Re: Anyone got an effective anti-spam and anti-virus regime?

by "Darrell King" <darrell(at)webctr.com>

 Date:  Tue, 26 Aug 2003 11:30:12 -0400
 To:  <mkear(at)afpwebworks.com>,
"'hwg-techniques forum'" <hwg-techniques(at)hwg.org>
 References:  mainman
  todo: View Thread, Original
It's neither possible nor appropriate to expect flawless filtering from a
hosting provider. Mine takes  a shot at it with SpamAssassin, but the
results are far from comprehensive. They get some of it, acting as a first
line of defense, and I rely on local filters to screen some more.  Even with
all that, I still end up using the delete button for three quarters of my
mail.

Some things they can do include disabling any catch-all email services
(accounts catching email sent to users not set up as specific POP accounts),
deleting any unneeded POP accounts and, yes, changing their POP account as
needed.  That last sounds drastic, but it can be done by changing it on the
site and notifying important contacts of the new account a month before
actually disabling the old one. Whether it's possible for your client
depends on their specific situation.

It goes without saying that if they are losing time because of "infected
email" then their virus protection is inadequate.  I am using Outlook
Express under Windows XP Pro with McAffee and have had no virus downtime in
2 years (I was using OE with Win2k before the current machine).

Never open an attachment that wasn't expected. Never.  If you suspect it may
be a valid message from a client or friend, keep the note and request
confirmation from the sender before opening it. If you like to open strange
jokes and attachments, you must take the consequences.  Personally, I delete
them unless I was told in advance to expect them.

If using Windows, set your environment to show the actual name of files,
with extensions, even for known types.  An attachment named ShowMe.txt.exe
if a giveaway that someone was trying to hide from the default Windows setup
the fact that it is an executable file.

I went through all this awhile back with a few clients, mostly during the
early days of the current SPAM craze.  My provider worked with me to help
them, but the final evaluation was that the filters can't keep up with the
new tricks the spammers seem to learn weekly.  The end responsibility for a
given machine's security lies with whoever is managing that machine and not
with anyone else in the world, including those in the email delivery chain.

D



----- Original Message -----
From: "Mike Kear" <mkear(at)afpwebworks.com>

My initial reaction is to tell him he's living in lala-land if he thinks he
can stop spam, specially since his website has his email address on it in a
dozen places, but before I did that I thought I'd check and see what you
guys think ..

HWG hwg-techniques mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.