Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

December 22, 2004 12:00 AM

Speed Up Mail Processing with Filter Order Adjustments

Windows IT Pro
InstantDoc ID #44870
Rating: (0)

I've discussed spam filtering, and in particular the use of blacklist services, in the recent past. I've been testing spam filtering mechanisms and want to share some insights.

Although blacklist services do help reduce the amount of unwanted email your users might receive in their inboxes, they also introduce some amount of processing overhead. Blacklist filters rely on DNS lookups, so message processing time is increased by the number of DNS lookups per message along with any network lag time involved in those lookups. Heavily used blacklist services sometimes take up to 1 second or longer to respond to queries.

The order in which your mail filters are used can make a performance difference. You might be able to reduce processing lag time by performing blacklist queries after other, simpler processing has taken place. For example, you might have filters that use whitelists or look for foreign languages, various countries of origin, various character sets, banned word lists, nonstandard message formatting, malformed HTML, banned scripts, file attachments, etc. These types of filters can typically process mail much faster than filters that rely on network communication to outsourced services such as blacklist providers. These types of filters can also process mail much faster than typical Bayesian filtering systems, especially Bayesian filters that have accumulated a big database of tokens (a database that probably grows larger by the hour). Whether you use Bayesian filters before or after blacklist service filters probably depends on how much mail your server processes and what kind of processing power your server has as compared to the sum of network lag time between your network and the blacklist service providers.

Another thing I've found, which is probably to be expected, is that blacklist services tend to respond to DNS queries much faster at night (in the US) than they do during the day. This phenomenon is undoubtedly due to far more people picking up mail during the day then at night. Most server-based filtering solutions are probably on dedicated connections and therefore process mail any time of day or night. But when you factor in the millions of individual computer users who run desktop-based mail filtering solutions, it stands to reason that there is a much greater load on blacklist services during daytime hours.

If your mail filtering solution lets you adjust the priority or processing order of the various filtering mechanisms that it uses, consider testing to see which priority or order works best for your needs. You might find that the out-of-the-box configuration works better after some tweaking.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.