Canit-PRO User's Guide
Total Page:16
File Type:pdf, Size:1020Kb
CanIt-PRO User’s Guide for Version 10.2.5 AppRiver, LLC 13 September 2018 2 CanIt-PRO — AppRiver, LLC Contents 1 Introduction 13 1.1 Organization of this Manual.............................. 13 1.2 Definitions........................................ 14 2 The Simplified Interface 19 3 The My Filter Page 21 3.1 Sender Rules...................................... 21 3.2 The Quarantine..................................... 22 3.3 Online Documentation................................. 22 4 The CanIt-PRO Quarantine 23 4.1 Viewing the Quarantine................................. 23 4.1.1 Message Summary Display........................... 23 4.1.2 Sort Order.................................... 24 4.1.3 Message Body Display............................. 25 4.1.4 Summary of Links............................... 25 4.2 Message Disposition.................................. 25 4.2.1 Quick Spam Disposal.............................. 26 4.3 Reporting Phishing URLs................................ 27 4.4 Viewing Incident Details................................ 27 4.4.1 Basic Details.................................. 28 4.4.2 Address Information.............................. 29 4.4.3 History..................................... 29 4.4.4 Spam Analysis Report............................. 29 4.5 Viewing Other Messages................................ 30 4.6 Viewing Specific Incidents............................... 30 CanIt-PRO — AppRiver, LLC 3 4 CONTENTS 4.7 Searching the Quarantine................................ 30 4.8 Closed Incidents..................................... 32 4.9 Whois Queries..................................... 32 4.9.1 Sending Abuse Complaints........................... 33 4.10 Quarantine Analysis................................... 34 5 Blocklists, Allow Lists and Rules 37 5.1 The Sender Action Table................................ 37 5.1.1 Holding Unlisted Senders........................... 38 5.2 The Domain Action Table................................ 39 5.2.1 Domain Matching Rules............................ 40 5.3 The Network Action Table............................... 40 5.4 Country Rules...................................... 41 5.5 Bulk Blocking and Allowing.............................. 42 5.6 MIME Types...................................... 43 5.7 Filename Extensions.................................. 44 5.7.1 Matching Entire File Names.......................... 44 5.7.2 Matching Filename Extensions inside an Archive............... 44 5.7.3 Matching Multi-Extension Filenames..................... 45 5.7.4 Matching All Attachments........................... 45 5.7.5 Matching PDF files that contain JavaScript.................. 45 5.7.6 Detecting Encrypted Files........................... 45 5.7.7 Detecting PDF files that contain embedded files................ 45 5.7.8 Detecting PDF files that contain URLs..................... 46 5.8 Passive OS Fingerprinting............................... 46 5.9 Custom Rules...................................... 46 5.9.1 Viewing Custom Rules............................. 46 5.9.2 Creating a Simple Custom Rule........................ 47 5.9.3 Creating a Custom Rule............................ 48 5.9.4 Special Relations................................ 53 5.9.5 Regular Expressions.............................. 53 5.9.6 Macro Values in Value Boxes......................... 54 5.9.7 Editing an Existing Custom Rule........................ 55 5.9.8 Deleting a Custom Rule............................ 55 5.10 RBL Rules....................................... 55 CanIt-PRO — AppRiver, LLC CONTENTS 5 5.11 SPF Rules........................................ 56 5.11.1 How SPF Queries Work............................ 57 5.11.2 Entering SPF Rules............................... 57 5.11.3 Vouch by Reference.............................. 58 5.11.4 SPF and Effects on Allow-Always rules.................... 59 5.12 DKIM Rules....................................... 59 5.12.1 Vouch by Reference.............................. 61 5.12.2 Multiple DKIM Signatures........................... 61 5.13 DMARC Rules..................................... 61 5.14 Blocking Recipients................................... 62 5.15 Enumerating Valid Recipients............................. 63 5.15.1 Sources of Valid Recipients.......................... 64 5.16 Overriding Built-In Test Scores............................. 64 5.17 Importing and Exporting Rules............................. 65 5.17.1 Exporting Rules................................ 65 5.17.2 Importing Rules................................ 66 5.18 Reviewing the Change History............................. 67 5.19 Viewing Inherited Rules................................ 68 6 Delivery Policy Rules 69 6.1 Delivery Policy Rules.................................. 69 6.1.1 Enabling or Disabling the Delivery Policy Feature.............. 70 6.1.2 Moving Rules Up and Down.......................... 71 6.1.3 Deleting Rules................................. 71 6.1.4 Creating or Editing Rules........................... 71 6.1.5 Macros in Rules and Actions.......................... 73 6.1.6 Macros in Rewrite Expressions........................ 73 6.1.7 Message that are Exempt from Delivery Policy Rules............. 74 7 Preferences 75 7.1 Preferences....................................... 75 7.2 Changing Default Preferences............................. 78 7.3 Changing your Password................................ 78 7.4 Aliases.......................................... 78 7.4.1 Creating an Alias................................ 79 7.4.2 Domain Aliases................................. 79 CanIt-PRO — AppRiver, LLC 6 CONTENTS 7.4.3 Deleting Aliases................................ 79 7.5 Quick Links....................................... 80 8 Reports 81 8.1 Statistics......................................... 81 8.1.1 Classification Reports............................. 82 8.2 Reports based on Quarantine Content......................... 83 8.3 Greylisting Report................................... 85 8.4 Load Report....................................... 85 9 Streams 87 9.1 Rule and Setting Inheritance.............................. 87 9.2 Opting Out of Spam Scanning............................. 88 9.3 Quarantine Settings................................... 88 9.4 Notification of Pending Messages........................... 94 9.5 RSS Feeds........................................ 96 9.6 Adding Addresses to your Stream........................... 97 9.7 Switching Streams................................... 98 9.7.1 Viewing All Streams at Once.......................... 98 10 Bayesian Filtering 101 10.1 Introduction to Bayesian Filtering........................... 101 10.2 Quarantine Settings Associated with Bayesian Filtering................ 102 10.3 Training the Bayesian Filter.............................. 103 10.3.1 Manual Voting................................. 104 10.4 Bayesian Score Settings................................. 105 10.5 Custom Bayes Stopwords................................ 106 11 Email Archiving 109 11.1 Introduction to Archiving................................ 109 11.2 Configuring Archiving................................. 109 11.3 Archiving Outbound Mail................................ 110 11.4 Archiving Internal Mail................................. 110 11.5 Searching the Archives................................. 111 11.5.1 Fields...................................... 113 11.5.2 Relations.................................... 114 11.5.3 Setting the Search Date Range......................... 114 CanIt-PRO — AppRiver, LLC CONTENTS 7 11.5.4 Creating a Query Clause............................ 115 11.5.5 Creating a Group................................ 115 11.5.6 Performing a Search.............................. 115 11.5.7 Query Cookbook................................ 115 11.6 Saved Searches..................................... 117 11.7 Mass-Redelivery of Archived Messages........................ 117 11.8 Viewing Archived Messages.............................. 117 11.8.1 Redelivering Archived Messages........................ 118 11.9 Searching for Related Messages............................ 118 11.10Replying to an Archived Message........................... 119 11.11Creating a New Message................................ 119 11.12Seeing Access History................................. 119 11.13Seeing Search History.................................. 119 11.14Creating Zip Files.................................... 119 11.14.1 Zip File Contents................................ 120 11.15Archive Expiry Details................................. 121 11.16Selective Archiving................................... 121 11.16.1 Creating an Archiving Rule.......................... 121 11.16.2 Adjusting Archive Rules............................ 121 11.16.3 Rule Hits.................................... 122 12 Secure Messaging 123 12.1 Introduction to Secure Messaging........................... 123 12.2 Configuring Secure Messaging............................. 123 12.2.1 Determining the Stream for Secure Messaging................ 124 12.3 Creating a Secure Messaging Rule........................... 124 12.3.1 Adjusting Secure Messaging Rules...................... 125 13 Locked Addresses 127 13.1 Introduction to Locked Addresses........................... 127 13.2 How Locked Addresses Work............................. 127 13.3 Creating a Locked Address............................... 128 13.4 Viewing Locked Addresses............................... 129 13.5 Editing a Locked Address................................ 130 13.6 Deciding