Understanding How iCore Advanced Anti-Spam Firewall Works
This article explains how iCoreHosting protects your email accounts with our Advanced Anti-Spam Firewall, including what it does, common mistakes to avoid, responsibility boundaries, limitations, real use cases, and a clear summary.
Table of Contents
- Service Direction / Introduction / Scope
- Common Mistakes
- Responsibility Breakdown
- Limitations
- Use Case
- Summary
Service Direction / Introduction / Scope
Service direction is to reduce junk mail, phishing, malware, scam attempts, and email abuse while keeping business email reliable and usable.
What it is is a multi layer filtering system placed in front of your mailbox to screen incoming messages before they reach your inbox.
Core protection layers
- Connection screening blocks suspicious sources early using reputation signals and abnormal connection behavior.
- SMTP behavior checks detect abuse patterns such as rapid retries, forged identifiers, unusual routing, and suspicious sending bursts.
- Email authentication validation evaluates SPF, DKIM, and DMARC alignment to reduce spoofing and domain impersonation.
- Content and link risk analysis identifies scam patterns, brand impersonation cues, and risky URLs that commonly lead to credential theft or fraud.
- Attachment risk checks scan attachments and file structures for malware indicators and suspicious behaviors.
- Decision actions deliver clean mail, quarantine suspicious mail for review, or reject clearly harmful mail depending on risk level.
Anti spam database is a continuously updated intelligence set used to identify and stop spam sources, spoofing patterns, and abusive sending behavior. It may include sender reputation signals, known bad IP and domain indicators, common spam fingerprints, and behavioral rules that detect unusual delivery patterns.
Anti virus database is a frequently refreshed collection of malware signatures and detection logic used to identify known viruses, trojans, worms, and malicious document payloads delivered through email attachments or embedded content.
Anti scam, anti phishing, and anti ransomware controls focus on detecting social engineering emails that try to trick users into paying money, sharing passwords, or opening malicious files. These checks look for impersonation wording, risky links, abnormal sender identity signals, and suspicious attachment indicators commonly used to distribute ransomware.
Scope covers incoming email filtering for iCoreHosting email services. Outgoing mail protection focuses on abuse prevention and reputation protection controls to reduce the risk of your domain being flagged or blacklisted by external providers.
Common Mistakes
- Missing SPF or incorrect SPF reduces trust and increases spam folder placement, and also makes spoofing easier.
- DKIM not enabled weakens email integrity proof and hurts deliverability across many receiving systems.
- DMARC not published means you lose policy control and visibility on spoofing attempts.
- Forwarding without proper configuration may break authentication and increase quarantine chances.
- Using weak or reused passwords increases account compromise risk and may trigger sending reputation issues.
- Expecting zero spam no filtering system can guarantee perfect blocking and also guarantee zero false positives.
- Ignoring quarantine review may cause missed emails when a legitimate message is held for safety checks.
- Sending bulk email without consent damages sender reputation and can cause delivery failures.
Responsibility Breakdown
iCoreHosting responsibilities
- Maintain the Anti Spam Firewall rules, intelligence updates, and reputation controls used to reduce junk and malicious email threats.
- Operate filtering, scanning, and quarantine logic to reduce spam, phishing, malware, scam, and ransomware delivery attempts by email.
- Protect platform level mail reputation using abuse prevention controls and monitoring where applicable.
- Provide guidance for SPF, DKIM, and DMARC best practices upon request.
Customer responsibilities
- Publish and maintain correct SPF, DKIM, and DMARC records for your domain and keep DNS records up to date.
- Maintain strong password practices and device security, and avoid password sharing across staff.
- Review quarantine if enabled, and whitelist trusted senders when necessary.
- Follow acceptable sending practices and avoid unsolicited bulk messaging.
- Verify sensitive requests such as payment changes or login prompts through a second channel before acting.
Limitations
- No system can promise 100 percent accuracy because attackers constantly change tactics and legitimate mail patterns can sometimes look similar to threats.
- False positives are possible especially for new domains, new mailboxes, unusual sending patterns, or heavily forwarded mail flows.
- Forwarding can reduce authentication trust unless properly configured, which can increase quarantine likelihood.
- Recipient side rules still apply external email providers may add their own filtering beyond iCoreHosting control.
- Encrypted or password protected attachments may limit deep scanning, so decisions may rely more on reputation and behavior signals.
Use Case
Use case 1 Supplier impersonation and fake invoice emails
- Firewall blocks known bad sender sources at connection level to reduce inbox noise.
- Content and link analysis detects impersonation phrases and suspicious URLs.
- Authentication checks identify spoofed domains using SPF, DKIM, and DMARC signals.
- High risk messages are quarantined or rejected depending on threat level.
Recommended customer actions
- Ensure SPF and DKIM are enabled for every system that sends email for your domain.
- Publish DMARC to gain visibility and control over spoofing attempts.
- Train staff to confirm payment instruction changes using phone confirmation or trusted contact channels.
Use case 2 Ransomware delivery attempts by attachment
- Attachment scanning and risk indicators detect suspicious payload patterns.
- Anti virus database signatures detect known malware families and common exploit patterns.
- High risk files are quarantined or blocked before reaching user inboxes.
Recommended customer actions
- Do not enable macros from unknown documents and do not run unknown attachments.
- Keep endpoints protected and updated, and ensure backups follow safe recovery practices.
Summary
iCore Advanced Anti Spam Firewall protects your mailbox using layered checks across connection reputation, SMTP behavior, SPF DKIM DMARC authentication validation, content and link risk analysis, and attachment scanning. It is powered by continuously updated anti spam and anti virus databases and includes anti scam, anti phishing, and anti ransomware controls to reduce modern email threats. Best results require customers to keep DNS authentication records correct, maintain strong account security, and review quarantine when needed.
