How To Detect Spam; Examining The Message Properties - IBM AH0QXML - Lotus Domino Messaging User Manual

User guide
Table of Contents

Advertisement

4.1 How to detect spam

As the Administrator, you will be tasked with determining what messages are
spam. Working closely with your end users, you will get a good idea of the
messages reaching the users' mail files.
But what about the messages that never make it to a user and wind up as,
depending on the configuration of your system, DEAD or HELD mail in mail.box?
Dead messages are messages that cannot route to the intended recipient and
cannot route back to the sender. Held messages are undelivered messages held
in mail.box instead of returning them to the sender. Often times, the address of
the sender appears to contain a valid Internet address and the same with the
name if the intended recipient. Viewing document properties, you can obtain
valuable information about each specific message. Each message contains
pertinent information about the sender, the intended recipient, the contents of the
message and the hosts that routed this message. Using the information found in
certain fields you can implement intended inbound recipient controls or even
deny connections from certain hostnames or IP addresses.

4.1.1 Examining the message properties

By analyzing the properties of a message and reviewing several key fields, you
can determine who the sender is, what servers processed this message, and
who the intended recipient is. The fields to examine are:
From: This is the address of the From: RFC822 header, if there was one
added to the message. The From: address is often different than the
SMTPOriginator on spam messages.
SMTPOriginator: This is the address of the sender; it is built from the value
of the MAIL FROM:
IntendedRecipient : This is who the message was originally sent to; often
times the address is invalid.
Recipients: This is the address of whomever the message should be routed
to.
Received: This header contains routing information and the names/IP
addresses of the SMTP servers that processed this message. All SMTP
servers that process this message are required to place a received header on
the message. It's not unusual to have a message that contains multiple
received headers.
To get the document properties of a message:
1. View the documents in mail.box (or mail1.box, mail2.box, and so forth).
30
Lotus Domino 6 spam Survival Guide for IBM eServer

Advertisement

Table of Contents
loading

This manual is also suitable for:

Lotus domino 6

Table of Contents