The following are general recommendations for configuring MDaemon's security, spam, and antivirus features provided by MDaemon AntiVirus.
Security configurations may very from server to server and certain servers may need to be adjusted accordingly.
The following screenshots where taken from MDaemon version 23.0. Prior versions may not contain all of the features below.
A valid MDaemon AntiVirus key must be activated in order to change AntiVirus settings.
Please direct any questions to our technical support team for more information.
Recommended Security Settings
- Navigate to the MDaemon GUI
- Select Security
- Select Security Settings
Security Settings
- Relay Control
- Reverse Lookups
- POP Before SMTP
- Trusted Hosts
Hosts added to this list will bypass all Security Settings. - Trusted IPs
IP Addresses added to this list will bypass all Security Settings.
Sender Authentication
- IP Shield
- SMTP Authentication
- SPF Verification
How to enable SFP Verification and create a simple SPF record - DKIM Verification
- DKIM Signing
Click here for more information on configuring the mail server to sign mail using DKIM - DKIM Settings
- DMARC Verification
Click here for more information on configuring DNS records for DMARC - DMARC Reporting
- DMARC Settings
Screening
- Sender Block List
- Recipient Block List
Local domains and/or addresses should not normally exist on this list - IP Screen
- Host Screen
Recommended values have been pulled from our recommended host screen article. - SMTP Screen
- Hijack Detection
- Spambot Detection
- Location Screening
Use this feature to disable SMTP/IMAP/POP connections from unauthorized regions of the world. Learn more about Location Screening here.
- MDaemon
A third party or self-signed certificate must exist in the server's certificate store to use SSL, STARTTLS, and STLS. The use of a self-signed certificate is not recommended.
How do I get a free SSL certificate from Let's Encrypt? - Webmail
You may use the same certificate above for secure Webmail connections over HTTPS. HTTPS only and HTTP redirected to HTTPS will disable non-SSL connections from occurring for Webmail. - Remote Administration
You may use the same certificate for Webmail and/or MDaemon SSL connections. HTTPS only and HTTP redirected to HTTPS will disable non-SSL connections from occurring for remote administration sessions. - No STARTTLS List
Hosts/IPs added to this list will be exempt from using STARTTLS during SMTP sessions. - STARTTLS List
Hosts/IPs added to this list will be required to use STARTTLS. - SMTP Extensions
- DNSSEC
- Let's Encrypt
This menu is used to generate and apply a valid certificate using MDaemon and Let's Encrypt. See the article below for assistance setting one up in MDaemon.
How do I get a free SSL certificate from Let's Encrypt?
- Backscatter Protection
- Tarpitting
- Greylisting
- LAN Domains
Domains listed here are considered by MDaemon to be part of the local area network (LAN).. - LAN IPs
IPs listed here will be considered by MDaemon to be part of the local area network (LAN). - Site Policy
Text transmitted during the initial connection of each SMTP session.
Policies should be limited to 15 lines with 75 characters per line.
Recommended Dynamic Screening Settings
- Select Security
- Select Dynamic Screening...
- Options/Customize
- Authentication Failure Tracking
These are default values and can be modified as desired. - Protocols
- Notifications
These options can be modified as desired. - Dynamic Block List
IP addresses can be added here permanently or expire after an desired date. CIDR notation and wildcards(*) are accepted here. - Dynamic Allow List
Exempt IP addresses or ranges. Default settings are pictured below.
Recommended AntiVirus Settings
MDaemon AntiVirus must be activated to access this menu.
- Open the MDaemon GUI
- Select Security
- Select AntiVirus
- Select Virus Scanning
Recommended Spam Filter Settings
- Open the MDaemon Configuration Session
- Select Security
- Select Spam Filter
Spam Filter
Messages scoring over 5.0 points will be marked as spam and messages scoring over 12.0 points will be rejected entirely. These are default values and can be modified as desired.
Bayesian Classification
Bayesian Auto-learning
Spam Daemon (MDSpamD)
No changes should be made here unless instructed to from technical support.
Allow List (automatic)
Allow List (no filtering)
Local domains/addresses should not be on this list unless messages to a specific account should receive spam-filter exempt mail.
Allow List (by recipient)
Local domains/addresses should not be on this list unless needed.
Allow List (by sender)
Local domains/addresses should not be on this list unless needed.
Block List (by sender)
Local domains/addresses should not be on this list unless needed.
Updates
Reporting
Settings
DNS-BL
Hosts
The SpamHaus ZEN block list (zen.spamhaus.org) is a default DNS-Blocklist applied in new MDaemon installations.
In the image below, another DNS-BL from SpamCop, has been configured to check incoming mail against the provider's block lists. Other DNS-BL hosts exist in free, fair-use, and subscription capacities and can be added to MDaemon for increased security against malicious and/or compromised servers.
Allow List
This file lists IP addresses of sites that are exempt from DNSBL lookups. Local domains/addresses should not be on this list.
Settings
Spamhaus Data Query Service (DQS)
This feature is available in MDaemon versions 23.0.2 and above.
Spamhaus Data Query Service offers increased protection utilizing multiple block lists. Once an account has been created with SpamHaus, enter your unique DQS key in the text box below to activate these services in MDaemon.
Getting started with Data Query Service