Tuesday, July 31, 2007

SpamTitan

SpamTitan is "the most comprehensive solution to email threats on the market today". I have implemented this solution to provide "protection from Viruses, Spam, Malware, Phishing and unwanted content" and it works very well. I used the VMware virtual machine image and converted it to run on ESX server.
  • The interface is very impressive and setup was quite straight forward - no reading of the manual required.
  • Uses two anti-virus engines: Kaspersky and ClamAV
  • Uses OCR to detect image-spam
  • Multi-layer anti-spam approach - scoring from several algorithms is compiled to provide a single spam score.
  • The product checks for valid recipients (including aliases) against my Exchange server.
  • Logging and reporting are excellent.
  • There have been some false positives and initially it didn't block as much spam as I had hoped but as the Beyesian analysis has improved so have the detection rates.
  • I have been monitoring the quarantine and whitelisting the domains from which we often see mail.
  • I am not yet sending outgoing mail through my SpamTitan but this should improve the filters as well.
  • After an upgrade, the ClamAV definitions were no longer being updated. I contacted support and they connected from remote (via a tunnel I opened) and fixed the problem. An excellent support experience.
I was surprised to find that in the two weeks or so that I have been filtering my SMTP traffic that we are averaging only approximately 20% legitimate mail.

No comments: