<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: What&#8217;s a DHA look like?</title>
	<atom:link href="http://www.vmunix.com/mark/blog/archives/2006/05/25/whats-a-dha-look-like/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.vmunix.com/mark/blog/archives/2006/05/25/whats-a-dha-look-like/</link>
	<description>by Mark Mayo</description>
	<pubDate>Tue,  6 Jan 2009 14:06:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: mark</title>
		<link>http://www.vmunix.com/mark/blog/archives/2006/05/25/whats-a-dha-look-like/#comment-13115</link>
		<dc:creator>mark</dc:creator>
		<pubDate>Fri, 26 May 2006 06:48:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.vmunix.com/mark/blog/archives/2006/05/25/whats-a-dha-look-like/#comment-13115</guid>
		<description>I only know it's was a DHA because it was ongoing as I flipped the MX from the Postfix box to the IronPort mid-attack.  :)</description>
		<content:encoded><![CDATA[<p>I only know it&#8217;s was a DHA because it was ongoing as I flipped the MX from the Postfix box to the IronPort mid-attack.  <img src='http://www.vmunix.com/mark/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://www.vmunix.com/mark/blog/archives/2006/05/25/whats-a-dha-look-like/#comment-13111</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Fri, 26 May 2006 03:24:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.vmunix.com/mark/blog/archives/2006/05/25/whats-a-dha-look-like/#comment-13111</guid>
		<description>What this graph really shows you is the connections getting blocked.  Because the remote mail system is not able to even send a MAIL FROM: SMTP command, there is no way to know if this really is a DHA.  If you have DHAP enabled on the ironport and someone tried to do a directory harvest, you will get an email once they reach the limit for invalid recipients you configure on the box.

Based on this graph you could presume that you were under some sort of DOS attack where many machines around the internet were trying to send email to your system and each of the IPs had a fairly negative SBRS score.  The other interresting thing is that the number that defines the connections blocked by reputation filtering does not necessarily correspond to a 1:1 ratio of email per connection but could in fact have had a payload of 3, 5, 10, 100 messages for each unique connection that the box was seeing.

A DHA would increase the "Invalid Recipients" number on the monitoring page because at that stage of the connection, it has already passed SBRS and has issued an invalid RCPT TO:.</description>
		<content:encoded><![CDATA[<p>What this graph really shows you is the connections getting blocked.  Because the remote mail system is not able to even send a MAIL FROM: SMTP command, there is no way to know if this really is a DHA.  If you have DHAP enabled on the ironport and someone tried to do a directory harvest, you will get an email once they reach the limit for invalid recipients you configure on the box.</p>
<p>Based on this graph you could presume that you were under some sort of DOS attack where many machines around the internet were trying to send email to your system and each of the IPs had a fairly negative SBRS score.  The other interresting thing is that the number that defines the connections blocked by reputation filtering does not necessarily correspond to a 1:1 ratio of email per connection but could in fact have had a payload of 3, 5, 10, 100 messages for each unique connection that the box was seeing.</p>
<p>A DHA would increase the &#8220;Invalid Recipients&#8221; number on the monitoring page because at that stage of the connection, it has already passed SBRS and has issued an invalid RCPT TO:.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
