locked
Filter only "triggers" for some recipients RRS feed

  • Question

  • I have set up a Policy Rule to allow all email from a specific sender through the filter.
     
    This Policy Rule does "trigger" when sent to some recipients and there is one recipient in particular where the Policy will not "trigger" and the e-mail gets Marked for the Spam Quarantine.
     
    All users are on the same domain and traffic scope.
     
    Thanks!
    Monday, November 5, 2012 2:22 PM

Answers

  • It took the rule a full 24 hours to begin working "all the time".

    The rule seemed to work sporadically when it was first created.  It seems to be working all the time now.

    Thanks for you help.

    • Marked as answer by koby16 Tuesday, November 6, 2012 2:35 PM
    Tuesday, November 6, 2012 2:35 PM

All replies

  • Hi,

    have you checked the message trace?

    http://blogs.technet.com/b/alexgray/archive/2012/06/28/tracing-a-message-in-the-fope-admin-centre.aspx

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Monday, November 5, 2012 4:02 PM
  • Yes.  That is how I confirmed that the Rule was not "triggering" for the specific user.  Here are the details:

    1. Created a Filter so that all messages from a specific e-mail address outside of our domain (xyz@acme.com) would bypass filtering.
    2. Sent a message from that e-mail address (xyz@acme.com) to user "A" inside of our domain.
    3. Checked the trace and it stated that the message did not pass filtering.
    4. Sent the same message from the same source e-mail address (xyz@acme.com) to user "B" inside of our domain.
    5. Checked the trace and it stated that the message used the filter setup in step 1.

    It seems that the Forefront Online Protection Administration Center is down at the moment so I cannot get the exact messages from the message trace.

    Thanks!

    Monday, November 5, 2012 4:56 PM
  • Hi,

    I've such a policy too to whiteliste some domains and the result in the trace looks always like this:

    Passed Filtering (Hit Policy Allow rule ID 85xxxx)

    I think there's something wrong with your policy rule.

    Can you post the settings here?

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Monday, November 5, 2012 9:58 PM
  • It took the rule a full 24 hours to begin working "all the time".

    The rule seemed to work sporadically when it was first created.  It seems to be working all the time now.

    Thanks for you help.

    • Marked as answer by koby16 Tuesday, November 6, 2012 2:35 PM
    Tuesday, November 6, 2012 2:35 PM
  • Hi,

    that's strange. Normally it takes about 45 minutes until the new settings are replicated all over the datacenters.

    Thanks for the feedback!

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Tuesday, November 6, 2012 2:43 PM