This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

MTA - Whitelist and Blacklist

Hello, after setting up MTA Email Protection, I noticed there is no Whitelist or Blacklist.  Not only for admin on the XG, but I don't see anywhere in the User Portal for users to manage a White/Black list.  Will this feature be added soon?

Thanks



This thread was automatically locked due to age.
  • Hi to all,  it's ridiculous that a product that wants to be a market leader is missing basilar functions like white/blacklisting or LDAP user account sincyng with internal mail/domain server.

    I have switched from Trendmicro IMSVA but I am seriously thinking to switch back,  I can't lose hours to check tons of spam looking for false positives.

    This feature request seems to be opened from several months, I don't think I'm the only one that needs it.

    At the moment I am very unsatisfied with this product.

  • Hi

     

    I have White Listed Domains With MTA in XG 130.

     

    Here is how i did it:

    1) Configure MTA mode

    2) Goto Email -> Address Groups -> Add and create one for example in Name: WhiteListedDomains and in put the domain that you want to whitelist like this for example google.com

    3) Goto Email -> Policies and you have for sure one SMTP Policy in that policie click on edit and under Domains And Routing Target on Protected Domain add the Address Group Created Before (WhiteListedDomains) and save.

     

    And that's all

     

    I hope i could help.

  • But you don't have blacklist option...

  • I've tried configuring an SMTP policy as you've mentioned here and that doesn't work. 

  • Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

  • Ha! They call it a solution! Now tell me how to block a TLD? you know, these pesky .work or .party or just simple .ru spam emails? The "Blocked email addresses" list will not accept "*@*.work" :-( They should've made the first list not "Allowed IP addresses/FQDNs" but "Blocked.." instead. And extended the mask to include just TLDs.

  • To be honest, in my opinion blacklisting a complete TLD seems not be a good solution. So I wouldn't implement that too. You never know who's going to send an email from such a TLD next time. Besides that I only see a few spam mails coming through. For these I'd like to see the greylisting feature work correctly. I bet that even the last spam mails are dropped then. The mentioned solution is more important to me regarding the whitelisting, as for example some important senders get blacklisted and don't do anything about it.

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

  • Hi Jelle,

     

    Are you sure this solve it?

    We are having issue receiving and sending email to a partner... put their domain on the whitelisting list; even tried to put individual email.

    does not work... 

    goes into the advanced shell and found the block reason is still SPAM

    Funny enough this is a trustworthy partner that we have no issue communicating email before....

  • Hi,

    it works for us. We already whitelisted some addresses as they are blacklisted in public lists and the owners of the addresses don't even know what blacklisting is or means. So they will never care about being removed.

    Does your XG run in MTA mode?

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

  • Yes it does... MTA Mode.

    will posting a ticket tomorrow