Skip to main content

Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

Loading...
Loading...

FIX: Spam not being identified due to "bare CR" or "bare LF" characters

Expand / Collapse


This article applies to:

  • MailMarshal SEG
  • MailMarshal SPE

Symptoms:

  • Some spam not being identified by SpamProfiler or other technologies

Causes:

  • Messages containing "bare carriage returns" or "bare linefeeds" in the header area may not be fully processed by some parts of SEG
  • Some spam campaigns are formatted with these bare characters

Resolution:

To resolve this issue, choose to fix or block messages containing these characters:

  1. Navigate to the appropriate setting location:
    • In the MailMarshal 10.0 or above Management Console, navigate to System Configuration > Receiver Properties > Advanced
    • In the MailMarshal 8.X Configurator, navigate to Tools > MailMarshal SEG Properties > Receiver Properties > Advanced
    • In SPE 4.3 and above Admin Console, see Server Configuration > (array name) > Services > Receiver
  2. Set the values for Bare carriage returns and Bare line feeds to "Fix".
    • You can also choose "Block" to immediately deadletter messages with this issue. However, legitimate mail may be affected.
  3. Commit configuration.

Notes:

  • A bare carriage return is the 'CR' (carriage return) character without an accompanying 'LF' (linefeed).
  • A bare linefeed is an 'LF' (linefeed) without a preceding 'CR' (carriage return).
  • Bare carriage returns and bare linefeeds are technically not allowed in email messages. SEG ignores this standard by default because legitimate messages are sometimes malformed in this way.

To contact LevelBlue about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.