---
title: What are the recommended Security, Dynamic Screening, Spam Filter, and AntiVirus Settings in MDaemon?
description: The following are general recommendations for configuring MDaemon's security, spam, and antivirus features provided by MDaemon AntiVirus.
---

[Skip to content](https://knowledge.mdaemon.com/recommended-security-dynamic-screening-spam-filter-anti-virus-settings#main-content)

[![](https://knowledge.mdaemon.com/hs-fs/hubfs/MDaemon-Technologies_logo.png?width=200&height=150&name=MDaemon-Technologies_logo.png)](https://mdaemon.com/)

- [Knowledge Base Home](https://knowledge.mdaemon.com/)
- [Go to www.mdaemon.com](https://mdaemon.com/)

Open main navigation

Close main navigation

- [Knowledge Base Home](https://knowledge.mdaemon.com/)
- [Go to www.mdaemon.com](https://mdaemon.com/)
- [Contact Us](https://mdaemon.com/pages/contact-us)

[Contact Us](https://mdaemon.com/pages/contact-us)

 Knowledge Base

- There are no suggestions because the search field is empty.

1. [Knowledge Base Home](https://knowledge.mdaemon.com/?hsLang=en)
2. [MDaemon Email Server](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en)

# What are the recommended Security, Dynamic Screening, Spam Filter, and AntiVirus Settings in MDaemon?

## The following are general recommendations for configuring MDaemon's security, spam, and antivirus features provided by MDaemon AntiVirus.

Security configurations may very from server to server and certain servers may need to be adjusted accordingly.  

The following screenshots where taken from MDaemon version 23.0.  Prior versions may not contain all of the features below.

A valid MDaemon AntiVirus key must be activated in order to change AntiVirus settings.

Please direct any questions to our technical support team for more information.

[Click here to contact us.](https://mdaemon.com/pages/support-request-form)

  
**Recommended Security Settings**

1. Navigate to the MDaemon GUI
2. Select **Security**
3. Select **Security Settings**

**Security Settings**

1. **Relay Control  
   ![Screenshot 2026-04-06 134549](https://knowledge.mdaemon.com/hs-fs/hubfs/Screenshot%202026-04-06%20134549.png?width=670&height=558&name=Screenshot%202026-04-06%20134549.png)**
2. **Reverse Lookups**  
   ![Screenshot 2026-04-06 134638](https://knowledge.mdaemon.com/hs-fs/hubfs/Screenshot%202026-04-06%20134638.png?width=670&height=554&name=Screenshot%202026-04-06%20134638.png)
3. **POP Before SMTP  
   ![Screenshot 2026-04-06 134748](https://knowledge.mdaemon.com/hs-fs/hubfs/Screenshot%202026-04-06%20134748.png?width=670&height=558&name=Screenshot%202026-04-06%20134748.png)**
4. **Trusted Domains**  
   The values here are compared to the domain in MAIL FROM commands, not the FQDN in HELO/EHLO commands. Use with care and do not make a domain trusted unless you know you need to do so.  
   ![Screenshot 2026-04-06 134819](https://knowledge.mdaemon.com/hs-fs/hubfs/Screenshot%202026-04-06%20134819.png?width=670&height=561&name=Screenshot%202026-04-06%20134819.png)
5. **Trusted IPs**  
   IP Addresses added to this list will bypass Security Settings such as SMTP Authentication and other security settings that exclude trusted IPs. Use with care and do not make an IP trusted unless you know you need to do so.  
   ![Screenshot 2026-04-06 134839](https://knowledge.mdaemon.com/hs-fs/hubfs/Screenshot%202026-04-06%20134839.png?width=670&height=557&name=Screenshot%202026-04-06%20134839.png)

**Sender Authentication**

1. **IP Shield  
   ![06_ip_shield](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/06_ip_shield.png?width=670&height=527&name=06_ip_shield.png)**
2. **SMTP Authentication  
   ![07_smtp_authentication](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/07_smtp_authentication.png?width=670&height=527&name=07_smtp_authentication.png)**
3. **SPF Verification**  
   [How to enable SFP Verification and create a simple SPF record](https://knowledge.mdaemon.com/_hcms/analytics/search/conversion?redirect=aHR0cHM6Ly9rbm93bGVkZ2UubWRhZW1vbi5jb20vc3BmLXZlcmlmaWNhdGlvbi1yZWNvcmQtY3JlYXRpb24%3D&ct=SEARCH&pid=6572702&cid=101104507657&t=c3Bm&d=knowledge.mdaemon.com&c=5&rp=1&ab=false&opcid=&rs=UNKNOWN&hs-expires=1714747612&hs-version=1&hs-signature=APUk-v7UCloPBQ-zItJxFviL3YbMGaMHzg&hsLang=en)  
   ****![08_spf_verification](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/08_spf_verification.png?width=670&height=557&name=08_spf_verification.png)****
4. **DKIM Verification  
   ![09_dkim_verification](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/09_dkim_verification.png?width=670&height=557&name=09_dkim_verification.png)**
5. **DKIM Signing**  
   [Click here for more information on configuring the mail server to sign mail using DKIM](https://knowledge.mdaemon.com/how-to-enable-dkim-signing-and-configure-primary-and-additional-domain-records?hsLang=en)  
   **![10_dkim_signing](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/10_dkim_signing.png?width=670&height=556&name=10_dkim_signing.png)**
6. **DKIM Settings  
   ![11_dkim_settings](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/11_dkim_settings.png?width=670&height=558&name=11_dkim_settings.png)**
7. **DMARC Verification  
   [Click here for more information on configuring DNS records for DMARC](https://knowledge.mdaemon.com/how-to-enable-dmarc-and-configure-records?hsLang=en)  
   ![12_dkim_verification](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/12_dkim_verification.png?width=670&height=554&name=12_dkim_verification.png)**
8. **DMARC Reporting  
   ![13_dmarc_reporting](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/13_dmarc_reporting.png?width=670&height=556&name=13_dmarc_reporting.png)**
9. **DMARC Settings  
   ![14_dmarc_settings](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/14_dmarc_settings.png?width=670&height=554&name=14_dmarc_settings.png)**

**Screening**

1. **Sender Block List  
   ![17_mdaemon-sender-blocklist](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/17_mdaemon-sender-blocklist.png?width=670&height=558&name=17_mdaemon-sender-blocklist.png)**
2. **Recipient Block List**  
   Local domains and/or addresses should not normally exist on this list
3. **IP Screen  
   ![19_mdaemon_IP-screen](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/19_mdaemon_IP-screen.png?width=670&height=556&name=19_mdaemon_IP-screen.png)**
4. **Host Screen**  
   Recommended values have been pulled from our [recommended host screen article](https://knowledge.mdaemon.com/what-are-the-recommended-host-screen-settings-for-mdaemon?hsLang=en).  
   ![20_mdaemon_host-screen](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/20_mdaemon_host-screen.png?width=670&height=557&name=20_mdaemon_host-screen.png)
5. **SMTP Screen  
   ![21-mdaemon_smtp-screen](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/21-mdaemon_smtp-screen.png?width=670&height=556&name=21-mdaemon_smtp-screen.png)**
6. **Hijack Detection  
   ![22-mdaemon_hijack-detection](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/22-mdaemon_hijack-detection.png?width=670&height=556&name=22-mdaemon_hijack-detection.png)**
7. **Spambot Detection  
   ![23_mdaemon_spambot_security](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/23_mdaemon_spambot_security.png?width=670&height=557&name=23_mdaemon_spambot_security.png)**
8. **Location Screening**  
   Use this feature to disable SMTP/IMAP/POP connections from unauthorized regions of the world. [Learn more about Location Screening here.](https://knowledge.mdaemon.com/how-to-block-incoming-connections-based-on-geographical-location-location-screening?hsLang=en)  
   **![24-mdaemon_location_screening](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/24-mdaemon_location_screening.png?width=670&height=554&name=24-mdaemon_location_screening.png)**

**SSL & TLS**

1. **MDaemon**  
   A third party or self-signed certificate must exist in the server's certificate store to use SSL, STARTTLS, and STLS.  The use of a self-signed certificate is not recommended.  
   [**How do I get a free SSL certificate from Let's Encrypt?**](https://knowledge.mdaemon.com/_hcms/analytics/search/conversion?redirect=aHR0cHM6Ly9rbm93bGVkZ2UubWRhZW1vbi5jb20vaG93LXRvLWdlbmVyYXRlLWEtZnJlZS1zc2wtY2VydGlmaWNhdGUtdXNpbmctbGV0cy1lbmNyeXB0&ct=SEARCH&pid=6572702&cid=29087396689&t=bGV0J3MgZW5jcnlwdA%3D%3D&d=knowledge.mdaemon.com&c=5&rp=1&ab=false&opcid=&rs=UNKNOWN&hs-expires=1714749855&hs-version=1&hs-signature=APUk-v5FEvdI0ppAi1d0rwAxmvmedPCKMQ&hsLang=en)  
   ![26-mdaemon-ssl-smtp](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/26-mdaemon-ssl-smtp.png?width=670&height=550&name=26-mdaemon-ssl-smtp.png)
2. **Webmail**  
   You may use the same certificate above for secure Webmail connections over HTTPS. **HTTPS only** and **HTTP redirected to HTTPS** will disable non-SSL connections from occurring for Webmail.  
   ![27-mdaemon_webmail_ssl](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/27-mdaemon_webmail_ssl.png?width=670&height=558&name=27-mdaemon_webmail_ssl.png)
3. **Remote Administration**  
   You may use the same certificate for Webmail and/or MDaemon SSL connections. **HTTPS only** and **HTTP redirected to HTTPS** will disable non-SSL connections from occurring for remote administration sessions.
   
   ![28-mdaemon-remote-administration](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/28-mdaemon-remote-administration.png?width=670&height=555&name=28-mdaemon-remote-administration.png)
4. **No STARTTLS List**  
   Hosts/IPs added to this list will be exempt from using STARTTLS during SMTP sessions.
5. **STARTTLS List**  
   Hosts/IPs added to this list will be required to use STARTTLS.
6. **SMTP Extensions  
   ![31_mdaemon_smtp_ext](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/31_mdaemon_smtp_ext.png?width=670&height=556&name=31_mdaemon_smtp_ext.png)**
7. **DNSSEC**
8. **Let's Encrypt**  
   This menu is used to generate and apply a valid certificate using MDaemon and Let's Encrypt.  See the article below for assistance setting one up in MDaemon.[**How do I get a free SSL certificate from Let's Encrypt?**](https://knowledge.mdaemon.com/_hcms/analytics/search/conversion?redirect=aHR0cHM6Ly9rbm93bGVkZ2UubWRhZW1vbi5jb20vaG93LXRvLWdlbmVyYXRlLWEtZnJlZS1zc2wtY2VydGlmaWNhdGUtdXNpbmctbGV0cy1lbmNyeXB0&ct=SEARCH&pid=6572702&cid=29087396689&t=bGV0J3MgZW5jcnlwdA%3D%3D&d=knowledge.mdaemon.com&c=5&rp=1&ab=false&opcid=&rs=UNKNOWN&hs-expires=1714749855&hs-version=1&hs-signature=APUk-v5FEvdI0ppAi1d0rwAxmvmedPCKMQ&hsLang=en)  
   ![33_lets_encrypt](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/33_lets_encrypt.png?width=670&height=556&name=33_lets_encrypt.png)

**Other**

1. **Backscatter Protection  
   ![recommended backscatter protection settings in mdaemon email server to prevent invalid notifications](https://knowledge.mdaemon.com/hs-fs/hubfs/KB%20Screenshots/1144/21_backscatter.png?width=670&name=21_backscatter.png)**
2. **Tarpitting  
   ![recommended mdaemon email server tarpitting settings to include ehlo helo delays](https://knowledge.mdaemon.com/hs-fs/hubfs/KB%20Screenshots/1144/22_tarpit.png?width=670&name=22_tarpit.png)**
3. **Greylisting  
   ![35-mdaemon-greylisting](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/35-mdaemon-greylisting.png?width=670&height=556&name=35-mdaemon-greylisting.png)**
4. **LAN Domains**  
   Domains listed here are considered by MDaemon to be part of the local area network (LAN)..
5. **LAN IPs**  
   IPs listed here will be considered by MDaemon to be part of the local area network (LAN).
6. **Site Policy**  
   Text transmitted during the initial connection of each SMTP session.  
   Policies should be limited to 15 lines with 75 characters per line.

  
**Recommended Dynamic Screening Settings**

1. Select **Security**
2. Select** Dynamic Screening...**
3. **Options/Customize  
   ![dynamic-screen-options](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/dynamic-screen-options.png?width=538&height=524&name=dynamic-screen-options.png)**
4. **Authentication Failure Tracking**  
   These are default values and can be modified as desired.**![dynamic-screen-tracking](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/dynamic-screen-tracking.png?width=538&height=524&name=dynamic-screen-tracking.png)**
5. **Protocols  
   ![dynamic-screen-protocols](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/dynamic-screen-protocols.png?width=538&height=524&name=dynamic-screen-protocols.png)**
6. **Notifications**  
   These options can be modified as desired.  
   **![dynamic-screen-notifications](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/dynamic-screen-notifications.png?width=538&height=524&name=dynamic-screen-notifications.png)**
7. **Dynamic Block List**  
   IP addresses can be added here permanently or expire after an desired date.  CIDR notation and wildcards(\*) are accepted here.  
   ![dynamic-screen-blocklist](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/dynamic-screen-blocklist.png?width=538&height=524&name=dynamic-screen-blocklist.png)
8. **Dynamic Allow List**  
   Exempt IP addresses or ranges.  Default settings are pictured below.  
   ![dynamic-screen-allowlist](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/dynamic-screen-allowlist.png?width=538&height=524&name=dynamic-screen-allowlist.png)

**Recommended AntiVirus Settings**

MDaemon AntiVirus must be activated to access this menu.

1. Open the MDaemon GUI
2. Select **Security **
3. Select** AntiVirus**
4. Select **Virus Scanning**  
   ![mdaemon-antivirus-scanning](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/mdaemon-antivirus-scanning.png?width=622&height=602&name=mdaemon-antivirus-scanning.png)

**Recommended Spam Filter Settings**

1. Open the MDaemon Configuration Session
2. Select **Security**
3. Select **Spam Filter**

**Spam Filter**

Messages scoring over 5.0 points will be marked as spam and messages scoring over 12.0 points will be rejected entirely.  These are default values and can be modified as desired.

**![01-spam-filter-menu](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/01-spam-filter-menu.png?width=670&height=531&name=01-spam-filter-menu.png)**

**Bayesian Classification  
![02-spam-filter-bayesian](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/02-spam-filter-bayesian.png?width=670&height=532&name=02-spam-filter-bayesian.png)**

**Bayesian Auto-learning  
![03-spam-filter-auto-bayes](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/03-spam-filter-auto-bayes.png?width=670&height=530&name=03-spam-filter-auto-bayes.png)**

**Spam Daemon (MDSpamD)**  
No changes should be made here unless instructed to from technical support.

**Allow List (automatic)  
![05-spam-filter-allow-automatic](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/05-spam-filter-allow-automatic.png?width=670&height=530&name=05-spam-filter-allow-automatic.png)**

**Allow List (no filtering)**  
Local domains/addresses should not be on this list unless messages to a specific account should receive spam-filter exempt mail.

**Allow List (by recipient)**  
Local domains/addresses should not be on this list unless needed.

**Allow List (by sender)**  
Local domains/addresses should not be on this list unless needed.

**Block List (by sender)**  
Local domains/addresses should not be on this list unless needed.

**Updates  
![06-spam-filter-updates](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/06-spam-filter-updates.png?width=670&height=531&name=06-spam-filter-updates.png)**

**Reporting  
![mdaemon-spam-filter-reporting](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/mdaemon-spam-filter-reporting.png?width=670&height=530&name=mdaemon-spam-filter-reporting.png)**

**Settings  
![mdaemon-spam-filter-settings](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/mdaemon-spam-filter-settings.png?width=670&height=529&name=mdaemon-spam-filter-settings.png)**

**DNS-BL**

**Hosts**

The SpamHaus ZEN block list (zen.spamhaus.org) is a default DNS-Blocklist applied in new MDaemon installations.  

In the image below, another DNS-BL from SpamCop, has been configured to check incoming mail against the provider's block lists. Other DNS-BL hosts exist in free, fair-use, and subscription capacities and can be added to MDaemon for increased security against malicious and/or compromised servers. 

**![mdaemon-spam-filter-dnsbl](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/mdaemon-spam-filter-dnsbl.png?width=670&height=530&name=mdaemon-spam-filter-dnsbl.png)**

**Allow List**  
This file lists IP addresses of sites that are exempt from DNSBL lookups. Local domains/addresses should not be on this list.  
![mdaemon-spam-filter-dnsbl-allow](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/mdaemon-spam-filter-dnsbl-allow.png?width=670&height=529&name=mdaemon-spam-filter-dnsbl-allow.png)  
**Settings  
![mdaemon-spam-filter-dnsbl-settings](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/mdaemon-spam-filter-dnsbl-settings.png?width=670&height=527&name=mdaemon-spam-filter-dnsbl-settings.png)**

 

**Spamhaus Data Query Service (DQS) **

This feature is available in MDaemon versions 23.0.2 and above. 

Spamhaus Data Query Service offers increased protection utilizing multiple block lists.  Once an account has been created with SpamHaus, enter your unique DQS key in the text box below to activate these services in MDaemon.

[Getting started with Data Query Service](https://info.spamhaus.com/getting-started-with-dqs)

![mdaemon-spam-filter-spamhaus-dqs](https://knowledge.mdaemon.com/hs-fs/hubfs/KBAs/mdaemon-spam-filter-spamhaus-dqs.png?width=670&height=527&name=mdaemon-spam-filter-spamhaus-dqs.png)

 

- [MDaemon Email Server](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en#main-content)
  
  
  
  
  
    - [Mobile Device Management](https://knowledge.mdaemon.com/mdaemon-email-server?hsLang=en#mobile-device-management)
- [MDaemon AntiVirus (SecurityPlus)](https://knowledge.mdaemon.com/mdaemon-antivirus-securityplus?hsLang=en)
- [ActiveSync for MDaemon](https://knowledge.mdaemon.com/activesync-for-mdaemon?hsLang=en)
- [MDaemon Connector for Outlook (Outlook Connector)](https://knowledge.mdaemon.com/mdaemon-connector-for-outlook-outlook-connector?hsLang=en)
- [SecurityGateway for Email Servers](https://knowledge.mdaemon.com/securitygateway-for-email-servers?hsLang=en)
- [RelayFax Network Software](https://knowledge.mdaemon.com/relayfax-network-software?hsLang=en)

[![Chill listening crop-3](https://knowledge.mdaemon.com/hs-fs/hubfs/belch.io/template-assets/MDaemon-Technologies_logo.png?width=199&height=41&name=MDaemon-Technologies_logo.png "Chill listening crop-3")](https://www.mdaemon.com)

[Knowledge Base Home](https://knowledge.mdaemon.com?hsLang=en)

<https://www.youtube.com/c/MDaemonTechnologies> <https://www.linkedin.com/company/mdaemon-technologies/> <https://www.facebook.com/MDaemon.Technologies/> <https://www.twitter.com/MDaemon_Email>

Copyright © 2025, MDaemon Technologies