We have FP 2010 (v 11.0.713.0) for Exchange Server 2010 (both reside on the same box if that matters). Sometime in the last coupe of months, the amount of spam getting through skyrocketed. Of course, to me, that would indicate some change somewhere. I haven't been able to track it down. I've read numerous posts here and tried a variety of things, but I simply can't get it to stop. Granted, I'm neither an Exchange superadmin or an FPE master of trade, so bear with me please.
First thing I noticed was that a TON of spam was coming from domains constructed with a variety and combination of underscores and hyphens. I created a sender-domain filter list to handle that and it seems to be working. I'm filtering for:
*__*@*,*___*@*,*\-\-*@*,*\-\-\-*@*,*_*_*@*,*\-*\-*@*
Now, for the rest of the spam getting through. To me, it would seem like very obvious stuff like:
How Oprah Lost <howoprahlost@fractal234.popsexybody.com> . From what I understand and what I'm reading, it appears that the spam getting through is all getting marked with an SCL -1. Here is an example header:
email.OURDOMAIN.com (192.168.44.3 THIS IS OUR LAN IP FOR THE EXCH SERVER) with Microsoft SMTP Server id
14.1.438.0; Wed, 11 Feb 2015 10:47:44 -0500
Date: Wed, 11 Feb 2015 08:54:33 -0700
Bien-Nial: 20200355b59f97bc2b1d6e41931dc765426d132b
To: <myemail@OURDOMAIN.com>
Bis-Marck: b59f97bc2b1d6e41931dc765426d132b
From: How Oprah Lost <howoprahlost@fractal234.popsexybody.com>
Content-Type: multipart/alternative; boundary="20200355"
MIME-Version: 1.0
Subject: How Oprah Dropped 4 Sizes. Special 30% Off Today.
Moun-Ting: 7067031b59f97bc2b1d6e41931dc765426d132b
Message-ID: <b59f97bc2b1d6e41931dc765426d132b.7067031.20200355@fractal234.popsexybody.com>
Return-Path: howoprahlost@fractal234.popsexybody.com
X-MS-Exchange-Organization-AuthSource: OUREXCHANGESERVERNAME.SUBDOMAIN.OURDOMAIN.COM
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-PRD: fractal234.popsexybody.com
X-MS-Exchange-Organization-SenderIdResult: None
Received-SPF: None (OUREXCHANGESERVERNAME.SUBDOMAIN.OURDOMAIN.COM:
howoprahlost@fractal234.popsexybody.com does not designate permitted sender
hosts)
X-MS-Exchange-Organization-SCL: -1
X-MS-Exchange-Organization-Antispam-Report: v=2.1 cv=OO4eg0qB c=1 sm=1 tr=0
a=qCJGFVaA1fzaSxQ8zXb7tw==:117 a=qCJGFVaA1fzaSxQ8zXb7tw==:17
a=KdRuVOa1AAAA:8 a=XfBrk5rWAAAA:8 a=0HtSIViG9nkA:10 a=r62mKx9POPts6foioEEA:9
a=4XpI_ubEG0oA:10 a=aPfxTJr7Be4A:10 a=gd2f-1C48sYA:10 a=NAJQqCe1gegA:10
a=cCZQZXtQNuk4Tf_iH0EA:9 a=FMzNQcTTHvZ4kECS:21 a=QEXdDO2ut3YA:10
a=_W_S_7VecoQA:10 a=K-FqxdBlMCgA:10;OrigIP:38.121.76.5;SCL:-1
X-MS-Exchange-Organization-AVStamp-Mailbox: MSFTFF;1;0;0 0 0
ANY help would be greatly appreciated!