • peer-to-peer [1]
    • policies [1]
    • profiles [1]
  • IPsec [1]
    • adding connections [1]
    • advanced configuration [1]
    • connections [1]
    • generate RSA key [1]
    • NAT configuration example [1]
    • office configuration example [1]
    • RSA key [1]
    • status [1]
    • troubleshooting [1]
  • IPS pattern files [1]
  • IPS violation
    • notifications [1]
  • IPS violation notifications [1]
  • IPv4 or IPv6 [1]
  • Knowledge Base [1]
  • known issues
  • language, change [1]
  • LDAP [1]
    • advanced authentication [1]
    • authentication method [1]
    • basic authentication [1]
    • configuring, basic and advanced [1]
    • integration [1]
    • method of user identification [1]
    • settings, global [1] [2]
  • LDAP user identification
  • lease time [1]
  • license [1] [2]
    • activation code [1]
    • expiration [1]
    • registration [1]
    • registration key [1]
    • updating [1]
  • local groups [1]
  • Local user identification
  • local users [1]
  • logs
    • about [1] [2]
    • audit, about [1]
    • introduction [1] [2]
    • querying [1]
    • querying audit logs [1]
    • querying system event logs [1]
    • querying VPN logs [1]
    • settings [1]
    • settings, global [1]
    • system events, about [1]
    • viewing PPTP VPN [1]
    • viewing SSL VPN [1]
    • VPN, about [1]
  • main features [1] [2] [3]
    • ActiveUpdate [1]
    • anti-spam [1]
    • application bandwidth monitoring [1]
    • Application Control [1]
    • LDAP integration [1]
    • logs [1]
    • Network Intrusion Protection [1]
    • reports [1]
    • security protection [1]
    • summary dashboard [1]
    • system notifications and alerts [1]
    • URL Filtering [1]
    • virus scanning [1]
    • Web Reputation [1]
  • maintaining updates [1]
  • maintenance [1]
  • Maintenance Agreement
  • malware
    • notifications [1]
  • malware notifications [1]
  • management
    • about [1]
    • device
    • enabling
      • management services [1]
    • service [1]
    • services, enabling [1]
    • SNMP [1]
  • manual reports [1]
    • generating [1]
  • manual updates [1] [2]
  • mobile VPN
    • viewing clients [1]
  • mode
  • modifying
    • DHCP settings [1]
    • NAT rules [1]
    • OSPF area [1]
    • OSPF interface [1]
    • passwords, user [1]
    • static route [1]
    • tabs [1]
  • monitoring mode [1]
  • NAT [1] [2]
    • adding rules [1] [2]
    • changing rule priorities [1]
    • deleting rules [1]
    • IPsec configuration [1]
    • modifying rules [1]
    • rules [1]
    • site-to-site VPN configuration [1]
  • network
    • bandwidth control [1]
    • configuring for SSL VPN [1]
  • Network Address Translation [1]
  • network configuration
    • interfaces [1]
  • network features [1]
    • bridge [1]
    • mobile virtual private network [1]
    • NAT [1]
    • routing [1]
    • services [1]
    • site-to-site virtual private network [1]
    • user virtual private network [1]
  • network information
  • network intrusion prevention [1]
  • network RIP settings [1]
  • next-generation firewall [1]
  • notification
    • SMTP, configuring [1]
  • notifications
    • alerts [1]
    • application control [1]
    • blocked URLs [1]
    • certificate failure [1]
    • configuring for security violations [1] [2]
    • file extension [1]
    • introduction [1]
    • IPS violation [1]
    • malware [1]
    • schedule updates, configuring [1] [2]
    • SMTP [1]
    • stopping [1]
      • notifications [1]
    • updates [1]
    • URL filtering [1]
    • user policies [1]
    • WRS [1]
  • objects
    • address [1] [2]
    • address parameters [1]
    • application objects [1]
    • policy [1]
    • schedule objects [1]
    • zone [1]
  • online
    • community [1]
  • Online Help [1]
  • open shortest path first [1]
  • OSPF [1]
    • adding area [1]
    • area [1]
    • deleting area [1]
    • enabling global settings [1]
    • enabling OSPF distribute route [1]
    • global [1]
    • interfaces [1]
    • modifying area [1]
    • modifying interface [1]
    • redistribute [1]
    • redistributing link-state advertisement [1]
    • router ID [1]
  • overview
    • advanced IPsec configuration [1]
    • DDNS [1]
    • DDNS status [1]
    • DNS interface configuration [1]
    • dynamic domain name system service [1]
    • dynamic route management [1]
    • global OSPF [1]
    • interfaces [1] [2]
    • NAT [1]
    • open shortest path first (OSPF) [1]
    • OSPF interfaces [1]
    • redistribute OSPF [1]
    • redistribute RIP settings [1]
    • remote access [1]
    • remote access for users [1]
    • routing information protocol (RIP) [1]
    • routing table [1]
    • services [1]
    • site-to-site VPN [1]
    • SSL VPN [1]
    • traffic [1]
    • user management [1]
    • VLANs [1]
    • VPN [1]
  • packet capture
    • components [1]
  • packet captures [1]
  • parameters [1]
    • address objects [1]
    • captive portal [1]
    • logs settings, global [1]
    • reports [1]
    • services objects [1]
  • password
    • users, modifying [1]
  • pattern files [1]
    • anti-spam protocol [1]
    • incremental updates [1]
    • IPS [1]
    • several on server [1]
    • virus [1]
  • pattern information [1]
  • ping
  • point-to-point tunneling VPN [1]
  • policies [1]
    • adding bandwidth rules [1]
    • adding rules [1]
    • adding VPN site-to-site [1]
    • addresses [1] [2]
    • address objects [1] [2]
    • bandwidth control [1]
    • enabling rules [1] [2]
    • how policies work [1] [2]
    • modifying IPS [1]
    • objects [1]
    • rules page [1] [2]
    • user id, adding [1]
    • user identification [1]
  • policy objects [1]
  • PPTP VPN [1]
    • advanced settings [1] [2]
    • enabling [1]
    • encryption level [1]
    • error messages [1]
    • overview [1]
    • troubleshooting [1]
    • viewing clients [1]
    • viewing logs [1]
  • product
    • administration [1]
    • license [1]
    • management, about [1]
    • version [1]
  • product license [1] [2]
  • product overview [1] [2]
  • product patches
    • Applying patches [1]
  • Product Patches
    • Backing up current configuration [1]
    • Downloading patch [1]
    • Restoring previous configurations [1]
  • profiles [1] [2] [3]
    • configuring WRS [1]
    • web reputation [1]
    • WRS [1]
  • program components
  • proxy [1]
  • proxy settings [1] [2]
    • configuring [1]
  • querying
    • audit logs [1]
    • system events logs [1]
    • VPN logs [1]
  • querying logs [1]
  • Quick Start Guide [1]
  • readme [1]
  • Readme [1]
  • redistributing OSFP [1]
  • redistribution
  • registering product [1]
  • registration
  • registration key [1]
  • remote access [1]
    • user management [1]
  • removing
    • schedule objects [1]
  • removing bridge settings [1]
  • reports [1]
    • about [1]
    • custom [1]
    • dashboard summary [1]
    • manual [1]
    • manual, generating [1]
    • parameters [1]
    • scheduled, about [1]
    • settings [1]
    • templates [1]
    • types [1]
  • report types [1]
  • restore
  • Restoring [1]
  • RIP [1]
    • advanced global settings [1]
    • configuring global settings [1]
    • deleting a RIP network [1]
    • enabling global settings [1]
    • global settings [1]
    • network setting [1]
    • redistribution [1]
  • RIP:
    • adding a network [1]
  • rolling back updates [1]
  • routing
    • dynamic route management [1]
    • settings [1]
    • static route management [1]
  • routing information protocol [1]
  • routing table
  • RSA key [1]
  • rules
    • adding NA [1] [2]
    • changing NAT priorities [1]
    • deleting NAT [1]
    • modifying NAT [1]
    • NAT [1]
  • rules page
  • scan engine
  • scanning
  • scheduled reports [1]
  • scheduled updates [1]
    • configuring notifications [1] [2]
  • schedule objects [1]
  • scheduling updates [1]
  • secure socket layer VPN [1]
  • security settings
  • security status
  • security violations
  • selecting
    • file extension scanning [1]
  • server certificate failure
    • notifications [1]
  • server certificate failure notifications [1]
  • service objects
  • services [1]
    • DNS forwarding configuration [1]
    • DNS forwarding settings [1]
    • management [1]
    • management, enabling [1]
  • services objects
  • session event summary
  • session summary
  • settings [1] [2]
    • console, about [1]
    • deployment [1]
    • DNS forwarding settings [1]
    • End user synchronization [1]
    • LDAP, global [1] [2]
    • logs [1]
    • logs, global [1]
    • network RIP [1] [2]
    • PPTP VPN general [1]
    • reports [1]
    • RIP redistribution [1]
    • SMTP notifications [1]
    • SSL VPN server [1]
  • shell
  • site-to-site VPN [1]
  • smart protection [1]
    • Web Reputation Services [1]
  • Smart Protection Network [1] [2] [3]
  • SMTP
    • notifications [1]
  • SNMP
  • SolutionBank
    • See Knowledge Base
  • spam detection [1]
  • spyware [1]
  • SSH
  • SSL VPN
    • configuring advanced settings [1]
    • configuring local network [1]
    • enabling [1]
    • installing client [1]
    • IP address pools [1]
    • overview [1]
    • server settings [1]
    • troubleshooting [1]
    • viewing clients [1]
    • viewing logs [1]
  • static mapping [1]
  • static routing
  • status
  • summary dashboard [1]
    • adding tabs [1]
    • deleting tabs [1]
    • modifying tabs [1]
    • tabs [1]
  • support [1]
    • knowledge base [1]
    • resolve issues faster [1]
    • TrendLabs [1]
  • SYN [1]
  • synchronous transmission (SYN) [1]
  • system
  • system alerts
    • notifications [1]
  • system events logs
  • system information
  • system maintenance [1]
  • system resources
  • system resource warnings [1]
  • system settings
  • tabs
  • TCP [1]
  • technical support [1]
  • templates
  • top applications
  • top devices protected by anti-spam
  • top domains
  • top entities protected by anti-spam
  • top entities protected by anti-virus
  • top entities protected by IPS
  • top entities protected by WRS
  • top URL categories
  • top users
  • traffic:routing [1]
  • traffic overview [1]
  • traffic status
  • traffic tracing [1]
  • transmission control protocol [1]
  • TrendEdge [1]
  • TrendLabs [1]
  • troubleshooting [1]
    • diagnosis [1]
    • packet capture [1]
    • PPTP VPN [1]
    • site-to-site VPN [1]
    • SSL VPN [1]
  • update
    • cache server [1]
  • updates [1]
    • anti-malware [1]
    • anti-malware protocol [1] [2]
    • anti-spam protocol [1]
    • anti-virus [1]
    • component version [1]
    • incremental [1]
    • maintaining [1]
    • manual [1] [2]
    • notifications [1]
    • program components [1]
    • proxy settings [1]
    • recommendations [1]
    • rolling back [1]
    • scheduled [1] [2]
    • scheduling [1]
    • verifying success [1]
  • updating
    • web console [1]
  • updating your license [1]
  • URL approved/blocked lists [1]
    • adding [1]
    • enabling/disabling [1]
  • URL database [1]
  • URL filtering [1]
    • notifications [1]
  • URL filtering notifications [1]
  • URLs
  • user
  • user authentication [1]
  • user datagram protocol [1]
  • user identification
  • user id policies
  • user management [1]
  • user notifications [1]
  • users
    • list of [1]
    • passwords, modifying [1]
  • verifying
    • file extension [1]
  • verifying updates [1]
  • viewing
    • action profiles [1] [2]
    • address objects [1]
    • application objects [1]
    • DHCP services [1]
    • DHCP settings [1]
    • list of users [1]
    • mobile VPN clients [1]
    • PPTP VPN clients [1]
    • PPTP VPN logs [1]
    • routing table [1]
    • service objects [1]
    • SSL VPN clients [1]
    • SSL VPN logs [1]
    • zone objects [1]
  • violation event status
  • virtual private network [1]
  • virus patterns [1]
  • Virus Scan Engine
    • scan engine [1]
  • virus scan engines [1]
  • VLANs [1]
    • adding subinterfaces [1]
  • VPN [1] [2] [3]
  • VPN logs
  • VPN on Demand [1]
  • VPN site-to-site
    • adding policies [1]
  • VPN tunnel
  • warnings
    • system resource, notifications [1]
  • web reputation [1]
    • profiles [1]
    • URL database [1]
  • web shell
  • widget
    • bandwidth summary [1]
    • pattern information [1]
    • top applications [1]
  • widgets [1]
    • about [1]
    • adding [1]
    • bandwidth control [1]
    • customizing [1] [2]
    • dashboard [1]
    • deleting [1]
    • description [1]
    • entity risk summary [1]
    • hardware monitor [1]
    • interface information [1]
    • network information [1]
    • pattern information [1]
    • security status [1]
    • session event summary [1]
    • session summary [1]
    • system information [1] [2]
    • system resources [1]
    • top devices protected by anti-spam [1]
    • top domains [1]
    • top entities protected by anti-spam [1] [2]
    • top entities protected by anti-virus [1]
    • top entities protected by IPS [1]
    • top entities protected by WRS [1]
    • top URL categories [1]
    • top users [1]
    • traffic status [1]
    • violation event status [1]
  • WRS
    • configuring profiles [1]
    • notifications [1]
    • profiles [1]
  • WRS notifications [1]
  • zone objects [1]
  • zones

Configuring Anti-Spam Settings Parent topic

Configure Deep Edge anti-spam settings to:
  • Use Email Reputation Services to determine spam based on the reputation of the originating MTA. With ERS enabled, all inbound SMTP and POP3 traffic is checked by the IP databases to see whether the originating IP address is clean or it has been blacklisted as a known spam vector.
  • Take default intelligent actions on spam or customize the actions setting for the organization
  • Create approved and blocked senders lists
  • Set the spam "sensitivity" level or catch rate
  • Define the tag used in the subject line of a spam email message

Procedure

  1. Go to PoliciesSecurity SettingsAnti-SpamAnti-Spam tab.
  2. Select Enable email reputation to enable ERS.
  3. Select the actions to take on detected spam email messages:
    1. Leave the Default intelligent action radio button selected for the following actions to be in affect:
      • Permanent denial of connection (550) for RBL+ matches
      • Temporary denial of connection (450) for Zombie matches
      Note
      Note
      When using the default intelligent action, spam messages are rejected at the MTA with a brief message.
    1. Click the Take customized action on all matches radio button to set the actions needed on spam email messages such as:
      • SMTP error code: Set a code between 400 to 599. The default error code is 450
      • SMTP error string: "Service unavailable" is the default string.
  4. Under Approved Senders, specify an email address and then click Add to approve the sender.
  5. Under Blocked Senders, specify an email address and then click Add to block the sender.
  6. Set the Anti-Spam Catch Rate (Sensitivity Level).
    • High: Catches more spam. Select a high catch rate if too much spam gets through to clients.
    • Medium: The standard setting (default)
    • Low: Catches less spam. Select a low catch rate if Deep Edge is tagging too many legitimate email messages as spam.
    Note
    Note
    If needed, adjust the anti-spam catch rate at a later time. If the threshold is too low, a high incidence of spam occurs. If the threshold is too high, a high incidence of false positives (legitimate messages that are identified as spam) occurs.
  7. Under Other Settings, change the subject line tag used to identify email messages detected as spam. The default is [Spam].
  8. Click OK to save the changes.