ExchangeDefender 5 Deployment Guide
Introduction
The purpose of this guide is to familiarize you with ExchangeDefender and walk you through the configuration, management and deployment of the service. ExchangeDefender is a transparent, cloud based security solution that protects users from email SPAM, viruses and even dangerous content on the web. In addition to the security, ExchangeDefender also includes LiveArchive, a business continuity solution as well as a long term archiving solution for HIPAA / SOX / SEC compliance and eDiscovery. Furthermore, ExchangeDefender also has transparent SMTP encryption, web file sharing, desktop tools and more to protect all corporate communication and collaboration activities on the Internet.
You can find more information about the service at http://www.exchangedefender.com
Checklist
In order to deploy ExchangeDefender and safely secure the mail server and individual users you need to have access to the following:
- Domain Name (DNS) control - Because ExchangeDefender SMTP Security is activated by pointing the domain's mail exchanger (MX) record to inbound30.exchangedefender.com you must have the ability to change the DNS.
- Mail Server Administrative access - Hackers and spammers can bypass ExchangeDefender if the mail server remains exposed to anonymous SMTP traffic. Furthermore, some data such as Active Directory (LDAP) access can only be accessed from the mail server. Finally, you will have to disable some built in antispam software that will interfere with the delivery of SPAM reports.
- Firewall access - You will need to make certain changes to the network access, such as blocking anonymous SMTP connections from the Internet unless they come from the ExchangeDefender IP ranges, and blocking internal SMTP connections to the external servers in case your network is compromised.
- Desktop (Administrative User) access - If you wish to deploy ExchangeDefender Outlook Addin, ExchangeDefender Desktop Agent or ExchangeDefender Web Security agents, you will need to have administrative access to the desktop in order to install software on the local system. We also recommend creation of several shortcuts on the users' Desktop so they can quickly locate ExchangeDefender resources when they need them.
- Network Configuration - You will need to know the IP address that the clients mail server is currently using and you must be able to accept mail on port 25 (while ExchangeDefender can deliver mail to ports other than 25, advanced configurations are beyond the scope of this guide).
- Business Requirements - You will need to make business related decisions about which features of ExchangeDefender will be enabled or disabled, when you would like to receive daily or intraday SPAM reports, whether or not you wish to enable LiveArchive business continuity, which passwords to assign to the new users and the contact information for the IT or contact person in the organization.
Service Provisioning
ExchangeDefender Service enrollment is a four step process through which you will be adding and configuring a new domain and it's users to the service. In the first step, you will be choosing how you wish to provide the user lists to ExchangeDefender. In the second step, you will be approving the domains that are about to be protected by ExchangeDefender. In the third step you will be reviewing email addresses and display names. Finally, you will be providing the service configuration and site specific policies for the new organization.
Creating Users: How to pick the right method
ExchangeDefender offers three ways to create user accounts and import email addresses that will be protected by ExchangeDefender. Please review the following information carefully before selecting one.
- XML Import - This method is recommended for smaller sites running Microsoft Exchange mail servers. If you choose this method you will be downloading a Visual Basic Script (.vbs) that will export Active Directory mail-enabled user objects in an XML file that you can upload to ExchangeDefender. All users and associated display names and email addresses will be imported.
- Manual Configuration - This method is recommended for smaller sites and servers that are not running Microsoft Exchange and do not have an LDAP directory. Manual Configuration allows you to use a wizard import tool to type in users names and email addresses directly into ExchangeDefender.
- XDSYNC LDAP tool for ExchangeDefender - This method is recommended for larger deployments of Microsoft Exchange, or environments with high user turnover. By installing XDSYNC LDAP tool on your Microsoft Exchange server you will be assured that all changes to your mail-enabled Active Directory users will be applied to ExchangeDefender, removing any maintenance and user management of ExchangeDefender or double data entry.
Service Enrollment
Protecting a domain with ExchangeDefender is quick and simple. First, let's get the list of users to add to ExchangeDefender.
1. To start the process please login as the Service Provider at https://admin.exchangedefender.com. Click on the Management tab and then on the New User Wizard:

2. Select how you wish to create your users:

If you wish to type in the accounts manually, or if you wish to use the XDSYNC LDAP tool for ExchangeDefender, select "Type in accounts manually." And skip to step #4.
If you wish to use the XML Dump script, which we recommend, please download the script from the screen above and proceed to step #3.
3. If you have chosen to use the XML Dump script (Visual Basic) please download it to your Microsoft Exchange server and execute it at the command prompt as follows:
cscript ExportAddresses.vbs
This script will create an XML file that you will have to upload to the screen above. The file is C:\EmailAddresses.xml
Click on Upload and when the file is confirmed, click on Next. Proceed to step #4.
4. In this step you will be asked to provide the domain names that will be protected on this server. Type them in and click on Add to validate. If you imported an XML file, the system will already list the domain names it has identified in the XML file. If there are any problems with the domain (such as invalid domain or a domain that is already protected by ExchangeDefender) they will show in the top "Conflict" section.
5. In this step we will confirm that our users are listed correctly.

You can add users to this list manually by typing in the users name and email address in the form on the bottom and clicking Add. Each user and alias will show up and you can add, remove or delete aliases or users from this list in realtime.
Note: If you are using XDSYNC LDAP tool, you should only add the Administrator account here. The rest of the users will be uploaded automatically by XDSYNC.
6. Finally, let's configure the domain policies.

|
Users Password - Please select the default password that will be assigned to the accounts you are about to create. Users can change this password at any time. Administrator - Administrator is typically the IT contact person at the organization and the users on whose behalf all welcome messages are sent to the users. Note: The password assigned here is the domain password that the site administrator can use to login to admin.exchangedefender.com and manage all the user and domain configurations. Inbound IP Address - This is the IP address to which we will deliver all inbound mail. If you have a complex inbound network and wish to load balance the delivery across multiple servers or create a failover scenario, click on Advanced Settings. Outbound IP Address - This is the IP address from which we will accept outbound mail. If you have more than one IP address please provide it under Advanced Settings. Note: Typically the inbound and outbound IP address are the same. SPAM Action - What should we do with SPAM messages? We recommend to quarantine them. SureSPAM Action - What should we do with SureSPAM messages? We recommend to delete them. SPAM Life - How long should we keep the SPAM messages in the quarantine? By default we only keep 7 days meaning the user can release any quarantined SPAM messages received over the past seven days. Around holidays it makes sense to extend this period if staff takes longer vacations. Note: We do not recommend changing this interval. Doing so causes exponential performance degradation because the database is larger and queries run exponentially slower. Report Options - Choose if you want to enable Daily or Intraday SPAM digest reports. We recommend disabling these reports and relying on the portal, Outlook Addin or Desktop agent. Report Schedule - If you have enabled the SPAM digest reports, pick the time at which you would like to have them generated. It takes up to 30 minutes for the report to be generated so please keep in mind that this setting only controls when the report is scheduled to be processed, not when it will be delivered. Report Contents - Report Contents allow users that have a lot of email addresses to not report email addresses that have no SPAM in the quarantine. Enabling this removes pages of "No SPAM Quarantined" in the report and reduces the report size. Time Zone - Time zone in which the clients server is located. LiveArchive - Select to enable or disable LiveArchive Business Continuity. If you choose to enable this solution, each user must login to their account when the domain is created in order to initialize the mailbox. |
7. Congratulations, you have enabled ExchangeDefender SMTP Security protection on your domain. Please allow for up to an hour for the new configuration to propagate to all of ExchangeDefender servers and proceed to the next section on configuring your infrastructure. If you've chosen to create users using XDSYNC LDAP tool for ExchangeDefender, please refer to this document now.
Network Configuration
In order to properly deploy ExchangeDefender, you need to make several changes on your network. First, you have to change your MX record to point all of your inbound mail to ExchangeDefender. This way ExchangeDefender will stand in front of your mail server and bounce all the dangerous content that is sent to your network. Then, you should change your outbound smarthost to allow us to scan all of your outbound mail. Finally, enforce IP restrictions so that you can only exchange mail through a trusted connection with ExchangeDefender.
MX Record
Please modify your MX record and change it to: inbound30.exchangedefender.com
You should not have any other MX records for your domain name (subdomain MX records are OK).
Outbound SmartHost
Please modify your SMTP server to route all outbound mail through the following smarthost: outbound.exchangedefender.com
Please follow these instructions to modify the smarthost on Exchange 2003 and 2007:
Exchange 2007
1. Login as the Administrative user to your Exchange 2007 server and open Exchange Management Console.

2. Expand Organizational Configuration, click Hub Transport.

3. On the right hand side under Actions click New Send Connector.

4. Give the Send Connector a name and select the intended use as Custom.

5. Click the Add button on the Address Space screen.
6. Under Address put the recipient domain name, check include all sub-domains and leave the cost as low as possible, click OK.

7. Click Next.

8. Select the radio button to "Route mail through the follow smart hosts:" and click Add.

9. Select the radio button to "Fully qualified domain name (FQDN):" and enter "outbound.exchangedefender.com" and click OK.

10. At this point, you should be able to see the server you specified listed then click Next.

11. Since ExchangeDefender uses your server's IP Address to authenticate access, leave the radio button set to Authentication Settings "None" and click Next.

12. On the source server screen verify that the exchange server is listed (If not, click Add and find the server) and then click Next

13. On the final screen you will see the commands that will be run to create the send connector. Click New and on then Finish
Exchange 2003
1. Login to your Exchange 2003 server and open System Manager.

2. Expand Connectors , right click SmallBusiness SMTP Connector (or your active outgoing SMTP connector) and select properties.

3. In the general tab, set the radio option to Forward all mail through this connector to the following smart hosts and input outbound.exchangedefender.com

4. Navigate to the Address Space tab and ensure there is one entry with the address specified as * and the Cost as 1.

IP Restrictions
Enforcing IP restrictions is absolutely critical to complete protection of your mail server. Because hackers and spammers can easily bypass cloud services and target your server directly, mail servers protected by ExchangeDefender should accept anonymous SMTP connections only from the ExchangeDefender networks listed below:
65.99.255.0/24
64.182.140.0/24
You should allow inbound SMTP traffic from the above IP ranges only and deny all other traffic. You should only allow outbound SMTP traffic from your mail server to the ExchangeDefender outbound servers.
Please follow these instructions to enforce IP restrictions on Exchange 2003 and 2007:
Exchange 2007:
To program the IP address restrictions on the receive connector in Exchange 2007:
1. Obtain the latest list of ExchangeDefender IPs from the ExchangeDefender Deployment Guide under 'Configuring IP Restrictions'
2. Open Exchange Management Console

3. Expand Server Configuration, click Hub Transport

4. SBS Users: Right click on the "SBS Internet Mail Connector" and select Properties
NON-SBS Users: Right click on "Default SERVERNAME" and select "Properties".

5. Once the dialog box pops up select the "Network" tab:

6. Under "Receive mail from remote servers that have these addresses:" find the entry that says 0.0.0.0-255.255.255.0 and delete the record.
7. Under "Receive mail from remote servers that have these addresses:" click Add. Input the first ExchangeDefender IP range/netmask. Repeat this step for each ExchangeDefender IP network in the deployment guide.

Exchange 2003:
1. Obtain the latest list of ExchangeDefender IPs from the ExchangeDefender Deployment Guide under 'Configuring IP Restrictions'
2. Login to your Exchange 2003 server and open System Manager

3. Expand Servers, ServerName, Protocols, SMTP - right click "Default SMTP Virtual Server" (Or the active receive connector name) and select properties

4. Navigate to the Access tab and then select the Connection button.

5. Remove any entries from previous providers or entries that have the IP range 0.0.0.0 - 255.255.255.0
6. Click Add to enter a new IP restriction. Select the Group of computers option, insert the first IP range for ExchangeDefender and set the subnet mask to 255.255.255.0 - click OK. Repeat this step for each ExchangeDefender network.

7. Restart the Simple Mail Transfer Protocol (SMTP) service to apply the changes.
Warning: Do not enforce IP restrictions until at least 72 hours after the MX record change. Enforcing IP restrictions while your old DNS zone is still cached on the Internet will result in a permanent mail loss and mail delays.
Should the IP restrictions be applied on the firewall or on the mail server? We are frequently asked this question and the answer depends on whether you have external users or third parties attempting to relay mail through your mail server. If you have external connections to your SMTP server (from third party vendors or mobile users) then it is easier to enforce restrictions on the mail server and enforce password protected SMTP access there. However, if you do not have external connections the restrictions should be enforced on the firewall in order to free up resources on the mail server.
Install Client Desktop Software
Own Web Now Corp recommends deployment of Client Software Suite solutions over email Daily and Intraday digest reports for several reasons:
- Over 99% of all email SPAM reports are ignored or filtered to junk mail.
- Outlook and Desktop addins allow for realtime access to SPAM quarantines and settings.
- Client Desktop solutions work the way users do, in the applications they use.
- Client Desktop solutions are interruptive, they alert the users when necessary.
ExchangeDefender Client Software Suite was designed to give the user a more familiar experience, closely tied to the way they access their email and messaging. Outlook 2007 addin is perfect for Outlook power-users that never want to leave their Outlook experience. Similarly, Windows Desktop agent "annoyarizer" was designed for sales professionals, travel agents, financial industry employees and anyone that needs frequent alerts telling them that SPAM has been blocked from their inbox.
For more information about Client Software Suite please see the following page:
http://www.exchangedefender.com/features_client_software.php
Documentation, branding and deployment instructions are available in the individual downloads.
Advanced Deployment Considerations
ExchangeDefender is a very flexible security solution and we encourage our more technically advanced partners to use ExchangeDefender to improve reliability and failover of their own sites with ExchangeDefender's help. Here are several Knowledge Base articles we recommend often:
Would you like to be emailed when updates and additions are made to the university content?
Email:
Knowledge Base articles for this product:
There are no intentions to ever bring this feature to a supported ExchangeDefender configuration. The complete answer is a little more technical and a little more involved than meets the eye. ExchangeDefender has full support for multihomed environments, be it over BGP4 routing or just multiple IP ranges with a load balancing or failover router. Truth is, we can route to a hostname or we can route to a Static IP address, which you can manually change using the control panel and have it propagate in less than 30 minutes. The situation is a little more involved than that. Because of the amount of traffic, ExchangeDefender automatically caches name lookups and assigns them an hour long TTL (3600 seconds)- meaning that if we were to route to a dynamic hostname, that lookup would expire in an hour automatically, even if your IP changed more often than that and even if you had a lower TTL than that. This is where the Dynamic DNS solution falls apart. When there are problems, there exists an inverse relationship between the importance of email and the amount of money the company is willing to spend to obtain a static IP address. When the setup happens, email is not critical and a business line connection with a static IP allocation is out of the question. When the email stops, for whatever reason, the company calls with $8.3 billion on the line threatening to sue if the mail is not restored 5 minutes before they noticed it went down. This is the reason why Own Web Now Corp officially does not support Dynamic DNS routing. Will it, technically, work without a problem? Perhaps, but we will not offer support or assistance if it does not.
|
|||
Note: Admins, please remember that even if you have a setting you’re using as default at the domain level an individual user can use their access to override their setting. In order to access this setting please go to your domain’s “Configuration” panel by clicking on configuration and setting the “SPAM Action” setting to quarantine for all users as show below:
|
|||
|
|||
In order to ensure that you receive your OOF messages please whitelist the IP address of your Exchange 2007 server. You can do this by adding this IP address in the same field as you would when adding an email address to your whitelist.
|
|||
In order to further troubleshoot please ensure that no other anti-SPAM solution exists in your network and turn on your Exchange server’s message tracking and turn on logs. If you need assistance enabling message tracking please view the Microsoft TechNet article below: http://technet.microsoft.com/en-us/library/bb124375.aspx
|
|||
|
|||
Deployment documentation is available here: http://www.exchangedefender.com/support_deployment_guide.php |
|||
Troubleshooting information is available here: http://www.exchangedefender.com/support_troubleshooting.php |
|||
Please remove all other MX records from the list, only leaving inbound30.exchangedefender.com in the listing. Please do not attempt to mask this URL, point a CNAME to it, replicate the IP allocation list or in any way type in anything other than inbound30.exchangedefender.com. Because of many DNS complications over the years, our support staff is instructed not to offer support if the above DNS configuration is not in place. The outbound smarthost for ExchangeDefender is always: outbound.exchangedefender.com. The server authentication is IP based, allowing relay permissions based on the IP address assigned to your mail server. There is no additional authentication required. |
|||
You should never set your Intraday report to run before your Daily report. It is important to note that the times that you configure in the ExchangeDefender administrative portal are the times for which the report is to be generated. For example, if you select to receive a report generated for 4:00 AM, you will receive the past 24 hours worth of email, from 4:00 AM from the previous day to the 4:00 AM today. The report will be generated and sent to you. It can take an hour or more for reports to get generated, so if you are trying to receive a report at a certain time, make sure you set the interval at least a few hours in advance. If you continue to experience problems with SPAM reports, please switch to the ExchangeDefender Client Software Suite http://www.exchangedefender.com/features_client_software.php or use the realtime admin portal at https://admin.exchangedefender.com |
|||
If you have a ExchangeDefender Service Provider account, you can add alias domains without contacting OWN -- just select add alias under Management in your control panel. Note: This is not a technical limitation of the product. It is a limitation we were forced to put in place in order to protect partners that were not reading the prompts. We experienced so many cases in which people tried to use a single ExchangeDefender account to serve multiple customers and in turn caused huge privacy and legal issues for their customers (each ExchangeDefender account is mapped to a single IP or single MX record), that we were forced to pull the feature from the product to protect our customers. |
|||
Because ExchangeDefender is the delivery agent, it will be the one to echo back any errors it sees during the SMTP conversation. For example, you may see an error message such as this: < outbound.exchangedefender.com # 5.5.2 SMTP; 500 Unable to relay > or < outbound.exchangedefender.com # 5.5.2 SMTP; 500 User not found > If you receive errors such as this one, please keep in mind that it is not ExchangeDefender that is causing these problems. It is simply echoing back the response outbound.exchangedefender.com got when it connected to the remote server to deliver the message. Note: Because these response codes are issued by the remote mail servers that we have no control over, we do not offer assistance or technical support when these issues come up. If you do experience the error, contact the remote mail server administrator. |
|||
ExchangeDefender can deliver inbound mail to a static IP address or perform an MX lookup and deliver to the first available server. We support secure TLS delivery to both IPv4 and IPv6 addresses. |
|||
If you are having problems with outbound delivery, please follow the steps on pages 3-6 from your mail server. If you need our assistance, please paste in the contents of the telnet session from page 4-5 into a support request in our support portal If you are having problems with inbound delivery, please consult the sending party to follow the steps on pages 7-11. If you need our assistance, please paste in the contents of the telnet session from page 5 into a support request in our support portal Important notes:
|
|||
For the location of the item type in: https://admin.exchangedefender.com/login.php?username=MYEMAIL&password=MYPASSWORD Replace MYEMAIL with your email address and MYPASSWORD with your password. **Click Next**.You will be prompted for the name of the shortcut. This can be anything, for example, **My SPAM**. **Click Finish**. You are done. This shortcut will now automatically log you into the ExchangeDefender portal at anytime for realtime, searchable and manageable SPAM quarantine and protection service. The same process can be followed for LiveArchive business continuity. |
|||
cn: Joe User Just provide all the users and we can activate them all automatically, create their accounts and send them welcome emails. If you just type random text in the SMTP dump text area to bypass the form validation, your domain name will be locked to valid recipients only. In that case, we will only relay users and SMTP aliases known to ExchangeDefender or, in other words, ones that you have explicitly added to ExchangeDefender as users and aliases. |
|||
During this time period, you should point the MX record at inbound30.exchangedefender.com anyway, so all of the mail sent to the domain will be delivered to the target mail server. (Even though the accounts don't technically exist yet, all of the mail sent through the system is logged and available to the users once the accounts are created. Even if the mail was received before the user account was created, they will be able to see / audit / review / deliver the message.) |
|||
|
|||
We often see Microsoft IMF (Microsoft Exchange component) either bouncing or discarding reports and even Microsoft Outlook moving our SPAM reports directly to junk. If you have IMF running, please disable it. If you have Outlook on your desktop, please add quarantine@exchangedefender.com to your Safe Senders list. To do so, click on Tools > Options > Junk E-mail > Safe Senders > Add and enter our email address. If none of the above works, check your ExchangeDefender configuration and make sure that the SPAM settings are configured to Quarantine and the reports are sent to Send Daily Report. If your mail rules are to "deliver" or "delete" SPAM messages, you will not be receiving a report because no email was quarantined so there is no SPAM to report.
|
|||
Incoming mail is bounced with the error "Insufficient system resources" or sent messages are stuck in the drafts folder in Outlook.
Incoming mail bouncing with "Insufficient system resources" or sent messages staying in the Drafts folder are common symptoms when an Exchange 2007 server is experiencing Back Pressure. Back Pressure was introduced in Exchange 2007 with the purpose of monitoring certain Exchange 2007 resources such as free space on the disk, memory usage, etc. and reacts with solutions based on status of the queue.
Normal Medium High
Typically when messages are bounced with "Insufficient System Resources" or messages get stuck in the drafts folder, the Exchange 2007 server is experiencing high backpressure which prevents any new messages from being accepted.
To confirm if Back Pressure is being applied you can telnet to port 25 on the server and if you see "4.3.1 Insufficient system resources" then the server is experiencing back pressure.
Experienced administrators can use the following article for setting the threshold values for Back Pressure monitoring Microsoft recommends leaving Back Pressure enabled on production servers, however, if you are uncomfortable adjusting the values and/or would rather disable the monitoring, you can disable Back Pressure through the edge transport config. 1. Navigate to your Exchange bin directory in Windows Explorer (eg, C:\Program Files\Microsoft\Exchange Server\bin) 2. Open EdgeTransport.exe.config in notepad 3. Search for the key EnableResourceMonitoring and set the value to false 4. Save the config file and restart the Microsoft Hub Transport service.
|
|||
A sample rejection would look like this:
Since this is an automated system, Yahoo does not offer a system to “delist” a domain from this feature. This system works under the assumption that a legitimate sender (like us) will reattempt delivery and a spammer will not. Therefore, please rest assured that your email will be delivered as soon as Yahoo allows it. To review Yahoo.com’s help topic on this issue please click on the link below: http://help.yahoo.com/l/us/yahoo/mail/postmaster/errors/421-ts01.html If you’d like additional information about “Greylisting” please click on the link below: http://en.wikipedia.org/wiki/Greylist
|
|||
If you have ExchangeDefender LiveArchive enabled on your account you can retrieve your messages through https://livearchive.exchangedefender.com Note: Sometimes we may be able to deliver the message that was released from the SPAM quarantine. Doing so requires a lot of work and permissions to break encryption for your company. This process requires paperwork, legal approval and at least 2 hours of engineers’ time so, unless the message was absolutely critical, it tends not to be financially worthwhile.
|
|||
You will only see messages sent or received by your email address after the LiveArchive feature has been enabled. |
|||
The requirement for the deployment of ExchangeDefender is that all antiSPAM tools be shut off. Otherwise, messages that we have quarantined will likely end up in the third party filters as well. Unlike antivirus, a layered antiSPAM approach does not work. |
|||
In Exchange and other SMTP environments, it is the recipient’s server that splits the recipients and delivers messages and alerts to their target users. Furthermore, Exchange implements a process called “Single Instance Storage” where a message is stored once in the email database even if it is being sent to multiple users (in order to conserve space). Note: In almost all instances, the Outlook 2003 / 2007 client had moved the message to junk. In other instances, users actually deleted the message accidentally and didn’t want to admit to it. |
|||
This business request is made by customers who wish to implement split/domain policies where mail for certain groups of users goes to one server and others to another. Split domains are implemented at the mail server level, not at the proxy/ExchangeDefender SMTP security level. You can still have split domains, but one of your mail servers will have to be the bridgehead. |
|||
There are instances in which we will not be able to remove the email address from an RBL. Our policy on RBL removals is that we will make the best attempt to delist the account, but we cannot guarantee that the removal will take place nor do we have any timeline. Sometimes cable and DSL providers have issues with their RBL / DNS systems. Sometimes the client side uses an RBL that is not recognized as legitimate (UCE Protect / BLARS), and the only recommendation we can make is that you advise your recipients that timely delivery of mail to their system cannot be made if they do not subscribe to the legitimate RBL providers such as SPAMCOP and SpamHaus. |
|||
ExchangeDefender offers two mechanisms for email delivery if your server is down. By default, ExchangeDefender spools deferred/delayed/timed out messages and attempts delivery at preset intervals. So long as your mail server is not down for more than 5 days, your messages will be delivered. ExchangeDefender automatically delivers spooled mail at a preset interval. Messages that have been received within the last hour will be retried every 5 minutes. Messages that are older than 1 day will be retried every 20 minutes. You should expect all your mail to be delivered within 1 hour at the most. If your messages have not been delivered within 1 hour, you likely bounced them already. In our experience this happens when a configuration on the server or on the firewall is not correct and the server accepts and bounces the messages immediately. ExchangeDefender LiveArchive is a free (but optional) service designed for business continuity. LiveArchive captures all inbound and outbound mail from your network and allows you to resume operations by using Outlook Web Access 2007 on our network to communicate with your clients while your systems are down. Note: ExchangeDefender does not compensate for misconfiguration or permanent failures / bounces caused by your mail servers. Frequently, clients will bring the server online without checking the recipient’s policies and other security software. If your server comes online and does not properly start or does not properly accept messages, it may bounce them back to the sender, and ExchangeDefender spooling will not be able to help because it was removed from the loop. |
|||
Once that has been done, go to the ExchangeDefender Administrative Portal at https://admin.exchangedefender.com and login as the domain administrator. You can change your IP address under the Configuration tab. |
|||
ExchangeDefender whitelist modifications and blacklist changes take approximately 2 hours. ExchangeDefender LiveArchive account modifications, ExchangeDefender password changes and searches are instant (or less than 60 seconds). |
|||
Note: This should not be a great concern. If you are seeing your own email address in the SPAM reports, you are almost guaranteed to be looking at the spoofed message. Messages sent to yourself generally do not leave your mail server and are routed and delivered locally. |
|||
In our experience, we have found that users will frequently whitelist their own domain. This is not recommended as it presents an easy way for spammers to target you and bypass ExchangeDefender. Please remove the email or domain address from ExchangeDefender whitelist and wait approximately 2 hours for the change to take place. |
|||
If you need additional help setting up an alias in Exchange please view the Microsoft TechNet topic below: http://support.microsoft.com/kb/313420
|
|||
Clients caught abusing our system to conduct this kind of activity will be removed from the outbound service and may even have their entire ExchangeDefender service cancelled. Please see our Acceptable Use Policy, #21: http://www.ownwebnow.com/aup.php
Distinction between legitimate, legal, illegal or illegitimate mailings is not relevant to this policy. Our service is not designed to distribute bulk messages or large distribution lists, and we have agreements in place with large service providers promising that we will not allow bulk content from our network.
|
|||
Please search for it under your Administrator domain login. If you are still unable to locate the message please contact us via the support portal (https://support.ownwebnow.com) and we will assist you. |
|||
“ExchangeDefender does not protect this email address” Once you have added your email address to ExchangeDefender it can still take up to 1 hour for the new address to be allowed through our network. |
|||
In order to most efficiently protect ExchangeDefender client’s servers, ExchangeDefender no longer processes or otherwise wastes client’s servers resources by acknowledging non-existent email addresses. |
|||
If you are trying to Trust Sender for a message that does not have an email address (null sender, <>) the system will throw an alert letting you know that spoofed NDRs are not allowed in the whitelists. You can still attempt to deliver the message, however we do not recommend it. |
|||
|
|||
"Exception occurred while initializing the installation: The system cannot find the file specified."
|
|||
This documentation is not produced or supported by Own Web Now Corp. Please consult a competent firewall engineer for ISA support. |
|||
|
|||
Note: None of the other circumstances are supported. For example, CSS will not work if you have your users login to individual Outlook profiles. If they share the same Windows login, there is no way to use ExchangeDefender CSS. |
|||
You have received a message similar to the one below:
Notice that this is a permanent failure of the recipient's mail server and you should contact them directly through other means. It is very likely that all the other mail you have sent them or will send them in the future will bounce as well. This feature is built into ExchangeDefender to alert the sender that the message has not been accepted by the recipient's mail server. ExchangeDefender has attempted to continuously deliver this message for 1 day. The error is not on your end or on ExchangeDefender's network. It is on the recipient's server. Tech Note: This usually indicates a graylisting process or a malfunctioning blacklist on the recipient's server. If you can reach a technical representative for the recipient's mail server, please advise them that their SMTP server is not properly processing SMTP connections from 65.99.255.232 or 65.99.255.236. In case this is a permanent failure and a problem on the recipients side that cannot be addressed, consider creating an SMTP connector between the two organizations if the direct connections work (process for this is beyond the scope of Own Web Now support and requires advanced understanding of mail systems configuration).
|
|||
You have received a message similar to the one below:
Notice that this is not a permanent failure but only a notice that your message has not been delivered to your recipient yet ("This is a warning message only, you do not need to resend your message") This feature is built into ExchangeDefender to alert the sender that the message has not yet been processed by the recipient's mail server. This typically indicates severe problems on the recipient's mail server. ExchangeDefender offers this alert so you can contact your recipient through alternate means if the message contents require urgent response. While ExchangeDefender will continue to attempt delivery for one full day, this initial alert is in place to allow you to seek other means of communication. Attempting to resend the message will not work because the problem is on the recipient's mail server, not yours or ExchangeDefender's. Tech Note: This usually indicates a graylisting process or a malfunctioning blacklist on the recipient's server. If you can reach a technical representative for the recipient's mail server, please advise them that their SMTP server is not properly processing SMTP connections from 65.99.255.232 or 65.99.255.236. In case this is a permanent failure and a problem on the recipients side that cannot be addressed, consider creating an SMTP connector between the two organizations if the direct connections work (process for this is beyond the scope of Own Web Now support and requires advanced understanding of mail systems configuration).
|
|||
ExchangeDefender blocks a variety of files that can potentially cause problems within corporate networks. Aside from checking the extension of a file, ExchangeDefender will check a files MIME type and contents, where a failure in the check will result in the attachment being stripped and replaced by "exchangedefender-attachment-warning.txt" Renaming a files extension will result in the file being stripped for trying to hide its file type. ExchangeDefender will block the following extensions/file types:
.its Dangerous Internet Document Set .com Windows/DOS Executable .scr Possible virus hidden in a screensaver
Currently there is no way to allow these attachments via custom policy. This is not subject to change because ExchangeDefender cannot assume the risk these files present. If you trust the source, please use a file sharing protocol to obtain the files and scan them correctly. Because it is so easy to forge (spoof) an email address to the one you and your clients or employees trust, it is impossible to whitelist executable content through our network.
|
|||
Nothing, ExchangeDefender treats all domains listed equally. Currently, the hierarchy of the domain listing within the Service Provider level of the portal is merely based on the order the domains were added. Even though this issue is only cosmetic, we plan on adding functionality to customize this hierarchy in the near future. In addition, the domain level authentication is shared by the domains that are connected. This means that if vlad.com is an alias of vlad.net. The admin portal will allow access with both of those as usernames, with the same password. Whichever domain is used to login, will be listed as the primary domain during that session. |
|||
To use our interface to add multiple white list entries at once, the system is set up to use csv (Comma Separated Values) formatting. Thus the file can look like: test1@email.com, or test1@email.com,test2@email.com,test3@email.com |





