17
Introducing Symantec Mail Security for SMTP
How Symantec Mail Security for SMTP works
queue with a large number of dedicated threads) to be processed. Symantec Mail
Security for SMTP first looks for messages to block before scanning for viruses.
You can configure Symantec Mail Security for SMTP to notify senders and
administrators when messages are blocked.
After blocking messages, Symantec Mail Security for SMTP uses several
antivirus technologies to scan remaining messages for viruses. It looks for
known viruses by comparing file segments to the sample code inside of a virus
definitions file. The virus definitions file contains nonmalicious bits of code, or
virus definitions, for thousands of viruses. If Symantec Mail Security for SMTP
finds a match, the file is considered infected, and the email is handled (repaired,
deleted, or logged and delivered) according to how you have configured the
software. To protect your network from new viruses, you can configure regular
virus definitions file updates.
See
“Updating virus and spam definitions files”
on page 84.
By default, when Symantec Mail Security for SMTP detects a virus in an email
attachment (that is not a container file), it attempts to repair the infected
attachment. If Symantec Mail Security for SMTP cannot repair the attachment,
it deletes the attachment by default. With container files, Symantec Mail
Security for SMTP removes the infected files from the containers and attempts
to repair the files. If a virus is detected, Symantec Mail Security for SMTP
inserts text in the body of the message that specifies which virus was found and
where it is located.
You can configure Symantec Mail Security for SMTP to forward infected
messages to a Central Quarantine Server, and configure the Central Quarantine
Server to automatically submit virus samples to Symantec Security Response
for analysis.
After blocking and scanning messages, Symantec Mail Security for SMTP
delivers them. If the message cannot be delivered, it is moved to the slow queue
so as not to backlog the fast queue. Once the message is in the slow queue, a
message is sent to the original message sender indicating that Symantec Mail
Security for SMTP will continue to attempt delivery of the message.
Symantec Mail Security for SMTP reorders messages in the slow queue.
Messages that cannot be delivered are moved to the rear of the queue. Queue
messages that are destined to the same host on the next hop are moved to the
front of the queue (if those hosts are accepting delivery). If the message is not
able to be delivered within the specified number of days, Symantec Mail Security
for SMTP returns a reason (for example, wrong domain, user name doesn’t exist)
to the original message sender, and the file is deleted from the slow queue.
Summary of Contents for 11105111 - SYM MAIL SEC SMTP 5.0 SMS PORT MEDIA CD EN
Page 1: ...Symantec Mail Security for SMTP...
Page 8: ...8...
Page 44: ...44 Installing Symantec Mail Security for SMTP Uninstalling Symantec Mail Security for SMTP...
Page 88: ...88 Setting your antivirus policy Setting up your own LiveUpdate server...
Page 124: ...124 Setting your antispam policy Blocking by custom spam rules...
Page 140: ...140 Setting your filtering policy Blocking by custom content rules...
Page 170: ...170...