Services Partners Contact Us About Help Support Blog Login

Presidents Blog


ExchangeDefender gets tougher on NDR and Backscatter
Posted: 10:34 am
June 14th, 2007
Post a comment
ExchangeDefender

Over the past year we have seen a steady increase in NDR traffic. We’ve done something about it previously but have since gotten far more aggressive on it to the point that virtually every fake bounce will be automatically quarantined.

It’s important to understand the motivation behind the spoofing and massive NDRs they produce. There are two ways in which spammers abuse the NDR system: one is to steal identity and the other is to diminish the confidence in the SPAM filtering solution. The first is quite easy, they want to use a legitimate sender address so that the remote servers will accept the mail. To combat this you can easilly enable SPF/SenderID on your domain and never worry about it. The second is a little more involved/contrived and involves systematically taking apart the ability of the “installed” SPAM filtering solution to adequately sort out mail. Most installed SPAM filtering solutions (the ones you install on your server) and appliances alike (that are devices on your network) build reputation models based on how often legitimate mail comes from certain addresses and IP blocks. They also build local bayesian databases that index known SPAM and non-SPAM; As such, by flooding the server with mail from all over the place those databases the reputation scores become increasingly less reliable – a process more commonly known as poisoning.

So what are we doing and how does it benefit you? Assuming you are using our outbound servers to relay messages, your messages will contain special tracking that will match up what we have in our internal databases. If an NDR is received with that tracking in tact, the message is allowed through. If the NDR is received without that tracking that means that the message didn’t come from you, from your server, that it was spoofed – and it adequately goes into the SPAM quarantine where you’ll likely let it die.

Own Web Now Blog

Own Web Now Corp blog is written by our staff to communicate with you, our customer, on the latest developments and events in our business and get feedback on how we're working for you.


News & Events

The best way to stay in touch with us is through our blog, but from time to time we do special things that we feel you might find interesting. Check them out!


OWN SPAM Show 15
Big in 2010, Karl, Erick and Vlad talk about 2009 and what they predict will contribute in a big way to IT business in 2010.

Alternative content




OWN SPAM Show 14
Managing your "humans" and turning them into resources with Karl, Vlad and special guest: Monique Rogers from CharTec.net. Learn how to successfully find, hire and motivate employees.

Alternative content




Become a Partner