ZyWALL USG Series User’s Guide
751
CHAPTER 40
Anti-Spam
40.1 Overview
The anti-spam feature can mark or discard spam (unsolicited commercial or junk e-mail). Use the white
list to identify legitimate e-mail. Use the black list to identify spam e-mail. The Zyxel Device can also
check e-mail against a DNS black list (DNSBL) of IP addresses of servers that are suspected of being used
by spammers.
40.1.1 What You Can Do in this Chapter
• Use the General Profile screens (Section 40.3 on page 753) to turn anti-spam on or off and manage
anti-spam policies.
• Use the Mail Scan screen (Section 40.4 on page 756) to enable and configure the mail scan functions.
• Use the Black/White List screens (Section 40.5 on page 758) to set up a black list to identify spam and
a white list to identify legitimate e-mail.
• Use the DNSBL screens (Section 40.7 on page 763) to have the Zyxel Device check e-mail against DNS
Black Lists.
40.1.2 What You Need to Know
White List
Configure white list entries to identify legitimate e-mail. The white list entries have the Zyxel Device
classify any e-mail that is from a specified sender or uses a specified header field and header value as
being legitimate (see E-mail Headers for more on mail headers). The anti-spam feature checks an e-mail
against the white list entries before doing any other anti-spam checking. If the e-mail matches a white
list entry, the Zyxel Device classifies the e-mail as legitimate and does not perform any more anti-spam
checking on that individual e-mail. A properly configured white list helps keep important e-mail from
being incorrectly classified as spam. The white list can also increases the Zyxel Device’s anti-spam speed
and efficiency by not having the Zyxel Device perform the full anti-spam checking process on legitimate
e-mail.
Black List
Configure black list entries to identify spam. The black list entries have the Zyxel Device classify any e-
mail that is from or forwarded by a specified IP address or uses a specified header field and header
value as being spam. If an e-mail does not match any of the white list entries, the Zyxel Device checks it
against the black list entries. The Zyxel Device classifies an e-mail that matches a black list entry as spam
and immediately takes the configured action for dealing with spam. If an e-mail matches a blacklist
entry, the Zyxel Device does not perform any more anti-spam checking on that individual e-mail. A
properly configured black list helps catch spam e-mail and increases the Zyxel Device’s anti-spam
speed and efficiency.