Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About

Messageware
Integration

Messageware is a market leader in securing and enhancing Microsoft Exchange Servers. By combining their Exchange Protocol Guard (EPG) software with Spamhaus’ real-time DNS blocklists, organizations can block connections from compromised users or malicious sources.

Enhanced intelligent security

Recognize attacks and automatically mitigate.

Gain visibility & insights

Access connection analytics and schedule detailed reports, including blocked connections, geo-locations, devices, and more.

Set up alerts

Trigger notifications on suspicious behaviour minimizing response time.

Messageware EPG & Spamhaus real-time DNSBLs

Exchange Servers receive thousands of connection attempts each year. While many are legitimate, businesses are often unaware that some originate from virus or malware-infected users, or from malicious actors probing for vulnerabilities. When these connections succeed, they can lead to data exfiltration, or in the worst case, ransomware attacks.

With this seamless integration, gain enhanced control, and ensure email client connections are only from legitimate users, keeping your corporate network and users safe.

Block unauthorized connections

Combining the EPG software with Spamhaus’ leading data ensures only legitimate corporate users can connect.

Proactive Protection

Our datasets protect against malicious threats in real time, including malware, IPs hijacked or compromised by 3rd party exploits, and botnets hijacked or leased for cybercrime.

Stay ahead of malicious activity

A cost-effective, proactive solution that reduces risk and prevents costly down time.

Integration details

  • Access the integration

    Spamhaus’ real-time DNSBLs come pre-configured in the EPG software, and are enabled via the IP Filtering setting in the EPG Admin. No development work is needed.

    The DNSBLs are delivered via the Spamhaus’ Data Query Service (DQS). You’ll be provided with a query key to access the data as part of the set up process.

    Simply get in touch with your Messageware contact to activate the Spamhaus integration.

  • Included datasets

    The following Spamhaus data is included:

    • Bruteforce IPs (AuthBL)

    IP addresses known to host bots using stolen credentials or brute-forcing SMTP-AUTH (and other authentication protocols), helping detect and mitigate ongoing abuse from malicious login attempts.

    • Compromised IPs (Exploits Blocklist)

    IP addresses exhibiting signs of compromise, which can include downloaded malware, security vulnerabilities allowing unauthorized access, etc. Designed to protect networks from malware and spam by preventing connections from these IPs. Available in binary and contextual format.

    • Email Spam IPs (Combined Spam Sources Blocklist)

    Spam-emitting IPs that are direct snowshoe spam sources or senders posing a risk. This includes emails showing indications of an unsolicited nature, sending malicious emails due to a compromise, and other indicators of low reputation or abuse.

    • Highly malicious networks (DROP)

    The worst of the worst malicious traffic IPs - an advisory to “drop all traffic” - with activity directly originating from rogue networks, such as encryption via ransomware, DNS-hijacking, authentication attacks, harvesting, DDoS attacks, and spam campaigns.

    • Malicious network ranges (Spamhaus Blocklist)

    This dataset exposes IPs being observed in a range of adversarial activities, derived through Open Source Intelligence (OSINT) from Spamhaus' most specialized and experienced researchers.


    Why does the data have two labels?

    We are moving to more transparent naming conventions. However, some organizations have been consuming these datasets for decades. To save any confusion, for old or new users, we’re currently documenting both names.

  • Suitable users

    Any Messageware EPG customer can use this integration. Set up is easy, and you can trial the data free.

    Simply get in touch with your Messageware contact who will enable the Spamhaus protection.

Ready to
get started?

Access the Messageware EPG integration with Spamhaus’ real-time DNSBLs. Set up is simple, and you can trial for free.

Contact Messageware
Speechmarks
Speechmarks

There are a lot of blocklists out there but the only one that’s ever been super trustworthy has been Spamhaus.

Tara Natanson

Manager of ISP Relations, Constant Contact

trial more data

Data Access

Rsync

Incremental synchronization of binary and contextual datasets to local servers, including access to our entire binary DNS blocklist data. Efficiently transfer data by only copying changes between the source and destination.

Learn More

Data Access

Intelligence API

Integrate context-rich metadata relating to IP and domain reputation to enhance existing data feeds, or consume as an independent data source. Gain additional intelligence to monitor, assess and remediate as required.

Learn More

Data Access

DNS Response Policy Zones

Access our wide variety of DNS Response Policy Zone files to block or redirect access based on your appetite for risk. We provide the data, you set the terms, configurable to your business’ needs and company requirements/policies.

Learn More