So tons of spam is getting through, but it doesn't show up in the logs. I looked at the email "properties" of one of the offenders and it appears spammers are using TLS. The box is checked for "Allow and ignore TLS sessions". I see on the Wiki it says:
"Allow and ignore TLS sessions: This option controls the allowance of TLS sessions. If unchecked (the default) the TLS advertisement (if present) is removed from the server advertisements and TLS is not allowed on any scanned sessions. If checked, the TLS advertisement is allowed and if the client initialized TLS the message will pass through completely unscanned, even if it is spam."
So, if I uncheck the box, will it block ALL email that uses TLS? It's clearly letting any and all TLS through now. Seems like a lose-lose. Any advice?
"Allow and ignore TLS sessions: This option controls the allowance of TLS sessions. If unchecked (the default) the TLS advertisement (if present) is removed from the server advertisements and TLS is not allowed on any scanned sessions. If checked, the TLS advertisement is allowed and if the client initialized TLS the message will pass through completely unscanned, even if it is spam."
So, if I uncheck the box, will it block ALL email that uses TLS? It's clearly letting any and all TLS through now. Seems like a lose-lose. Any advice?
Comment