Home > Microsoft Exchange Tips > Exchange Security Tips > Outlook's automatic picture download settings
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SECURITY TIPS

Outlook's automatic picture download settings


Serdar Yegulalp
05.18.2005
Rating: -4.75- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Please let others know how useful this tip is via the rating scale at the end of it. Do you have a useful Exchange or Outlook tip, timesaver or workaround to share? Submit it to our tip contest and you could win a prize.


VIEW MEMBER FEEDACK TO THIS TIP

Outlook 2003 has stricter security controls over the presentation of rich content sent in e-mails. E-mail with HTML containing ActiveX controls, for instance, is one of the biggest vectors for spyware or virus infections.

As an additional security measure, Outlook 2003 does not download images by default when users open HTML e-mails. This conserves bandwidth and protects users from questionable images (for instance, in the context of pornographic spam e-mail).

If you right-click on an image in an e-mail sent to you and select "Change Automatic Download Settings," you can modify the way Outlook handles image downloads depending on the e-mail's originating domain. The "Don't download pictures or other content automatically" option is usually enabled by default, but there are two other settings that deserve attention:

1. "Permit downloads…from Safe Senders/Recipients" uses Outlook's Junk E-mail filter's whitelists to determine if the mail in question is safe to load pictures for. This is only useful if the Junk E-Mail filter's whitelists are in use in the first place. However, if you're relying on a server-side filtering system that doesn't interact directly with Outlook, this won't be as valuable.

2. "Permit downloads … from Trusted Zone [sites]" is a little more helpful. The Trusted Zone in Internet Explorer can be managed through IE's own control panel, or through third-party tools like the Internet Explorer Power Tweaks Web Accessories pack, or by editing the registry directly. This option makes it possible to define, either through policies or perhaps a script, what sites are recognized as safe throughout your organization.

Unfortunately, Outlook does not perform reverse DNS checking to determine if a given e-mail did actually originate from the server it claims to be from. This makes it possible for someone to send spoof e-mails that claim to be from a specific domain -- and may even load pictures from that domain -- but aren't in fact from that location. It's largely your server's responsibility to filter out these mails, and the tools now exist to do so.

Serdar Yegulalp is editor of the Windows Power Users Newsletter and a regular contributor to SearchExchange.com.


MEMBER FEEDBACK TO THIS TIP

It should have been stated that the junk e-mail filter is not available for a Microsoft Exchange Server e-mail account (prior to version 2003) when you are working online. To enable the junk e-mail filter in this case, you must switch to Cached Exchange Mode.
—David P.


Do you have comments on this tip? Let us know.
Related information from SearchExchange.com:

  • Topics Library: Outlook tips and expert advice
  • Malware Learning Guide: Spam, spyware and viruses
  • Topics Library: Spam prevention and management



    Rate this Tip
    To rate tips, you must be a member of SearchExchange.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Outlook and Outlook Web Access Tips
    Outlook 2007 shut-down problems and fixes
    OWA 2007 configuration tricks to boost performance
    Pros and cons of Outlook 2007's storage engine redesign
    Lock down direct file access and protect OWA users
    Simplify an OWA URL on Windows Server 2008
    Windows Mobile 6.5 touts Internet Explorer, OWA improvements
    Custom error message redirects OWA users
    When OWA's default configurations aren't good enough
    Save time typing Outlook 2007 messages with Quick Parts
    Troubleshoot Microsoft Outlook Web Access problems

    Exchange Security Tips
    Is full email encryption the solution to Exchange security?
    Lock down direct file access and protect OWA users
    Controlling spam in Exchange 2007 at the edge transport server level
    When to use a self-signed certificate with Exchange Server 2007
    Obtaining and verifying SSL certificates in Exchange Server
    How file-level antivirus software can harm your Exchange Server
    Understanding Exchange Server 2007 SP1 mobile security settings
    Which ActiveSync authentication method is best for your mobile device?
    Why you should secure Exchange 2007 using administrative policies
    Microsoft Exchange Server security dos and don'ts

    Microsoft Outlook
    Outlook 2007 shut-down problems and fixes
    Microsoft Outlook and SharePoint calendar dos and don'ts
    Free tools facilitate large-scale Outlook and SharePoint integrations
    Exchange Mailbag: POP3 settings and Outlook issues
    Pros and cons of Outlook 2007's storage engine redesign
    Fix Outlook 2007 and SharePoint synchronization breaks
    Email issues after configuring hosted Exchange server on laptop
    Avoid Outlook 2007 performance issues during repairs
    A behind-the-scenes look at Outlook 2007 and SharePoint integration
    When to use a self-signed certificate with Exchange Server 2007
    Microsoft Outlook Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bacn  (SearchExchange.com)
    email bankruptcy  (SearchExchange.com)
    offline folder file  (SearchExchange.com)
    OST file  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Email Server Solutions: Exchange 2007, Exchange 2003, Exchange 2000, SharePoint
    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts