Product manual

GFI MailEssentials 7 Anti-Spam | 115
Option Description
Add URIDNSBlocklist If required, add more URI DNS Blocklists to the ones already listed. Key in
the full name of the URI DNS Blocklist domain and click Add
URIDNSBlocklist.
Order of preference The order of preference for enabled URI DNS Blocklists can be changed by
selecting a blocklist and clicking on the Up or Down buttons.
Enable Selected Select a URIDNSBlocklist and click Enable Selected to enable it.
NOTE
It is recommended to disable all other URI DNS Blocklists when enabling
multi.surbl.org as this might increase email processing time.
Disable Selected Select a URIDNSBlocklist and click Disable Selected to disable it.
Remove Selected Select a URIDNSBlocklist and click Remove Selected to remove it.
3. Click Actions tab to select the actions to perform on messages identified as spam. For more
information, refer to Spam Actions - What to do with spam emails (page 135).
4. Click Apply.
7.1.7 Sender Policy Framework
This filter uses SPFrecords to stop email sent from forged IPaddresses by identifying if the sender
IPaddress is authorized. The Sender Policy Framework filter is based on a community-based effort,
which requires that the senders publish the IPaddresses of their mail servers in an SPF record.
Example: If an email is sent from xyz@CompanyABC.com then companyABC.com must publish an SPF
record in order for SPF to be able to determine if the email was really sent from the
companyABC.com network or whether it was forged. If an SPF record is not published by
CompanyABC.com, the SPF result will be ‘unknown’.
For more information on SPF and how it works, visit the Sender Policy Framework website at:
http://www.openspf.org.
The SPF filter is NOT enabled by default and it is recommended to enable this option and to have this
filter running prior to the Email Whitelist so to block forged senders before these are whitelisted.
GFI MailEssentials does not make it a requirement to publish any SPF records. To publish SPF records
use the SPF wizard at:
http://www.openspf.org/wizard.html.
Prerequisites
Before enabling the Sender Policy Framework filter on a non-gateway server installation:
1. Click Anti-spam > Anti-Spam Settings and select Perimeter SMTP Servers tab.
2. Click Detect in the Perimeter SMTP setup option to perform a DNS MX lookup and automatically
define the IP address of your perimeter SMTP server.
Enabling the Sender Policy Framework
1. Select Anti-Spam > Anti-Spam Filters > Sender Policy Framework.