<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : How to prevent Backscatter in ISP Spamfilter</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : How to prevent Backscatter in ISP Spamfilter]]></description>
  <pubDate>Tue, 10 Mar 2026 11:47:14 +0000</pubDate>
  <lastBuildDate>Thu, 27 May 2010 18:02:04 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=6835</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[How to prevent Backscatter in ISP Spamfilter : Hi Roberto Thanks for your very...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13641&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13641</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=865">morten44</a><br /><strong>Subject:</strong> 6835<br /><strong>Posted:</strong> 27 May 2010 at 6:02pm<br /><br /><P>Hi Roberto</P><DIV>Thanks for your very well and detailed explenation as always :)</DIV><DIV>&nbsp;</DIV><DIV>Regards</DIV><DIV>Morten</DIV>]]>
   </description>
   <pubDate>Thu, 27 May 2010 18:02:04 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13641&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13641</guid>
  </item> 
  <item>
   <title><![CDATA[How to prevent Backscatter in ISP Spamfilter : Morten,The new behavior is standard...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13637&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13637</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6835<br /><strong>Posted:</strong> 25 May 2010 at 2:30pm<br /><br />Morten,<div><br></div><div>The new behavior is standard on this new release, there is nothing that needs to be enabled. Please note however that there may be other reasons why someone may get blacklisted, often caused by viruses within a network that may be sending huge amounts of spam to the internet. Usually the sites that blacklist you are able to provide you with details on the "why" the IP/subnet was blocked, which would then pinpoint the problem.</div><div><br></div><div>For the Imail question, if your user sends an email to a non-existent user, the bounce back would usually go back to your user, however the remote server would detect the incoming email to the non-existent user. If these are isolated email attempts it wouldn't be a problem, but if the user is infected/spamming and is sending out a lot of emails, then yes, this would be an issue.</div>]]>
   </description>
   <pubDate>Tue, 25 May 2010 14:30:39 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13637&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13637</guid>
  </item> 
  <item>
   <title><![CDATA[How to prevent Backscatter in ISP Spamfilter : Hi Thanks for the answer.  I...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13632&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13632</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=865">morten44</a><br /><strong>Subject:</strong> 6835<br /><strong>Posted:</strong> 21 May 2010 at 6:02pm<br /><br />Hi<DIV>Thanks for the answer.</DIV><DIV>&nbsp;</DIV><DIV>I think the first option to make a list of all valid emails is not a good option, as we have about 100 domains and each of them can create their own addresses. It would be hard to maintain.</DIV><DIV>&nbsp;</DIV><DIV>About the newest version: 4.2.4.830 we have installed some weeks ago.</DIV><DIV>However we got blacklisted 3 days ago.</DIV><DIV>&nbsp;</DIV><DIV>By Standard we are using very minimal filtering.</DIV><DIV>We basically only use the MAPS servers as filter and that has generally worked OK.</DIV><DIV>We started to get alot of spam from local so we added some more filters but the day after we got bloked. I assume tha its a coinsident that the blocking happened after also applying SFDB on nr4.</DIV><DIV>&nbsp;</DIV><DIV>In this new version, Is it by default that it should work that way?</DIV><DIV>&nbsp;</DIV><DIV>Another potential problem</DIV><DIV>We have ISP listening on port 25 and forwards to Imail Server port 2225.</DIV><DIV>&nbsp;</DIV><DIV>When our users sends mail out they set port 2225 in outlook and send directly from Imail SMTP and it does not pass ISP when sending.</DIV><DIV>&nbsp;</DIV><DIV>Is there a chance that ISP is working as it should, and the problem is that its Imail who when address is not found, sends a postmaster mail to sender?</DIV><DIV>&nbsp;</DIV><DIV>Regards</DIV><DIV>Morten</DIV>]]>
   </description>
   <pubDate>Fri, 21 May 2010 18:02:46 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13632&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13632</guid>
  </item> 
  <item>
   <title><![CDATA[How to prevent Backscatter in ISP Spamfilter : Morten,When SpamFilter receives...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13629&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13629</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6835<br /><strong>Posted:</strong> 21 May 2010 at 10:20am<br /><br />Morten,<div><br></div><div>When SpamFilter receives an email that passes all filtering rules, it forwards it to your destination SMTP server. If that user does not exist, or if their mailbox is full for example, your SMTP server will reject the email attempt. At that point, SpamFilter has to notify the sender that the email was not delivered, and this is (was) done by sending a NDR (non-deliverable report) email back to the sender. If you send out too many of these NDRs, then yes, that may cause the SpamFilter server to be blacklisted. This scenario can be greatly reduced by implementing a "Authorized TO" whitelist, which contains a list of valid email addresses on your mail server. SpamFilter will only accept emails to addresses on that list, which practically eliminates the backscatter issue, and has the great benefit of reducing spam, as spammers who attempt to "guess" valid email addresses will be blocked by SpamFilter's blacklist cache.</div><div><br></div><div>This said... a few weeks ago we released a new version of SpamFilter (v4.2.4.830) which completely changes how SpamFilter processes emails. In particular, this feature is exactly what you're looking for:</div><div><br></div><div><span ="Apple-style-span" style="font-family: Helvetica, Arial, sans-serif; line-height: 20px; "><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">/ New to VersionNumber = '4.2.4.830';</div><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">{TODO -cNew To avoid backscatter, if an incoming email passes all filtering rules, but cannot be forwarded (ex. mailbox full, non-existent user), SpamFilter maintains open the incoming remote connection until it can verify with the destination server that the email can be delivered. If not, a 5xx error is output forcing the remote server to generate the NDR, rather than having SpamFilter send an NDR notification email}</div></span></div><div><br></div>]]>
   </description>
   <pubDate>Fri, 21 May 2010 10:20:54 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13629&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13629</guid>
  </item> 
  <item>
   <title><![CDATA[How to prevent Backscatter in ISP Spamfilter : Morten, we once used imail 822...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13624&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13624</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=221">jerbo128</a><br /><strong>Subject:</strong> 6835<br /><strong>Posted:</strong> 20 May 2010 at 10:22pm<br /><br />Morten,<DIV>we once used imail 822 also and it's failure to use was the backscatter. Spamfilter for the most part does not backscatter. But Imail 822 has many vulnerabilities and we found it to difficult to plug them all.&nbsp; My advice, find a new mail server.</DIV>]]>
   </description>
   <pubDate>Thu, 20 May 2010 22:22:32 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13624&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13624</guid>
  </item> 
  <item>
   <title><![CDATA[How to prevent Backscatter in ISP Spamfilter : Hi. We have an issue with our...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13623&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13623</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=865">morten44</a><br /><strong>Subject:</strong> 6835<br /><strong>Posted:</strong> 20 May 2010 at 11:40am<br /><br />Hi.<DIV>We have an issue with our mail server. We sometimes get blocked on </DIV><DIV>Backscatterer.org<BR></DIV><DIV>We have ISP Spamfilter infront of Imail 8.22 server</DIV><DIV>&nbsp;</DIV><DIV>If I understand correct, we get blocked because we "bouce" delivery failed mail back to sender that sometime is not the real sender. Therefore its taken as spam.</DIV><DIV>&nbsp;</DIV><DIV>I understand we have to configure the system, only to "bounce" delivery failed messages back to LOCAL users, not external users.</DIV><DIV>&nbsp;</DIV><DIV>So my question is;</DIV><DIV>Is this something we need to setup in ISP spamfilter or is it in the Imail Server?</DIV><DIV>we are using ISP for all incomming mails. we do not use ISP Spamfilter to validate any outgoing smtp.</DIV><DIV>&nbsp;</DIV><DIV>Our IMAIL Smtp is using "no relay" and "smtp authentcation"</DIV><DIV>&nbsp;</DIV><DIV>can you give me any idea if I can add settings in ISP spamfilter to prevent this and if yes, what.</DIV><DIV>Or will it be a Imail Configuration setting</DIV><DIV>&nbsp;</DIV><DIV>regards<BR>Morten</DIV>]]>
   </description>
   <pubDate>Thu, 20 May 2010 11:40:58 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6835&amp;PID=13623&amp;title=how-to-prevent-backscatter-in-isp-spamfilter#13623</guid>
  </item> 
 </channel>
</rss>