Answered by:
How to read X-Forefront-Antispam-Report

Question
-
Hello
I'm using Microsoft Forefront Protection 2010 for Exchange Server on edge Exchange2010 SP2.
How I read X-Forefront-Antispam-Report.
X-Forefront-Antispam-Report: CIP:*.*.*.*;KIP:(null);UIP:(null);IPV:NLI;H:*****.jp.***.com;RD:*****.jp.***.com;EFVD:NLI
What CIP,KIP,UIP,EFVD:NLI stand for?
Thanks for any ideas.
Hiroko
Thursday, April 24, 2014 5:25 AM
Answers
-
Hi,
here is a description of this Header:
http://technet.microsoft.com/en-us/library/dn205071(v=exchg.150).aspxIt contains not all fields but this information: "Other fields in this header are used exclusively by the Microsoft anti-spam team for diagnostic purposes."
GreetingsChristian
Christian Groebner MVP Forefront
- Proposed as answer by Christian Groebner Friday, April 25, 2014 7:31 AM
- Marked as answer by Susie Long Friday, April 25, 2014 8:32 AM
Thursday, April 24, 2014 5:49 AM -
Hi,
an IP address earns a negative reputation when suspicious activity, such as spam or viruses originating from that address are detected. Those IP addresses are in a database and every incoming email is checked against the database.
Greetings
Christian
Christian Groebner MVP Forefront
- Marked as answer by Susie Long Friday, April 25, 2014 8:32 AM
Friday, April 25, 2014 6:50 AM
All replies
-
Hi,
here is a description of this Header:
http://technet.microsoft.com/en-us/library/dn205071(v=exchg.150).aspxIt contains not all fields but this information: "Other fields in this header are used exclusively by the Microsoft anti-spam team for diagnostic purposes."
GreetingsChristian
Christian Groebner MVP Forefront
- Proposed as answer by Christian Groebner Friday, April 25, 2014 7:31 AM
- Marked as answer by Susie Long Friday, April 25, 2014 8:32 AM
Thursday, April 24, 2014 5:49 AM -
Thanks for your help.
There are no mention on Japanese var..
Hiroko
Friday, April 25, 2014 2:57 AM -
I read more about this article.
http://technet.microsoft.com/en-us/library/dn205071(v=exchg.150).aspx
The artile says IPV:NLI meane "The IP address was not listed on any IP reputation list.".
What IP reputation stands for.
Is it used exclusively by the Microsoft anti-spam team??
Hiroko
Friday, April 25, 2014 5:45 AM -
Hi,
an IP address earns a negative reputation when suspicious activity, such as spam or viruses originating from that address are detected. Those IP addresses are in a database and every incoming email is checked against the database.
Greetings
Christian
Christian Groebner MVP Forefront
- Marked as answer by Susie Long Friday, April 25, 2014 8:32 AM
Friday, April 25, 2014 6:50 AM -
Thanks for your quick response.
I got what IP reputation is.
Then who has a database?
Microsoft or other site?Hiroko
Friday, April 25, 2014 7:15 AM -
Hi,
there are many databases available almost any antispam vendor has one. I'm sure Microsoft has one too.
Greetings
Christian
Christian Groebner MVP Forefront
Friday, April 25, 2014 7:19 AM -
Thanks so much your help!!
Hiroko
Friday, April 25, 2014 7:30 AM -
Hi,
In addition, the Microsoft IP Reputation Service is an IP Block list service offered exclusively to Exchange customers and the Microsoft IP Reputation Service data is only available when you use FPE.
Best regards,
Susie
Friday, April 25, 2014 7:40 AM -
So, if specify "X-Forefront-Antispam-Report", using the Reputation list exclusively to Microsoft FPE?
Thanks for your additional information!
Hiroko
Friday, April 25, 2014 8:08 AM -
And anyone without the Microsoft anti-spam team can see or check the Microsoft IP Reputation ?
Hiroko
Friday, April 25, 2014 10:21 AM -
Hi,
the database is not public. If you have enabled IP filtering in FPE it will use this database.
Greetings
Christian
Christian Groebner MVP Forefront
Friday, April 25, 2014 10:48 AM -
Thanks for your response!!
So, if I have particular IP address then want to know if it on the Microsoft IP Reputation or not, I don't have way to search?
HirokoMonday, April 28, 2014 1:14 AM -
Hi,
as far as I know you can't.
Greetings
Christian
Christian Groebner MVP Forefront
Monday, April 28, 2014 6:55 AM -
I see.
Thanks a lot!!
Hiroko
Monday, April 28, 2014 8:45 AM -
Hi Hiroko
Not too far from now all programers in the world have been affecte by this forefront antispam system that involves everyone with a hotmail account...
Hotmail mark emails as spam with content filtering, how?? why they act that way?they block all our communications even when we are truly authenticate by dkim and spf
Hiroko you should get out micrsoft
Saturday, March 4, 2017 9:37 PM