03-16-2021 08:11 AM
Hi All,
Looking for recommendations or best practice how to approach scenario where the IT staff of a company is being overloaded with the amount of messages going into quarantine. Some of these look to be failing spf (soft/hard) and dkim. Would the best approach be to whitelist the legitimate domains?
I read in some best practice document with contradicting recommendations. One document says to drop all SPF hardfails, while others and the default settings on CES has SPF hardfails to quarantine. Which is it? Can I get definitive best practice for what to drop and what to quarantine?
Also what steps would you take to reduce the amount of legitimate emails going into quarantine?
03-16-2021 09:07 AM
03-16-2021 09:21 AM
Hi Madura,
it is all a numbers game. If I break down our PVO numbers we have :
60 % SPAM
15% GREYMAIL
3% SPF fail
2 % DKIM fail
3 % URL CATEGORY FAIL
2 % AV FAIL
2 % ENCRYPTION FAIL
1 % OTHER
For us that would mean SPAM and GREYMAIL need to managed without admins, the rest needed admins. At the end you will create whitelists per category to decide what to do. A properly setup email domain should not have emails in the quarantine. What kind of messages are you worried about ?
-Marc
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide