Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Sender domain shows as (none)

Updated: 21 May 2010 | 6 comments
milindhf's picture
0 0 Votes
Login to vote

Hi,

We are using Symantec 8360 appliances as our SMTP gateway. When we try to generate a report we see that there are around 40000 mails under sender domain as (none). 

Also, out  of these 40k (none) mails it shows 45% as spam !!!

Could anyone please explain me what exactly these (none) message refers to?

Regards,

Milind HF
9819122588

Discussion Filed Under:

Comments

Ian McShane's picture
21
Jul
2009
2 Votes +2
Login to vote

Which report?

Hi,

Are you using BAP?  The rejected NDRs will usually have a NULL sender value which could explain this.
Also, you could see the messages rejected at connection time on a reputation basis in this report.  Because they are rejected before the SMTP conversation, we don't know the sending domain.

HTH

//ian

MichielB's picture
22
Jul
2009
0 Votes 0
Login to vote

Question, what is BAP? and we

Question, what is BAP? and we are getting the exact same thing, about 17.000 emails per day as (none) and i have no idea what this is or what i can do about it, any idea?

milindhf's picture
24
Jul
2009
0 Votes 0
Login to vote

BAP stands for --Bounce

BAP stands for --Bounce Attack Prevention

Milind HF :-)

Marco Bicca's picture
29
Jul
2009
0 Votes 0
Login to vote

The senders = (none) are

The senders = (none) are usually NDR's, if you are being hardly hit by NDR attacks I would suggest enabling BATV (Bounce Address Tag Verification) if your outbound mail goes out through the appliances otherwise it won't work.

Also, on version 8.x and later there was a major improvement on our reputation technology and it can probably increase the number of (none) a lot since the reputation will catch a lot more Spam.

Mikee..'s picture
31
Aug
2009
0 Votes 0
Login to vote

Is your appliance is

Is your appliance is configure for Inbound and Outboud, if yes then you can configure BAP, which will prevent Non-valid NDRs or NDR attack.

Optimus Prime's picture
06
Sep
2009
0 Votes 0
Login to vote

Hi Milindhf, The category

Hi Milindhf,

The category “none” are for senders that cannot be identified. For example, spam coming from zombie network. Zombies have been used extensively to send e-mail spam, an estimated 50-80% of all spam worldwide was sent by zombie computers. This allows spammers to avoid detection.

Below is the official symantec document about "Top sender report that shows sender (None)" for additional info.

http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2009080608193054

Please "mark it as solution" if this solves your concern.

;-)