Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Configuring the Mail Transfer Agent on RBL for Email Reputation Services (ERS)

    • Updated:
    • 24 Feb 2015
    • Product/Version:
    • Email Reputation Services Hosted.All
    • Email Reputation Services Standard/Advanced.All
    • Platform:
    • Not Applicable N/A
Summary

Learn how to configure the Mail Transfer Agent (MTA).

Details
Public

To configure your WebStar server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message, go to SMTP Server/DNS Blacklists. You will need to have 15 entries for all 15 Response codes ranging from 127.1.0.1 through 127.1.0.15.

  • Name Hostname
  • Response MAPS activationcode.r.mail-abuse.com 127.1.0.1
    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.
  • Denial Message

You can also refer to the Email Reputation Services site.

To configure your Aladdin eSafe server to use Trend Micro Network Reputation Services:

 
Make sure all 15 RBL server entries are at the top of the search list.

eSafe 4.0

  1. Open the eSafe Gateway Configuration.
  2. Under Anti-Spam, select Mail Server Validation.
  3. Under Check mail server validity at RBL server:, select Check incoming email.

    You will need to add a new RBL server with the responses.

  4. For RBL server name field, enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  5. For Response, enter "127.1.0.1".

    You will need to repeat this step many times. Once for each Response ranging from 127.1.0.1 through 127.1.0.15.

    You must enter all 15 response codes to get the full benefit of the RBL+ service.

eSafe 5.0

  1. Open the eSafe Gateway Configuration.
  2. Under Anti-Spam, select Mail Server Validation.
  3. Tick the Check if mail server is in RBL for INCOMING email
  4. Click List on the right. This will bring up a list of existing RBL entries.

    You will need to add a new RBL server with the reponse.

  5. Click Add.
  6. For the RBL server name field, enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  7. For the Response (to block) field, enter "127.1.0.1".
  8. Tick the Activate use of this servercheckbox.

    You will need to repeat this step 15 times. Once for each Response ranging from 127.1.0.1 through 127.1.0.15.

    You must enter all 15 response codes to get the full benefit of the RBL+ service.

To configure your MDaemon to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. On the DNS Black Lists (DNS-BL) page, go to the DNS-BL options tab.
  2. Tick the Enable DNS-BL engine option.
  3. Select Block email from servers which have been blacklisted.
  4. Click Apply.
  5. Go to the DNS-BL Hosts tab.
  6. For the New host field, enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  7. For the Message, enter "blocked by Trend Micro RBL+".

    Refer to the Email Reputation Services site.

  8. Click Add.
  9. Select Stop host lookups on the first host match.
  10. Check the Send Message on match (instead of User unknown) option.
  11. Click Apply.

Bizanga’s IMP solution is highly customizable. In order to ensure that you have the most comprehensive and effective solution to meet your needs, refer to the technical configuration document provided with the product, and/or contact Bizanga’s customer support for assistance.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product, you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

For instructions on how to configure your Cisco product to access Trend Micro Network Reputation Services, refer to your Trend Micro product manual.

If you have questions on testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your MAILsweeper to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Under Policies Properties, click the Security tab.
  2. Tick the Look up SMTP hosts in unsolicited mail database checkbox.
  3. For the Web site field, enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

    If you want it to log the rejections, tick the Record rejected host in Event Log checkbox. This is the MailSweeper Event Log, not the Windows Event Log.

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product, you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product, you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your Deerfield VisNetic Mail Server to use Trend Micro Network Reputation Services:

Visnetic 7.x

  1. Log on to Visnetic Web Admin.
  2. On the left side of the main configuration page, click Delivery.
  3. Look for the Anti-Relaying subset.
  4. Tick the DNSBL checkbox to enable the feature.
  5. Click DNSBL.

    This will bring up a page for adding DNSBL server names.

  6. Add one server name per line.
  7. Enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  8. Click Save.

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product, you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your exim server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Edit your ../usr/exim/configure file.

    Your file may be in a different location.

  2. Check if you have a dnslists section.
  3. Enter the following information:
    • deny message = $sender_host_address blocked using Trend Micro RBL+.

      Refer to the Email Reputation Services site.

    • dnslists = activationcode.r.mail-abuse.com
  4. Make sure the deny line is one long line.
  5. Stop and restart exim.

To configure your Fortigate Firewall to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Under Spam Filter > DNBSBL & ORDBL section, click Create New.
  2. For the RBL Server name field, enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  3. Select the action you want to use.
  4. Select Enable, then click OK.

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product, you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your Gordano Messaging Server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

You will need to setup 15 response codes for our RBL+ service.

  1. Set 127.1.0.1 through 127.1.0.15.
  2. For the RBL Server field, enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  3. Set Action to "Fail".
  4. For the IP Response, enter "127.1.0.1".

    Be sure to setup all 15 entries.

    For more information on configuring filters for Gordano Messaging Server, refer to the the Gordano article: How do I set up GMS to use the RBL+ database from mail-abuse.org?.

To configure your GWAVA Mail Server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Go to Configuration > GWAVA Manager > RBL lists.
  2. Tick the Enable RBL lookup checkbox.
  3. Click Add, then enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

To configure your IMail Server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

Yu need to configure the RBL checking in 2 places: under the main server configuration and the host connection filtering. Refer to switch's Server Configuration User Guide.

Main Server Configuration

To Configure DNS Black Lists:

  1. Go to the DNS Black Lists tab.
    1. Under Server Configuration, expand the localhost folder and select the Antispam folder.
    2. On the right panel, click the DNS Black Lists tab.
  2. On the DNS Black Lists tab, click Add to open the Add DNS BlackList dialog box.
  3. Enter the requested information in the Add DNS BlackList dialog box.
    • Name: Trend Micro RBL+ Server
    • Query Domain: activationcode.r.mail-abuse.com
    • Type: DNS
  4. Click OK.
  5. Click Apply to save the Server black list information.
  6. Select the Trend Micro RBL+ name, then click Enabled.

    If you would like to log the rejections, click the Logging tab.

Anti-spam logging is separate from other IMail Server logging and is configured on the anti-spam Logging tab.

Only black lists that are configured and enabled on this tab are available for use by a host. Once a black list is enabled for the server, it must be enabled for the host on the Connection Filtering tab.

A DNS black list must be enabled at the server level for it to be available for use by hosts. If a DNS black list is disabled, it is not available for hosts. If a DNS black list is in use by a host, but is then disabled at the server level, the black list is immediately disabled for the host and removed from the Connection Filtering tab.

Host Connection Filtering

Enable Trend Micro RBL+ in the Connection Filtering tab. To get to the Connection Filtering tab:

  1. Under Host Configuration, expand the localhost folder and select a host with an IP address.
  2. Expand the host, then select the Antispam folder.
  3. On the right panel, click the Connection Filtering tab.

Enabling/Disabling DNS Blacklists

  1. Decide whether you want the blacklist to be a Standard DNS blacklist, or a Trusted DNS blacklist.
     
    If an e-mail matches one of these blacklists, it is immediately deleted and no further spam checks are performed.
  2. Do one of the following:
    • If you choose to use "Standard DNS blacklists":
      1. Click Add in the appropriate grouping to open the Add DNS Blacklist dialog box.
      2. Select a blacklist.
      3. Select Delete Message after X matches.
      4. Enter "1" for the number of matches.
    • If you choose to use "Trusted DNS Blacklists":
      1. Click Add in the appropriate grouping to open the Add DNS Blacklist dialog box.
      2. Select a black list, then click OK.
        Note: Only blacklists that are configured and enabled for the server are displayed in the Add DNS Blacklist dialog box.
      3. To save the blacklists, click Apply at the top of the right panel.

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product, you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your Kerio Mail Server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Under Spam Filtering, add a new Internet blacklist.
  2. Enter the following:
    • 'DNS Suffix' activationcode.r.mail-abuse.com
    • 'Description' Trend Micro RBL+

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  3. Select Block the message.
  4. Make sure that the Ask the blacklist DNS servers directly option is unchecked.
  5. Click OK.

To configure your Domino server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Make sure you already have a Configuration Settings document for the server(s) to be configured.
  2. From the Domino Administrator, click the Configuration tab and expand the Messaging section.
  3. Click Configurations.
  4. Select the Configuration Settings document for the mail server or servers where you want to enable DNS blacklist filters.
  5. Click Edit Configuration.
  6. Go to Router/SMTP > Restrictions and Controls > SMTP Inbound Controls.
  7. Complete the following fields in the DNS Blacklist Filters section:
    • DNS Blacklist filters: Enabled
    • DNS Blacklist sites: activationcode.r.mail-abuse.com

      Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

    • Desired action: Log and reject message
    • Custom SMTP error response: Blocked by Trend Micro RBL+.

      Refer to the Email Reputation Services site.

  8. Click Save > Close.
  9. Reload the SMTP task, or update the SMTP configuration to put changes into effect.

    For more information on configuring filters on Domino Server, refer to the artile: Enabling DNS blacklist filters for SMTP connections.

To use Trend Micro Network Reputation Services DNSBL zone with a custom error message on a Mac server:

  1. On the Server Admin, select Mail in the Computers & Services pane.
  2. Click Settings.
  3. Select the Filters tab.
  4. Choose the Use these junk mail rejection servers option.
  5. Edit the list of servers by adding the DNS name of an RBL server:
    • Click Add to add a server to the list.
    • Click Remove to delete the currently selected server from the list.
    • Click Edit to change the currently selected server from the list.
    • Enter the domain name of the desired RBL server, such as "rbl.example.com".
    • Enter "activationcode.r.mail-abuse.com".

      Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

We currently do not have exact instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

We believe you are looking for the Anti-Spam Techniques tab. Under there, it looks like Blocked List Services might be what you are looking for. Insert this string where indicated:

activationcode.r.mail-abuse.com

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or just need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your Webshield server to use Trend Micro Network Reputation Services DNSBL zone:

  1. Go to E-mail (SMTP) > AntiSpam > Real-time Spam.
  2. Look for the Blackhole Server box.
  3. Click Add, then enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

To configure your Microsoft Exchange Server 2003 to use Trend Micro Network Reputation Services DNSBL zone with custom error messages:

  1. Under Global Settings, right-click Message Delivery and select Properties.
  2. Click the Connection Filter tab.
  3. Click New to add a new filter.
  4. Enter the following:
    • 'Display Name' Trend Micro RBL+
    • 'DNS Suffix of Provider' activationcode.r.mail-abuse.com

      Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

    • 'Custom Error Message to Return'
    • Host %0 was blocked using Trend Micro RBL+.

      Refer to the Email Reputation Services site.

  5. Click Return Status Code.
  6. Select the Match Filter Rule to Any Return Code option.
  7. Click OK.

    A warning message will pop up indicating that Connection, Recipient and Sender Filter must manually be enabled on specific SMTP virtual servers since they are not enabled by default.M

  8. Right-click Protocols/SMTP/Default SMTP Virtual Server select Properties.
  9. Go to the General tab.
  10. Click Advanced > Edit.
  11. Tick the Apply Connection Filter checkbox.
  12. Click OK.

For more information on configuring filters on Microsoft Exchange Server 2003, refer to the article: How to configure connection filtering to use Realtime Block Lists (RBLs) and how to configure recipient filtering in Exchange 2003

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product, you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing that your configuration is setup correctly, or need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your MailMarshal to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Under Server Properties, select the Host Validation tab.
  2. Create the following DNS Blacklist entries:
    • Name: Trend Micro RBL+
    • Domain: activationcode.r.mail-abuse.com
      Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.
    • Reply message.
       
      Some versions have separate boxes for Message Number and Description.
      • Message Number: 550
      • Message Description: {SenderIP} blocked using Trend Micro RBL+
        Refer to the Email Reputation Services site.

      If your version does not have separate boxes for the Message Number and Description fields, then enter both in the box provided.

    • 550 {SenderIP} blocked using Trend Micro RBL+.

      Refer to the Email Reputation Services site. 

  1. Edit your ../opt/ecelerity/etc/ecelerity.conf file:

    Module generic/spf_macros spf_macros {}
    Validate validate/sieve sieve {connect_phase1 = /opt/ecelerity/etc/rbl.siv}

  2. Place the following in /opt/ecelerity/etc/rbl.siv:

    $a = ec_dns_lookup "%{spfv1:ir}.activationcode.r.mail-abuse.com" "a"; if ec_test :matches "${a}" "127.1.0.*" {ec_disconnect 550 "Your host is in the TrendMicro RBL+, Refer to the Email Reputation Services site.

This will disconnect the connection right after it is created, in lieu of the SMTP banner. This is ideal for most situations, except for when XCLIENT is used. In those cases, "connect_phase1" should be changed to "mailfrom_phase1", which will process the script with the XCLIENT address.

We currently do not have instructions on how to configure this product to utilize Trend Micro Reputation Services. Refer to your product manual for information on the proper method to configure your MTA to utilize DNSBLs or block lists. Your vendor’s Technical Support organization should also be able to assist you with detailed configuration and setup options.

When you are configuring this product you will need to access our DNSBL zone. Insert this string where indicated:

activationcode.r.mail-abuse.com

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

If you have questions on setting up the appropriate DNSBL zone, the proper error message to utilize, testing if your configuration is setup correctly, or need general assistance in accessing the service, contact Trend Micro Technical Support.

To configure your Postfix to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

Postfix 2.x

  1. Find out if your OS supports hash or dbm tables by typing "postconf -m".

    If you see hash, use hash in Steps 2 and 3 below. If you see dbm, use dbm in Steps 2 and 3 below.

  2. Edit the main.cf file, then add our RBL and rbl_reply_maps entries.

    While it is really a client check, we have it in "smtpd_recipient_restrictions" (as recommended by many experts) since that is needed if you want to whitelist any recipients (e.g. Postmaster). Putting it as a recipient restriction only affects the timing (after the RCPT TO command), but not the effect.

     
    Make sure that the "smtpd_recipient_restrictions =" is one really long line. We added line breaks to show you the example.

    rbl_reply_maps = hash:/$config_directory/rbl_reply
    smtpd_recipient_restrictions = permit_mynetworks,
    reject_rbl_client activationcode.r.mail-abuse.com,
    reject_unauth_destination

  3. Create the rbl_reply map, then "postmap" it.

    Make sure each line is one long line, and that there are no leading spaces in front of the activation code lines.

    ....contents of rbl_reply file....
    activationcode.r.mail-abuse.com 550 Service unavailable; $rbl_class [$rbl_what]>
    blocked using Trend Micro RBL+.
    ....contents of rbl_reply file....

    You can also refer to the Email Reputation Services site.

  4. Save, then type "postmap hash:rbl_reply" to create the hash table.
  5. If postmap complains about unknown "hash", type "postconf -m".

    If you do not see hash, but you do see dbm, then change the word "hash" to dbm in steps 2 and 3 above.

  6. Reload postfix by typing "postfix reload".

To configure your Proofpoint server to use Trend Micro Network Reputation Services DNSBL zone:

  1. Open the GUI, then click System > Settings on the left menus.
  2. Click DNS Block List on the top right menu.
  3. Click Add.
  4. For the ID field, enter "TrendMicroRBL+".
  5. For the Domain field, enter "activationcode.r.mail-abuse.com".
  6. For the "Has TXT Records" field, click No.
    Note: Our DNSBL zones do not have TXT records.
  7. Click Save Changes.
  8. Tick the Enabled checkbox.
  9. Tick the TrendMicroRBL+ checkbox.
  10. Click Save Changes.

To configure your qmail server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

 
Our DNSBL zone does not contain TXT messages, so you must compile RBLSMTPD to use the "A" record patch. Otherwise, our service will not work.

Here is a sample run file to show you the rblsmtpd syntax.

..... sample /var/qmail/supervise/qmail-smtpd/run file…..
#!/bin/sh QMAILDUID=`id -u qmaild`
NOFILESGID=`id -g qmaild`
MAXSMTPD=`cat /var/qmail/control/concurrencyincoming`
exec /usr/local/bin/softlimit -m 2000000 \ /usr/local/bin/tcpserver -v -R -H -l 0 -x /etc/tcp.smtp.cdb -c "$MAXSMTPD" \
-u "$QMAILDUID" -g "$NOFILESGID" 0 smtp /usr/local/bin/rblsmtpd \
-b -r "activationcode.r.mail-abuse.com:blocked using Trend Micro RBL+,
..... sample /var/qmail/supervise/qmail-smtpd/run file…..

Refer to the Email Reputation Services site.

Your setup may use different options, but that is a working rblsmtpd -b -r "...." entry.

qmail will log rblsmtpd rejections in /var/log/qmail/smtpd/current.

@400000003fd843f92af91f1c rblsmtpd: xx.xx.xx.xx pid 19122: 553

Refer to the Email Reputation Services site.

To configure your Sidewinder to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

Option 1: If you have the newer version of Sidewinder

  1. On Sidewinder, go to the Service Configuration tab.
  2. Click Servers.
  3. Click Sendmail.
  4. Click m4 config on external burb. This will bring up a text editor.
  5. Locate the line FEATURE(`blacklist_recipients')dnl, then add the following:

    FEATURE(`dnsbl',`activationcode.r.mail-abuse.com', `"550 Mail from " $&{client_addr}"
    blocked using Trend Micro RBL+.

    Refer to the Email Reputation Services site.

    Make sure the FEATURE line you enter is one long line when you add it.

  6. Save and close the file
  7. Apply the change that will rebuild the Sendmail config and restart Sendmail.

Option 2: If you have the older version of Sidewinder

  1. On Sidewinder v5.2.1.10, edit the following file: ../etc/sidewinder/sendmail/sidewinder.X.mc

    where: "X" designates the burb.

  2. Locate the line FEATURE(`blacklist_recipients')dnl, then add the following:

    FEATURE(`dnsbl',`activationcode.r.mail-abuse.com', ` "550 Mail from " $&{client_addr}"
    blocked using Trend Micro RBL+.

    Refer to the Email Reputation Services site.

    Make sure the FEATURE line you enter is one long line when you add it.

  3. Rebuild your sendmail.cf and restart sendmail.
  4. Save the file.
  5. Rebuild the sendmail server with the command "reconfigure_mail rebuild".

To configure your Sendmail to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Here is a working sendmail.mc entry for Trend Micro RBL+ service:

    FEATURE(`dnsbl',`activationcode.r.mail-abuse.com', ` "550 Mail from " $&{client_addr}"
    blocked using Trend Micro RBL+.

    Refer to the Email Reputation Services site.

    Make sure the FEATURE line you enter is one long line when you add it.

  2. Rebuild your sendmail.cf and restart sendmail.

To configure your SonicWALL server to use Trend Micro Network Reputation Services DNSBL zone:

  1. Go to the RBL Domain Settings page.
  2. Tick the Enable RBL Domain checkbox to enable RBL checking.
  3. For the RBL Domain field, enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  4. Under the RBL Blocked Responses field, click Block ALL Responses.
  5. Click OK.
 
Some customers have told us that their version of SonicWALL has a 39 character limit and our RBL domain entry is 48 characters. If your version has this limitation, contact SonicWALL support to see if they have an update.

To configure your SpamAssassin server to use Trend Micro Network Reputation Services DNSBL zone:

SpamAssassin 3.00

http://www.spamassassin.org/

Edit the ../etc/mail/spamassassin/local.cf file, then add the following:

rewrite_header Subject *SPAM*
skip_rbl_checks 0
required_score     5
header RCVD_IN_TM_RBL_PLUS eval:check_rbl('tmrblplus','activationcode.r.mail-abuse.com.')
describe RCVD_IN_TM_RBL_PLUS Received via Trend Micro RBL+,
score RCVD_IN_TM_RBL_PLUS 5.0

Refer to the Email Reputation Services site.

Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

Make sure the header, describe, and score lines do not have any line breaks. This will add *SPAM* to the beginning of the subject line when a detection is made.

"skip_rbl_checks 0" should be default, but double-check to be sure.

The required_score needs to match the score you set for "RCVD_IN_TM_RBL_PLUS".

Trend Micro RBL+ service does not have TXT records for the error message. Refer to the Sun ONE Messaging Server 6.0 Administrator's Guide, December 2003. There is an example at the bottom of page 420 to specify the error message.

Example: Edit your MAPPINGS file and look for the FROM_ACCESS section.

Make sure there are two spaces at the start of the TCP line, and that each line is less than 252 characters.

FROM_ACCESS

TCP"25|*.*.*.*"SMTP*"tcp_local|* $[IMTA_LIB:dns_verify.so,dns_verify,+$4.$3.$2.$1.activationcode.r.mail-abuse.com.+$$N$$X5.5.0|IP$ $$1.$$2.$$3.$$4$ found$ on$ MAPS-RBL$ list+$$CTCP|$$0|25|$$1.$$2.$$3.$$4|$$5|SMTP$$6|$$7|tcp_local|$$8]

Rebuild and restart the mail service:

imsimta cnbuild
imsimta restart dispatcher

To configure SurfControl E-mail Filter for RBLs In the Server Configuration Settings window:

  1. Open the E-Mail Filter Monitor.
  2. Click on the Server Configuration icon on the toolbar.
  3. Click the SMTP tab.
  4. Tick the Enable RBL DNS Lookup checkbox.
  5. Highlight Anti Spam Servers (RBL) and enter the domain name of an RBL.
  6. Enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

To configure your Antigen server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Under Filtering/Mailhost Filtering, look for the Mailhosts List box.
  2. Click RBL Servers to see the current Filter Lists.
  3. Click Add.
  4. Enter "activationcode.r.mail-abuse.com" for the domain name of the RBL server, then save it.

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  5. Make sure the Filter is set to 'Enabled' Action: can be Skip/Purge/Identify (tag subject line).
  6. Select Purge to have it delete all email detected in Trend Micro service.

To configure your Symantec Anti-Virus for SMTP Gateways server to use Trend Micro Network Reputation Services DNSBL zone:

Symantec versions 3.1.0.29, 3.1.1.32, 3.2.x, 4.0

  1. Under Blocking Policy/Anti-Spam, click the small box on the left of DNSBL domain name.
  2. Enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  3. Do NOT tick the Identify spam by return codes checkbox, which appears under the domain name. This will block everything detected in Trend Micro service.
  4. Select Drop message.

To configure your Symantec Firewall to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Go to SMTPD Properties and under the Antispam Tab, tick the Use Black Hole List checkbox.
  2. Type "activationcode.r.mail-abuse.com" for the domain name for blackhole list.

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

    If nslookup 2.0.0.127.activationcode.r.mail-abuse.com fails, check the firewall log for the following dnsd warning:

    "<TIME> <FIREWALL> dnsd[277]: 343 dnsd Warning: Asked about Address for
    <IP ADDRESS>.activationcode.r.mail-abuse.com. -- server <SERVER IP> sent
    (<IP ADDRESS>.activationcode.r.mail-abuse.com. A 127.1.0.4) - Answer includes data
    under our authority."

To fix this, under DNS Records Tab, rename "127.in-addr.arpa" to 0.127.in-addr.arpa". If this does not work, rename "127.in-addr.arpa" to "1.0.0.127.in-addr.arpa".

The web page says to restart the firewall computer, but for some cases it works without a restart.

For more information refer to the Symantec Knowledgebase article: Antispam features of Symantec Raptor Firewall, Symantec VelociRaptor, and Symantec Enterprise Firewall

To configure your Symantec server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

Symantec Mail Security 4.5 for Microsoft Exchange

  1. To block by real-time blacklists, do one of the following:
    • Open Symantec Mail Security for the single server.
    • In the Symantec Mail Security for Microsoft Exchange console, select a server group on the left pane.
  2. On the left pane, expand Configuration.
  3. Click Spam Prevention Settings.
  4. Under Real-time Blacklist Blocking in the Domains of providers supporting IP-based lookup box, type the domains of the RBL providers.
     
    Separate domains with commas with no spaces between entries. RBL providers are queried in the order in which you list them. The first RBL provider to return a match during an SMTP connection results in the message being rejected, and no other RBL providers are queried.
  5. Enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  6. Click Save.

For Symantec Mail Security 5.0.3.360 for Microsoft Exchange, you will need to download a patch from Symantec, but it is not available yet as of July 26, 2006.

To configure your InterScan Messaging Security Suite to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Open the GUI, then click Configuration.
  2. Under Configuration, click Product Licenses.
  3. Under Network Reputation Services, click View license details.
  4. Enter your activation code.
  5. Under Configuration, select Network Reputation.
  6. Tick the Enable Network Reputation Service checkbox.
  7. Under Action, select Default: intelligent action.
  8. Click Save.

To configure your Tumbleweed Enterprise Mail Firewall to use Trend Micro Network Reputation Services:

  1. Login to the web manager.
  2. Click Setup on the lower portion of the left pane
  3. Click Relays.
  4. Scroll to DNSBL settings, then enter the RBL name.
  5. Select the action you wish to take if the sender is found on the RBL.
    • DNSBL Source Domain: activationcode.r.mail-abuse.com
    • Response to Client: Refuse connection with a permanent error response.
  6. Click Setup.
  7. Click Network Connections.
  8. Look for a "DNSBL" entry, then check the box beside it to enable it.

To configure your WatchGuard SpamScreen to use Trend Micro Network Reputation Service:

  1. In the Services Arena, double-click the SMTP Proxy icon. The service Properties dialog box opens.
  2. Go to the Properties tab.
  3. Click Incoming. The Incoming SMTP Proxy dialog box appears displaying the General tab.
  4. To check email against RBL servers, select Use RBLs to determine the email's spam classification. You can now configure the RBL/DNS servers.
  5. From the SpamScreen dialog box, click the RBL Lists tab.
  6. Click Add, then enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  7. Tick the activationcode.r.mail-abuse.com box.
  8. Click OK.

To configure your XWall server to use Trend Micro Network Reputation Services DNSBL zone with a custom error message:

  1. Under the Options/Spam tab, tick the Enable lookup of the IP address of the connecting host in the Spam Lookup Service database checkbox. Below that is the list of Services.
  2. Click Newand enter "activationcode.r.mail-abuse.com".

    Insert your unique valid "activation code" to replace the instructional text example. Do not include any dashes.

  3. For the Action field, select Block message transfer at the SMTP level.
  4. Click Apply.

To configure Message Inspector to use Trend Micro RBL+ Services DNSBL zone with a custom error message:

  1. Launch the Administration Client.
  2. Log in and go to Manage > MTA Configuration.
  3. Scroll downwards to the Custom configuration field.
  4. Enter the Realtime Blackhole List of your choosing.

    For Trend Micro RBL+, you should use the following:

    FEATURE(`dnsbl',`activationcode.r.mail-abuse.com',` "550 Mail from " $&{client_addr}" refused.

    Refer to the Email Reputation Services site.

    Make sure that is one really long line.

  5. Click Apply at the bottom to implement the change.
Premium
Internal
Rating:
Category:
Configure; Troubleshoot
Solution Id:
1053980
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.