Before Arrival filtering does not seem to work, any ideas?
There are some scenarios when the Before Arrival filtering cannot be used effectively, typical examples are: • incoming emails are filtered by an anti-virus/mail filtering proxy running in front of ORF • incoming emails are forwarded by a front-end server • incoming emails are received using a POP3 forwarder • incoming emails arrive via a secondary MX These scenarios can be recognized easily, check the ORF logs and if you find that all incoming emails are from the same IP address at the Before Arrival filtering point, most likely you experience the problem above. Before email arrival, the email delivery path is not known, so ORF identifies the sender as the incoming connection remote peer. In the scenarios above, these peers are not the actual sender servers, but the forwarders (proxy, front-end, etc.) so IP-based tests (including DNSBL tests) does not work, the emails may be whitelisted (due to the source intranet address). In this case, assign all tests to the On Arrival filtering po