Exchange Server processes inbound messages in a very specific order. As messages are processed by the various filters, each filter has the ability to block the connection or email from being transmitted to the recipient(s). The Connection Filter, which is the first filter that Exchange Server 2003 processes, has two options: Block and Allow. If you allow an IP address using the Connection Filter settings, it will override the remaining filters, including IMF. Per the Intelligent Message Filter release notes:
"IP allow addresses under connection filtering allows mail to bypass Intelligent Message Filter, which results in messages that have no SCL value stamped on them. These messages can be filtered by Outlook 2003 Junk E-mail rules. Intelligent Message Filter does not specify an SCL by design because content scanning was actually bypassed. In this case, setting an SCL of 0 would not be an accurate value from Intelligent Message Filter."
The same cannot be said about Exceptions in the Connection filter, which has no affect on the IMF filter.
Do you have comments on this Ask the Expert Q&A? Let us know.
Ask an Exchange Server question in our forum.
Dig deeper on Spam and virus protection
Related Q&A from Richard Luckett
When you're stumped on how to track email items following a central mailbox move, fix the dilemma by knowing what happens to items in mailboxes when ...continue reading
You can pull out the big guns to manually remove what's left of your failed Exchange Server from Active Directory, but it's best to consider ...continue reading
There are a number of actions to take to implement OWA security, including obvious ones like creating strong password policies. Admins should also ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.