Chapter 34 Anti-Spam

Table 169 Configuration > Anti-X > Anti-Spam > DNSBL (continued)

LABEL

DESCRIPTION

Edit

Select an entry and click this to be able to modify it.

 

 

Remove

Select an entry and click this to delete it.

 

 

Activate

To turn on an entry, select it and click Activate.

 

 

Inactivate

To turn off an entry, select it and click Inactivate.

 

 

Status

The activate (light bulb) icon is lit when the entry is active and

 

dimmed when the entry is inactive.

 

 

#

This is the entry’s index number in the list.

 

 

DNSBL Domain

This is the name of a domain that maintains DNSBL servers. Enter the

 

domain that is maintaining a DNSBL.

 

 

Apply

Click Apply to save your changes back to the ZyWALL.

 

 

Reset

Click Reset to return the screen to its last-saved settings.

 

 

34.7 Anti-Spam Technical Reference

Here is more detailed anti-spam information.

DNSBL

The ZyWALL checks only public sender and relay IP addresses, it does not check private IP addresses.

The ZyWALL sends a separate query (DNS lookup) for each sender or relay IP address in the e-mail’s header to each of the ZyWALL’s DNSBL domains at the same time.

The DNSBL servers send replies as to whether or not each IP address matches an entry in their list. Each IP address has a separate reply.

As long as the replies are indicating the IP addresses do not match entries on the DNSBL lists, the ZyWALL waits until it receives at least one reply for each IP address.

If the ZyWALL receives a DNSBL reply that one of the IP addresses is in the DNSBL list, the ZyWALL immediately classifies the e-mail as spam and takes the anti-spam policy’s configured action for spam. The ZyWALL does not wait for any more DNSBL replies.

If the ZyWALL receives at least one non-spam reply for each of an e-mail’s routing IP addresses, the ZyWALL immediately classifies the e-mail as legitimate and forwards it.

Any further DNSBL replies that come after the ZyWALL classifies an e-mail as spam or legitimate have no effect.

The ZyWALL records DNSBL responses for IP addresses in a cache for up to 72 hours. The ZyWALL checks an e-mail’s sender and relay IP addresses against the cache first and only sends DNSBL queries for IP addresses that are not in the cache.

578

 

ZyWALL USG 50 User’s Guide