Follow GFI:
Find us on Facebook Follow us on Twitter Find us on Linkedin Subscribe to our RSS Feed Find us on YouTube Find us on Google+
 

How to stop archiving useless spam (Part 1)

on August 2, 2010

In a routine check you may have discovered that your database is growing too fast. With further investigation you may have found out that GFI MailArchiver is also archiving unwanted spam emails.

In a three part tutorial I will explain:

a) how you can avoid more spam emails getting stored in the active GFI MailArchiver Archive Store

b) how you can easily remove archived spam emails from all other GFI MailArchiver Archive Stores.

Step 1

In the first step I will temporarily disable the current “mail servers to archive” process which is maintained by GFI MailArchiver. New emails will therefore remain (for a short interruption time) in the journaling mailbox of the Microsoft Exchange Server.

For this I will log on to the GFI MailArchiver machine as a domain administrator. Then I will open the GFI MailArchiver Administration Configuration Console.

In GFI MailArchiver I will open the node “GFI MailArchiver” >> “Configuration” >> “Mail Servers to Archive” (1):

From this screenshot you can see that I have configured two journaling mailboxes on two different Microsoft Exchange Servers.

Step 2

We will launch the “Mail Server Wizard” for each journaling mailbox that we want to disable.

As you can see in the next screenshot, click on the icon “edit mail server settings” (2) and choose to enable/disable the option “Archive emails from this server” (3). We will disable the option and confirm the changes (“Finish” button).

From now on no further emails will be downloaded from the journaling mailbox by GFI MailArchiver.

Step 3

In the next step we will create a SPAM retention policy in GFI MailArchiver. This should help us to prevent GFI MailArchiver from archiving further spam emails in the archive store.

For this I will open the node “GFI MailArchiver” >> “Retention Policies” in GFI MailArchiver (4):

I have now two choices:

  • Add Spam Retention Policy (5)
  • Add Retention Policy (6)

Step 4

If I use GFI MailEssentials in the latest build as an Anti-Spam solution which should filter inbound spam emails, then GFI MailEssentials will automatically mark the spam email with a specific spam tag in the header.

GFI MailArchiver will now be able to make a difference between a HAM and a SPAM email by just looking into the header of an email that should be archived.

By choosing the option “Add Spam Retention Policy” (5) I will determine that GFI MailArchiver will not archive any further emails into the GFI MailArchiver Archive Store which have been marked as SPAM by GFI MailEssentials.

In my case I will select the option (5). In the first form of the “Retention Policy Wizard” I will provide a proper name for the Spam Retention Policy (5a) and confirm the name of the Spam Retention Policy (‘Next’ button) (5b).

In the next form of the “Retention Policy Wizard” I need to determine the Retention Policy Action which means that spam emails should be deleted by GFI MailArchiver immediately or after X days (5c).

Per default GFI MailArchiver will suggest 30 days. After selecting the right option I confirm the selection (‘Next’ button).

In the last form of the “Retention Policy Wizard” a summary of my selections will be displayed. I confirm my selections (‘Finish’ button) (5e)

We have now set up a Spam Retention Policy which takes immediate affect on all new emails which GFI MailArchiver should archive. Emails which have been marked as spam will not be archived in the GFI MailArchiver Archive Store or will be removed after X days from the GFI MailArchiver Archive Store.

 
Comments
Alexander Bordachenkov August 3, 201011:53 am

Dear Mohammed,

Thank you for the article.

How can we deal with “false positives” – the HAM mail erroneously marked as SPAM? Are there any techniques to archive such e-mails by the end-users?

Sincerely,
Alexander

Mohammed Ali August 6, 201012:17 pm

Dear Alexander,

Thank you very much for your question. If a HAM email has
been tagged as SPAM, then GFI MailArchiver will remove the
HAM email from the GFI MailArchiver Archive Store.

This action will take place as the action has been configured
in the spam retention policy in GFI MailArchiver.

Currently there are no techniques available to archive such
e-mails by the end-users, however there are several workarounds
to archive such “lost” ham emails in the Archive Store by the
administrator.

Workarounds are provided by the Technical Support Team. Please
feel free to open a legitimate support request on our website.

Reference: http://support.gfi.com/Support/supportrequest.aspx?lcode=en

Furthermore, I would strongly advise you to submit any new
feature request for GFI MailArchiver on our Website:
http://ideas.gfi.com.

Best regards

Mohammed Ali