Deciding on whether to white list domain or individual email     Article #418


Avoid white listing any common domain. Spammers can easily forge email addresses, and pretend to be common domains such as eBay.com, Microsoft.com, etc.. Unique domains such as ExchangeSentry.com are normally safe to use a wildcard entry such as *@ExchangeSentry.com.

You can whitelist common domains if you absolutely need guaranteed delivery from any sender using that domain, but be prepared to receive at least some occasional spam because of this.

NOTE: IP addresses are much tougher to fake, and rarely are faked. If you know the last IP address of even a common domain, you can list it and all email from that server will be allowed, regardless of domain used.

Author: D. Reno
1/12/2004