Atec Solutions Ltd

Viruses

Our server scans all incoming email for viruses, and blocks any that it finds (SMTP reject, error code 554)

We also have a many virus definitions, which will detect a large number of spam messages as well (and it will reject them as a virus because almost all spam is from a virus infection).
We use the sanesecurity rules, along with 200+ of our own custom definitions.

Here is a summary of viruses blocked in one day:

Virus summary: Wednesday 20 August 2008

285xEmail.Malware.Sanesecurity.08081914
258xEmail.Spam.Gen3729.Sanesecurity.08072505
156xEmail.Malware.Sanesecurity.08072227
84xEmail.Dipl.Gen101.Sanesecurity.08081700
72xEmail.Spam.Gen3880.Sanesecurity.08081900
71xEmail.Spam.Gen3753.Sanesecurity.08072818
71xEmail.Phishing.Cur.Gen1182.Sanesecurity.08080500
68xEmail.Phishing.Cur.Gen1181.Sanesecurity.08080402
67xEmail.Spam.Gen3602.Sanesecurity.08070319
62xEmail.Spam.Gen3881.Sanesecurity.08081901

DNSBL

Our server also checks incoming messages against various "DNS block lists", which help to identify spam sources. Any incoming message found to be from a known spam source will be rejected (SMTP reject, error code 553) with a note telling them to visit our DNSBL page for more information

If you find that a message you are trying to send is blocked by our DNSBL checks, please contact us to discuss possibilities; we do have whitelisting capabilities.

Here is a summary of spam sources blocked in one day:

DNS blocklist worst offenders: Wednesday 20 August 2008

102 from 212.100.109.37
83 from 59.188.113.229
69 from 217.58.78.236
66 from 70.104.24.4
65 from 66.157.16.201
63 from 68.166.99.234
62 from 85.100.106.20
61 from 64.126.161.2
56 from 213.169.171.104
55 from 213.123.142.40

Spam

For clients who collect email directly from our server (ie POP3, not forwarding), we check all messages using spamassassin.
We do, naturally, have several custom rules which are identifiable by starting with 'Y_'
We also regularly update our scoring for certain tests in order to tag as much spam as possible without tagging non-spam messages.

We do not delete messages which spamassassin decides are spam, for the simple reason that it sometimes gets things wrong (false positives)
Our server will either block messages at SMTP time, with a 5xx reject, or will deliver emails - we never just drop emails programmatically (except for our blackhole address).
Some customers have found that our spam rules are highly accurate and the shear volume of spam they receive has become too unwieldy to even attempt to find false positives; for these customers we file all spam with a score of 7 or above into a separate mailbox, which can be accessed with webmail in the event of a legitimate email being mis-tagged.

To cut down on the most spam possible, we use several techniques and programs:
When a particular remote computer/server has sent a vast number of spam messages, or has tried to compromise our server some other way, we will block connections within our firewall. This is reserved for the most drastic cases and is not a measure we take lightly.
Our first main line of defense is to check incoming connections against DNS black lists (see above)
We then check messages using clamav for viruses and known significant spam signatures
For customers who have their email forwarded to another address, this is all we do.
For customers who collect directly from our server (POP3) however, we also check messages with spamassassin, including:
several custom rules and custom scoring:
checking the message with Vipul's razor (i.e. cloudmark),
the PDFInfo module to detect spam sent as a pdf attachment,
running OCR software against included pictures to extract text which is then also checked against a black list.

Each test is assigned a score; if the total score is high enough then the message is tagged to make it easily identifiable and easily filtered. A large proportion of our customers simply have a filter rule set up to delete all tagged messages, although we do recommend checking the deleted items for incorrectly tagged messages.

If any of our customers' legitimate email is tagged, we will look at ways of rectifying this, including whitelisting specific senders and recipients.

Here is a summary of spam tagged messages in one day:

Spamassassin tagged messages: Wednesday 20 August 2008

All tagged messages: 734
All picture spam: 8
All razor2 tagged spam: 242