How can I configure Exchange Server 2003 to block spam?

Microsoft Exchange Server 2003 now has built-in Open Relay Filter (ORFilter) or DNS Blacklist and Realtime Blackhole List (DNSBL, RBL) capabilities, which releases us from the need to rely on 3rd party software for the spam filtering.

Update – Exchange Intelligent Message Filter

Microsoft Exchange Intelligent Message Filter (IMF) was first released at the end of May 2004.
Microsoft Exchange Intelligent Message Filter is a product developed by Microsoft to help companies reduce the amount of unsolicited commercial e-mail (UCE), or spam, received by users.
imf3 small
Intelligent Message Filter is based on Microsoft SmartScreen Technology from Microsoft Research. By using e-mail characteristics tracked by SmartScreen technology, Intelligent Message Filter can help determine whether each incoming e-mail message is likely to be spam. Based on this likelihood, you can choose to block e-mail messages at the gateway or at the mailbox store.
Note: The Intelligent Message Filter is not supported in a clustered environment. Therefore, Intelligent Message Filter updates are not offered to Exchange Server 2003 servers in a clustered environment.
Exchange Server 2003 SP2 Update Note: IMF used to be a stand-alone tool downloadable from Microsoft. Although one can still download and install it separately (here, if you insist, but you don’t need it anymore), IMF is now an integral part of Exchange Service Pack 2 (SP2). You can learn how to configure it on SP2 by reading Configure Intelligent Message Filter in Exchange 2003 SP2.
Read more about IMF in the Related Articles section below.

Using 3rd party software

The anti-spam features in Exchange 2003 are far from complete, and using software like Policy Patrol, GFI MailSecurity and GFI MailEssentials for Exchange/SMTP and others is still recommended, but for small businesses or companies that cannot afford these products – Exchange Server 2003 can now handle most the job, especially with IMF around.
However, there are still many problematic “features” (as Microsoft likes to call them) in the built-in anti-spam support in Exchange 2003. One bad thing about the Exchange Server 2003 Spam protection options is the fact that there is no GUI-easy way to import or export blocked e-mail addresses or sending domains.
Another bad thing is that there is no default way to see if the filters are working, and how much spam is blocked.

Configuring e-mail blocking

To configure e-mail blocking do the following:

  1. Go to the properties of the Message Delivery settings.

rbl small

  1. Click new to add a connection filter.

rbl1 small

  1. Add the desired RBL service and click OK.

rbl2 small rbl3 small

  1. You can also configure exceptions for these rules. Click the Exceptions button and enter your settings.
  2. A warning shows that you have to enable the filtering at the SMTP virtual servers.

rbl8 small

  1. Go to the properties of your SMTP Virtual Server.

rbl4 small

  1. On the General tab, click the Advanced Button.

rbl5 small

  1. Click the Edit button.

rbl6 small

  1. Check the ‘Apply Connection Filter’ checkbox.

rbl7 small

  1. Click Ok all the way out.

Further Reading

You might also want to read the following related articles:

Links

Prevent Junk E-Mail Messages with Outlook 2003


Exchange Intelligent Message Filter