IP
Profiler proactively identifies IP addresses of computers that send email messages
containing threats mentioned in the section About Sender Filtering. You
can customize several criteria that determine when IMSVA starts taking a specified action on an IP
address. The criteria differ depending on the potential threat, but commonly include
a
duration during which IMSVA monitors the IP address
and a threshold.
The following process takes place after IMSVA receives a connection request from a sending
mail server:
-
FoxProxy queries the IP Profiler's DNS server to see if the IP address is on the blocked list.
-
If the IP address is on the blocked list, IMSVA denies the connection request.If the IP address is not on the blocked list, IMSVA analyzes the email traffic according to the threshold criteria you specify for IP Profiler.
-
If the email traffic violates the criteria, IMSVA adds the sender IP address to the blocked list.
