locked
How to read X-Forefront-Antispam-Report RRS feed

  • Question

  • Hello

    I'm using Microsoft Forefront Protection 2010 for Exchange Server on edge Exchange2010 SP2.

    How I read X-Forefront-Antispam-Report.

    X-Forefront-Antispam-Report: CIP:*.*.*.*;KIP:(null);UIP:(null);IPV:NLI;H:*****.jp.***.com;RD:*****.jp.***.com;EFVD:NLI

    What CIP,KIP,UIP,EFVD:NLI stand for?

    Thanks for any ideas.

    Hiroko

    Thursday, April 24, 2014 5:25 AM

Answers

  • Hi,

    here is a description of this Header:
    http://technet.microsoft.com/en-us/library/dn205071(v=exchg.150).aspx

    It contains not all fields but this information: "Other fields in this header are used exclusively by the Microsoft anti-spam team for diagnostic purposes."

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Thursday, April 24, 2014 5:49 AM
  • Hi,

    an IP address earns a negative reputation when suspicious activity, such as spam or viruses originating from that address are detected. Those IP addresses are in a database and every incoming email is checked against the database.

    Greetings

    Christian


    Christian Groebner MVP Forefront

    • Marked as answer by Susie Long Friday, April 25, 2014 8:32 AM
    Friday, April 25, 2014 6:50 AM

All replies

  • Hi,

    here is a description of this Header:
    http://technet.microsoft.com/en-us/library/dn205071(v=exchg.150).aspx

    It contains not all fields but this information: "Other fields in this header are used exclusively by the Microsoft anti-spam team for diagnostic purposes."

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Thursday, April 24, 2014 5:49 AM
  • Thanks for your help.

    There are no mention on Japanese var.. 

    Hiroko

    Friday, April 25, 2014 2:57 AM
  • I read more about this article.

    http://technet.microsoft.com/en-us/library/dn205071(v=exchg.150).aspx

    The artile says IPV:NLI meane "The IP address was not listed on any IP reputation list.".

    What IP reputation stands for.

    Is it used exclusively by the Microsoft anti-spam team??

    Hiroko

    Friday, April 25, 2014 5:45 AM
  • Hi,

    an IP address earns a negative reputation when suspicious activity, such as spam or viruses originating from that address are detected. Those IP addresses are in a database and every incoming email is checked against the database.

    Greetings

    Christian


    Christian Groebner MVP Forefront

    • Marked as answer by Susie Long Friday, April 25, 2014 8:32 AM
    Friday, April 25, 2014 6:50 AM
  • Thanks for your quick response.

    I got what IP reputation is.

    Then who has a database?
    Microsoft or other site?

    Hiroko

    Friday, April 25, 2014 7:15 AM
  • Hi,

    there are many databases available almost any antispam vendor has one. I'm sure Microsoft has one too.

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Friday, April 25, 2014 7:19 AM
  • Thanks so much your help!!

    Hiroko

    Friday, April 25, 2014 7:30 AM
  • Hi,

    In addition, the Microsoft IP Reputation Service is an IP Block list service offered exclusively to Exchange customers and the Microsoft IP Reputation Service data is only available when you use FPE.

    Best regards,

    Susie

    Friday, April 25, 2014 7:40 AM
  • So, if specify "X-Forefront-Antispam-Report", using the Reputation list exclusively to Microsoft FPE?

    Thanks for your additional information!

    Hiroko


    Friday, April 25, 2014 8:08 AM
  • And anyone without the Microsoft anti-spam team can see or check the Microsoft IP Reputation ?

    Hiroko

    Friday, April 25, 2014 10:21 AM
  • Hi,

    the database is not public. If you have enabled IP filtering in FPE it will use this database.

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Friday, April 25, 2014 10:48 AM
  • Thanks for your response!!

    So, if I have particular IP address then want to know if it on the Microsoft IP Reputation or not, I don't have way to search?

    Hiroko
    Monday, April 28, 2014 1:14 AM
  • Hi,

    as far as I know you can't.

    Greetings

    Christian


    Christian Groebner MVP Forefront

    Monday, April 28, 2014 6:55 AM
  • I see.

    Thanks a lot!!

    Hiroko

    Monday, April 28, 2014 8:45 AM
  • Hi Hiroko

    Not too far from now all programers in the world have been affecte by this forefront antispam system that involves everyone with a hotmail account...

    Hotmail mark emails as spam with content filtering, how?? why they act that way?they block all our communications even when we are truly authenticate by dkim and spf

    Hiroko you should get out micrsoft

    Saturday, March 4, 2017 9:37 PM