Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2013, 12:24:37 AM

Login with username, password and session length

664096 Posts
70638 Topics
145272 Members

Latest Member: iqhancpu458

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Business / Enterprise Security Products & Services
| |-+  Comodo AntiSpam Gateway - Hosted Anti Spam Service
| | |-+  CASG Beta 1, Feedback!
« previous next »
Pages: 1 [2] 3 4 Go Down Print
Author Topic: CASG Beta 1, Feedback!  (Read 34158 times)
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #15 on: October 18, 2011, 12:45:28 PM »

Ive noticed that many incoming mail, just go straight to our mailserver, even not through CASG.
Why does this happen? Is very often that your mailservers are not reachable?

We have configured our mailservers with this priorities:
. mxsrv1.spamgateway.comodo.com (10)
. mxsrv2.spamgateway.comodo.com (20)
. mail.mydomain.com (30)

As you can see, our mailserver has the lowest priority.
So that means that whenever the first two mailservers (by comodo) dont respond, then our mailserver will process directly the messages.

We have received some spam that was directly sent through mail.mydomain.com.
How can this be avoided?
Logged
Kirill Nelinov
Comodo Member
**
Offline Offline

Posts: 30



« Reply #16 on: October 19, 2011, 05:59:57 AM »

We have received some spam that was directly sent through mail.mydomain.com.
How can this be avoided?

Hmm... I'm not sure yet how did happen. Let me ask you few questions:
Was it during some specific time period?
Do you still receive it?
Could you please send me source of the received spam message?

Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #17 on: October 19, 2011, 02:58:21 PM »

Thank you Kirill,

Ive just sent you 3 spam samples that we received directly bypassing CASG.
We keep getting some of them.

I couldnt send you any spam from today or yesterday because I always delete them.
The 3 samples I sent you through PM, are from another mailbox using the same domain.
Actually, you will have 4 PM with the "bypassed spam". Dont pay attention to the very first one, since it doesnt include the headers. The other 3 PM include their respective headers.

Should I keep posting latest spams that are bypassed?
« Last Edit: October 19, 2011, 06:01:54 PM by w-e-v » Logged
Kirill Nelinov
Comodo Member
**
Offline Offline

Posts: 30



« Reply #18 on: October 20, 2011, 10:06:48 AM »

Thanks, We are investigating.
Yes, please keep posting latest spams
Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #19 on: October 20, 2011, 10:23:15 AM »

Thanks, We are investigating.
Yes, please keep posting latest spams

Ok, I will keep posting them as soon as we receive them.

Now what about spam that has been through CASG and were 'caught-missed'?
Can I report those too via PM, or you have an email where can I attach these files?
Logged
Kirill Nelinov
Comodo Member
**
Offline Offline

Posts: 30



« Reply #20 on: October 20, 2011, 10:27:51 AM »

We are releasing new version soon, which will have this functionality in UI.
For now - yes please keep posted.
It would be great if you could mark it as 'caught-missed' and 'mx-skipped'
Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #21 on: October 20, 2011, 06:28:25 PM »

Hi,

I have 4 "caught-missed" and 1 "mx-skipped" from today, but I am not able to send the source through the forum because there is a limit of 4,000 characters. And well, apparently the characters in the SPAM samples are more than that.

What do you recommend?
« Last Edit: October 20, 2011, 06:32:36 PM by w-e-v » Logged
Kirill Nelinov
Comodo Member
**
Offline Offline

Posts: 30



« Reply #22 on: October 21, 2011, 07:45:39 AM »

Ok.
We've checked and looks like there where no connectivity issues with our servers.

It means that "mx-skipped" messages where sent directly to your server.
This is possible until you have mail.yourdomain.com as the third MX server.
Spammers also has access to MX and may send spam directly to the third or to all servers in MX.
So if you want to completely avoid this type of spam - remove mail.yourdomain.com from MX.

As for "caught-missed" I think it is better to wait two weeks for a new version.
Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #23 on: October 21, 2011, 09:57:05 AM »

It means that "mx-skipped" messages where sent directly to your server.
This is possible until you have mail.yourdomain.com as the third MX server.
Spammers also has access to MX and may send spam directly to the third or to all servers in MX.
Thats what I thought. It makes lots of sense. Thank you Kirill.

So if you want to completely avoid this type of spam - remove mail.yourdomain.com from MX.
I understand your suggestion, and thats something I thought before on doing in order to avoid CASG to be bypassed. However, I didnt delete it, because mail.mydomain.com is the final mail server destination route in the 'Destination routes' field of CASG UI. This is where the mails are delivered from CASG after appropriate filtering of mails.

Thats the reason why I didnt delete mail.mydomain.com from my MX records list.

What can we do in this case?

As for "caught-missed" I think it is better to wait two weeks for a new version.
Ok, I cant wait until the new release!
Logged
Kirill Nelinov
Comodo Member
**
Offline Offline

Posts: 30



« Reply #24 on: October 21, 2011, 10:15:01 AM »

because mail.mydomain.com is the final mail server destination route in the 'Destination routes' field of CASG UI.

Ah, let me explain.
Routes should contain exactly the same records as you had in MX before CASG.
We will use these routes to send messages that had passed filters.
And strictly saying your new MX should not contain old destination servers, only mxsrv*.

However here you have choice:
1) Set MX as you did to be completely sure that mail will be delivered even if our network segment (with mxsrv*) is unavailable which is not likely as it is located in US.
2) Remove your destination servers from MX and be fully protected.
« Last Edit: October 21, 2011, 10:17:42 AM by Kirill Nelinov » Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #25 on: October 21, 2011, 10:23:23 AM »

However here you have choice:
1) Set MX as you did to be completely sure that mail will be delivered even if our network segment (with mxsrv*) is unavailable which is not likely as it is located in US.
2) Remove your destination servers from MX and be fully protected.
I completely understand, and I definitely want choice No. 2.
But what I dont understand is, that if I "remove my destination servers from MX", that means mail.mydomain.com will not exist anymore. How can CASG deliver the messages that where filtered to our servers if mail.mydomain.com doesnt exist anymore?
Logged
Kirill Nelinov
Comodo Member
**
Offline Offline

Posts: 30



« Reply #26 on: October 21, 2011, 10:26:10 AM »

CASG will deliver taking destination not from MX but from routes you enter in CASG UI
Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #27 on: October 21, 2011, 10:32:59 AM »

So actually the destination route in CASG UI (which right now I have configured is mail.mydomain.com) its only used by CASG to resolve the IP and forward messages to that IP through the port configured, am I right?

I thought that the destination route in CASG UI was and should be the MX record from the server.
Logged
Kirill Nelinov
Comodo Member
**
Offline Offline

Posts: 30



« Reply #28 on: October 21, 2011, 11:10:54 AM »

So actually the destination route in CASG UI (which right now I have configured is mail.mydomain.com) its only used by CASG to resolve the IP and forward messages to that IP through the port configured, am I right?
Yes

I thought that the destination route in CASG UI was and should be the MX record from the server.
Should be the old (original) MX record
Logged
w-e-v
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1087


BETA FORCE MEMBER


« Reply #29 on: October 21, 2011, 11:13:49 AM »

Great! Thanks Kirill for your help and vital information.

I already made the changes and deleted the MX record for mail.mydomain.com
Now there should be no more direct spamming! Cheesy

Hopefully I did everything in the right way.
I just hope not to loose messages that people send us.

I will let you know how it goes with the new changes. Thanks again!
Logged
Tags:
Pages: 1 [2] 3 4 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.055 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com