Symantec 10744983 Administration Guide - Page 65

Configuring invalid recipient handling, Under Bloodhound Level, click

Page 65 highlights

Configuring email settings 65 Configuring invalid recipient handling can determine in microseconds whether a message or attachment is likely to be infected. If it determines that a file is not likely to be infected, it moves to the next file. Lower heuristic levels may miss viruses, but consume less processing power, potentially speeding incoming mail processing. Higher heuristic levels may catch more viruses, but consume more processing power, potentially slowing incoming mail processing. To set the Bloodhound Level 1 Click Settings > Virus. 2 Click the Bloodhound tab. 3 Under Bloodhound Level, click High, Medium, Low, or Off. 4 Click Save. Configuring invalid recipient handling By default, when an email message arrives addressed to your domain, but is not addressed to a valid user, Symantec Mail Security passes the message to the internal mail server. The internal mail server may either accept the message and generate a bounce message for that recipient, or the internal mail server may reject the recipient, in which case Symantec Mail Security generates a bounce message for the recipient. Upon receiving the bounce message, the sender can resend the original message with the correct address. However, messages with invalid recipients can also result from a spammer's directory harvest attack. You can drop all messages for invalid recipients using the Drop messages for invalid recipients action described below. There is a Remove invalid recipients action available on the Policies > Attacks > Directory Harvest Attacks page that only removes invalid recipients if a directory harvest attack is occurring. These two settings can be combined or enabled individually. Note: Dropping messages for invalid recipients is an extreme measure. Enabling it may prevent diagnosis of serious problems with your email configuration, so only enable it after you're sure your email system is stable. Also, if enabled, even accidentally mis-addressed messages will be dropped, and no bounce message sent. The Remove invalid recipients action available on the Policies > Attacks > Directory Harvest Attack page is a less extreme measure.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249

can determine in microseconds whether a message or attachment is likely to be
infected. If it determines that a file is not likely to be infected, it moves to the next
file.
Lower heuristic levels may miss viruses, but consume less processing power,
potentially speeding incoming mail processing. Higher heuristic levels may catch
more viruses, but consume more processing power, potentially slowing incoming
mail processing.
To set the Bloodhound Level
1
Click
Settings > Virus
.
2
Click the
Bloodhound
tab.
3
Under Bloodhound Level, click
High
,
Medium
,
Low
, or
Off
.
4
Click
Save
.
Configuring invalid recipient handling
By default, when an email message arrives addressed to your domain, but is not
addressed to a valid user, Symantec Mail Security passes the message to the
internal mail server. The internal mail server may either accept the message and
generate a bounce message for that recipient, or the internal mail server may
reject the recipient, in which case Symantec Mail Security generates a bounce
message for the recipient. Upon receiving the bounce message, the sender can
resend the original message with the correct address. However, messages with
invalid recipients can also result from a spammer's directory harvest attack.
You can drop all messages for invalid recipients using the Drop messages for
invalid recipients action described below. There is a Remove invalid recipients
action available on the Policies > Attacks > Directory Harvest Attacks page that
only removes invalid recipients if a directory harvest attack is occurring. These
two settings can be combined or enabled individually.
Note:
Dropping messages for invalid recipients is an extreme measure. Enabling
it may prevent diagnosis of serious problems with your email configuration, so
only enable it after you're sure your email system is stable. Also, if enabled, even
accidentally mis-addressed messages will be dropped, and no bounce message
sent. The Remove invalid recipients action available on the Policies > Attacks >
Directory Harvest Attack page is a less extreme measure.
65
Configuring email settings
Configuring invalid recipient handling