User Guide

7-12
AsyncOS 9.1.2 for Cisco Email Security Appliances User Guide
Chapter 7 Defining Which Hosts Are Allowed to Connect Using the Host Access Table (HAT)
Understanding Predefined Sender Groups and Mail Flow Policies
Table 7-7 lists the predefined sender groups and mail flow policies that are configured when a private
listener is created.
Note When you run the System Setup Wizard on an appliance model that has only two Ethernet ports, you are
prompted to create only one listener. It creates a public listener that also includes a $RELAYED mail
flow policy that is used to relay mail for internal systems. For appliance models that have more than two
Ethernet ports, the RELAYLIST sender group and $RELAYED mail flow policy only appear on private
listeners.
UNKNOWNLIST The Unknownlist sender group may be useful if
you are undecided about the mail flow policy you
should use for a given sender. The mail flow
policy for this group dictates that mail is accepted
for senders in this group, but the Anti-Spam
software (if enabled for the system), the anti-virus
scanning engine, and the SenderBase Reputation
Service should all be used to gain more
information about the sender and the message
content. Rate limits for senders in this group are
also enabled with default values. For more
information on virus scanning engines, see
Anti-Virus Scanning Overview, page 12-1. For
more information on the SenderBase Reputation
Service, see SenderBase Reputation Service,
page 6-1.
$ACCEPTED
ALL Default sender group that applies to all other
senders. For more information, see Default HAT
Entries, page 7-2.
$ACCEPTED
Table 7-6 Predefined Sender Groups and Mail Flow Policies for Public Listeners (continued)
Predefined Sender Group Description
Default Configured
Mail Flow Policy
Table 7-7 Predefined Sender Groups and Mail Flow Policies for Private Listeners
Predefined Sender
Group Description
Default Configured
Mail Flow Policy
RELAYLIST Add senders you know should be allowed to relay to the
Relaylist sender group. The $RELAYED mail flow policy
is configured so that email from senders you are allowing
to relay has no rate limiting, and the content from those
senders is not scanned by the anti-spam scanning engine or
anti-virus software.
Note The RELAYLIST sender group includes the
systems allowed to relay email when the System
Setup Wizard was run.
$RELAYED
ALL Default sender group that applies to all other senders. For
more information, see Default HAT Entries, page 7-2.
$BLOCKED