Chapter 40 Anti-Spam
ZyWALL USG Series User’s Guide
767
Figure 527 DNSBL Legitimate E-mail Detection Example
1 The Zyxel Device receives an e-mail that was sent from IP address c.c.c.c and relayed by an e-mail
server at IP address d.d.d.d. The Zyxel Device sends a separate query to each of its DNSBL domains for IP
address c.c.c.c. The Zyxel Device sends another separate query to each of its DNSBL domains for IP
address d.d.d.d.
2 DNSBL B replies that IP address d.d.d.d does not match any entries in its list (not spam).
3 DNSBL C replies that IP address c.c.c.c does not match any entries in its list (not spam).
4 Now that the Zyxel Device has received at least one non-spam reply for each of the e-mail’s routing IP
addresses, the Zyxel Device immediately classifies the e-mail as legitimate and forwards it. The Zyxel
Device does not wait for any more DNSBL replies.
If the Zyxel Device receives conflicting DNSBL replies for an e-mail routing IP address, the Zyxel Device
classifies the e-mail as spam. Here is an example.
DNSBL A
DNSBL B
DNSBL C
IPs: c.c.c.c
d.d.d.d
1
c
.
c
.
c
.
c
N
o
t
s
p
a
m
2
4
c
.
c
.
c
.
c
?
d
.
d
.
d
.
d
?
c
.
c
.
c
.
c
?
d
.
d
.
d
.
d
?
c.c.c.c?
d.d.d.d?
d.d.d.d Not spam
3