In the protected system
Dr.Web for MS Exchange performs the following actions:
- scans incoming and outgoing messages;
- blocks and moves infected and suspicious objects to the quarantine;
- sends alerts on virus events to administrators and users;
- keeps logs and collects statistics;
- automatically updates virus databases;
- filters spam;
- filters e-mails by different criteria;
- adds customizable texts to sent messages, if necessary;
- generates summary reports and statistics.
Dr.Web for MS Exchange is managed via the administration console integrated with Microsoft Management Console (MMC). It allows to easily manage all components of the anti-virus protection, receive alerts on virus events and specify automatic actions for them, automate tasks, perform daily routines in few minutes, without any extensive time commitments, increase productivity while reducing administrator time and costs.
Grouping and managing groups
Dr.Web for MS Exchange is a highly scalable solution. It can be deployed both in small networks and in complex distributed intranets with thousands of hosts. The option of grouping facilitates administration of the anti-virus protection. The administrator can edit profiles of groups to specify different settings for different groups, as well as similar settings for several groups. A profile specifies actions for infected, suspicious, and incurable objects — cure, delete, move to the quarantine, block, etc.
Changing priority during the scanning
All incoming messages are processed according to their assigned scanning priority. When saved to a folder, a message receives a low priority. As soon as a mail client attempts to open the message, the priority is changed to high. To assure ultimate protection outgoing messages are checked for viruses before they are processed by a mail client. Thus dynamic and two-way scanning, allow maintaining high protection level and spare system resources.
Efficient filtering of spam
E-mail messages are filtered for spam using the VadeRetro library. Due to the dynamically updated code of the anti-spam’s library the filtering speed is always high and the quality of detection is constantly improving. High filtering speed is combined with low system load; the anti-spam perfectly functions on mail servers of almost any configuration.
Depending on the analysis each messages receives the score from the VadeRetro library – an integer ranging from -10000 to +10000. The less the score is, the more likely the message is to be a "legitimate", i.e. not spam. The threshold is set to 200, i.e. if the score equals to 200 or more, the message is classified by the VadeRetro library as spam. At the end of analysis "***SPAM***" is added to such messages.
Different parameters for filtering of e-mails
An administrator can create special rules to filter incorrect messages. The rules can be based on names and extensions of attached files, file size and number of recipients. Such filtering is made before a message is checked for viruses and spam; this allows decreasing even more the load of the protected system.
Adding texts to outgoing messages
An arbitrary text can be added to messages sent by the company employees (for example, disclaimers, or advertisements). The texts can be added to messages sent both in HTML format and in plain text.
Quarantine
Incurable and suspicious objects can be moved to the quarantine mail box. The location of the quarantine is specified during the installation. Objects in the quarantine can be deleted or saved to the hard drive by an administrator. Original copies of suspicious messages are stored in the backup before they are deleted. This option is disabled by default for incurable objects.
Logging&Reporting
Any action taken for protection of the data stored on the server is logged. The max log file size option allows avoiding overcrowding the server hard drive space with log files and archived log files of large size. There is another option to delete such a file when the max log file size is exceeded.
Reports are sent via e-mail. The reports interval is specified by an administrator. The following reports are generated:
- All Incidents;
- Incidents by recipients;
- Most recent viruses;
- Spam count;
- Who are most spammed ever;
- Who are most virused ever.
Customized alerts
To customize alerts macros are used. A custom alert can be created for every type of detected objects: curable, incurable, spam. Alerts are sent via e-mail or logged to the Windows event log. Recipients of alerts, subject, message text and other parameters can be specified for every type of alerts (by macros as well).
Licensing
The product is licensed per number of protected users. License options: Anti-virus, Anti-virus&Anti-spam.
Types of the license
- Per protected users – any number of users over 5.
- Per protected servers – an unlimited amount of e-mail traffic of one mail server with the number of users within 3 000.
The product is also available in money-saving Dr.Web bundles for small and medium businesses.
License options