Introduction to E-mail Filtering
Spam and virus's has been a problem for many years but only until recently has people started to become disgusted with it. Performance could also be a concern for many people. One of those people is me. I do not like to use an additional program to combat something that should not be there from the start.
This guide explains how I fight spam and gives a few pointers as to what you can do without downloading an additional program. I also have included information on how to spot an E-Mail virus without any additional software. Only thing it takes is a little knowledge and the ability to refrain from opening every E-Mail you get, regardless of where it came from. What people do not understand is that the user must do something to get a virus. It is not magic. That something, a very high percentage of the time, is click and open an infected E-Mail. DO NOT DO THIS!
Something to consider is the fact that the E-Mail filters and spam filtering do NOT work with HTTP E-Mail accounts, such as Hotmail and Yahoo. Most of those kind of services offer filtering of their own. Use it.
This guide also offers a sneak peek inside Black Viper's inbox.
As of this writing, I use Outlook Express 6, but most "newer" E-Mail clients have the same or similar type of features. In reality, the E-Mail client you chose could be much better than OE in many respects. I would love to use a more "feature rich" E-Mail client, but, sometimes I am rather hard set in my ways.
You also need to note two very important things:
- I DO NOT EVER display the "Preview Pane." This is a HUGE security issue.
- In OE 6, select View --> Layout --> Layout Tab --> uncheck Show preview pane.
- In Outlook 2002, select View --> Preview Pane (toggle: select to disable, select to enable)
- In Outlook 2003, select View --> Reading Pane --> select Off
- I DO NOT view "HTML stationary" (or any other inlined images) as the sender intended. I view ALL E-Mail as "plain text." This also reduces the chance of executing "malicious" HTML spam and makes for easier reading of high volumes of E-Mail from many different people.
- In OE 6, select Tools --> Options --> Read Tab --> check Read all messages in plain text. (Option available with IE6 SP1 installed).
- In Outlook 2002, you must download the latest service pack and add a setting in the registry. Instructions on how to do this is here: http://support.microsoft.com/default.aspx?scid=kb;en-us;307594
- Ensure you have the latest service pack already installed and you can download and apply this registry patch: Outlook2002PlainTextFix.zip ~ 330 bytes
- In Outlook 2003, select Tools --> Options --> Preferences Tab --> E-mail options... button --> check Read all standard mail in plain text.
1) Shall we begin? (Image 1.1)After a small break away from the computer, I had quite a few E-Mails sitting around. Note: According to the screen shot, not one of them is in my "Inbox." What I have done is used filters to distribute them according to predefined rules. This screen shot was taken right after I opened OE. More on filters later, but first, a tour of the results of the filters. | ||||||||||||
2) Deleted Items. (Image 1.2)Out of 275 E-Mails, 58 of them were automatically deleted without any actions by me. What this filter does is take ALL E-Mail not directly addressed to me and delete it. Absolutely no legitimate E-Mail sent by a "real" person or company will ever falsify where the E-Mail is going TO! Initially, I had recommended in my E-Mail Filtering Guide to automatically forward to uce@ftc.gov and delete all E-Mails that did not pass my spam filters. This procedure was flawed with respect to how Outlook Express handles the action. What Outlook Express does is remove the spammers from address and replace it with the E-Mail account currently in use. After realizing this problem, I removed the recommendation. However, this step opened up a whole new can of worms. For the E-Mails that actually are going to me, these are caught by my "Blocked Senders List" filter that automatically deletes E-Mails originating from a particular domain or person on a domain. Again, more on the actual filters later. | ||||||||||||
3) blackviper.com Inbox. (Image 1.3)After removing a few "important" E-Mails, I have taken the screen shot displayed as Image 1.3. Many people ask "Why do you automatically place a subject line in your E-Mails?" This is the reason. It is extremely easy to see that these people have visited my web site and actually clicked on the link located on my domain to contact me. I have little fear as to whether or not it is spam. Also, a VERY important note: Look at the "average" size of these E-Mails. Most are between 3KB and 6KB with none of them over 10KB. This will be important in the next screen shot of the "Filtered Spam." Something else to understand. Even though I removed the "From" column for these screen shots, I always look to see "who" it came from. In the above screen shot, the From column is not removed and you can actually see the pathetic E-Mails addresses and names that these spams "seem to come from." | ||||||||||||
4) This is my Filtered Spam. (Image 1.4)Some of these E-Mails are legitimate. Some are virus's. Others are spam. Can you spot each? I have a filter to catch "common" subject matter and code it in Red. Very rarely (especially using a "default" subject line) does my filters ever tag a "real" message with Red. I must thank all spammers that attempt to confuse E-Mail filters by adding random characters to the end of a subject line. When this pathetic attempt at getting through to E-Mail users started, it annoyed me. However, after it became a "wide spread practice," I expanded my subject line column way out and scan only the end of the line. If it contains gibberish, it is gone. It has reduced the time I take to filter E-Mails considerably. You will also notice that several E-Mails display "..." on even the short subject lines. This means that the full subject does not fit in the column and more information exists. This common practice just shows that spammers add many spaces to their messages and then place the random characters out of "normal" view. Expanding the column reveals the truth. Also here, you see MANY messages that are well over 100KB. These are absolutely, positively a virus. Zero doubt. Why? Because any "real" person that would send any attachment would actually "attach" the file. Look on the far left column of the next shot. | ||||||||||||
5) Attachment reporting. (Image 1.5)Not one of these E-Mails, sorted by size, reports having an attachment. Now, understand that an E-Mail that is 180KB is a rather large amount of typing. This should give you the first clue about the origin of these E-Mails and the destructive intent. However, some E-mail programs, if using "HTML" stationery and such, do not report attachments of .jpg and .gif's if they are part of the layout. For example, a background picture and a .jpg signature block. Take note: Out of 8400 E-Mails in the last year, only 16 of those have had "large" images (over 50KB worth) included with them as "normal" E-Mails. Please, for the love of dial-up users around the world... Do not send 295KB picture as a "normal" part of your E-Mail. For the sake of time, I now bounce all E-Mails that are larger than 50KB. Can you confirm that this E-Mail is a virus without "opening" it? Yes, and I will show you how following this short disclaimer: ABSOLUTELY, NEVER, EVER double click these files to open them! You WILL be infected. This method is NOT intended to substitute a virus scanner with the eyes of an average user. However, my network has never been infected by a virus. Ever. What AV software do I run daily? None. I do not visit "questionable" web sites, I utilize a hardware firewall and never open an attachment sent via E-Mail. What is the best defense anyone can have? Common sense.
How can you create filters to do the same as what I have displayed here? Easy. READ MORE... How to filter your E-Mail using Outlook ExpressSpam and virus's do not have to get you down. Here, I take a look at the filters I use for the results you viewed on the previous page. It is not magic. With effective filters, a huge amount of spam can be dealt with behind the scenes with tools you already have at your disposal.
I hope this offered some insight into the techniques I use to, not only fight spam, but identify the clever virus's out there attempting to suck up bandwidth from the rest of the internet. If this has helped you, feel free to Contact BV, but, remember, leave the default subject line intact... or your E-Mail could be tagged and automatically deleted as spam. |