Managing spam in the real world

Opinion
Mar 17, 20053 mins

* One reader’s story

I recently received an interesting account of how spam is managed in a real-world setting, from a reader of this newsletter who is also a member of our survey panel.

What follows is this administrator’s story. Thank you very much to the individual who provided it.

“I am the lead system administrator for the e-mail perimeter at a large financial/insurance company. We have about 17,000 mailboxes altogether. About a year ago, we completed a project to upgrade to a best-of-breed anti-spam solution. We looked at all of the options and settled on Brightmail, which ran as a milter on our Sendmail servers. Later in the year we upgraded to IronPort appliances. At the beginning of last year, we were processing about 250,000 e-mails per day. Today, we’re processing about 800,000 recipients (IronPort reports on the number of recipients processed instead of the number of messages) per day. On the back end, we’re currently running Exchange 2000 with Outlook 2000 clients. 

“Last year, when we were in front of the CIOs, they told us that there should be no user interaction with whatever spam tool we used. Their reasoning was that we were hoping to recover the amount of time our users were spending on spam. By adding a client piece, you were replacing one productivity problem with another. The vast majority of our users are not technical and would need some initial training on how to use the tool. Then, there would inevitably be problems with the Outlook plug-in not working with some clients out there and our help desk would have to address that. So, by adding a client piece, you are replacing one cost with another.

“On a side note, as I said before, we’re processing about 800,000 recipients per day. This is even after dropping an average of 100,000 connections per day just because of the IP addresses’ reputation score in SenderBase. Without that, the number of recipients would no doubt be over 1 million per day. I recently discovered an interesting effect of the connection dropping, though. Our Brightmail and virus stats have drastically dropped. Today, Brightmail is blocking about 40% of our total mail volume. In the past, without SenderBase and connection dropping, Brightmail was blocking about 60% of our total mail volume. So, by using a reputation filter, we’re blocking about half to one-third of the total spam that hits our environment before the sending server ever sends the message.

“Because our Brightmail percentages are going down, I am going to have to find more creative ways to tell our story to the CIOs. Financial companies don’t like guesstimates. They like hard numbers. Unfortunately, I can’t tell them how many total recipients may have been in those 100,000 connections per day that we dropped. I can only tell them that the industry is still seeing a steady increase in spam, and we are simply doing a better job of blocking it at the perimeter, before even Brightmail gets to take a look at it.”