This document describes the Sender Domain Reputation (SDR) configuration for the Email Security Appliance (ESA).
Cisco recommends that you have knowledge of these topics:
General knowledge of SEG functions/features including; Mail Flow Policies, Message filters, Content Filters, Global Domain Reputation.
The information in this document is based on AsyncOS for ESA 14.2 and later.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
1. SDR has been developed as an additional service to improve spam phishing detection.
2. SDR captures multiple header values and uploads them to Talos Threat Intelligence Servers where the vast Talos Resources determine a verdict for each message on a graduated scale.
3. The header values included in the decision are:
5. SDR Scan gets performed on all inbound messages.
6. SDR scan takes place just after the Simple Mail Transfer Protocol (SMTP) acceptance of a message.
7. SDR action can be taken at the initial Mail Flow Policy stage as well as Message Filter or Content Filter options.
8. Configured components include:
SDR can be enabled from either the WebUI or the CLI interfaces.
WebUI:
1. Navigate to Mail Security Services > Domain Reputation > Enable.
2. Click the box next to Enable Sender Domain Reputation Filtering.
3. Choose this box Include Additional Attributes: (Optional) if you would like to include the optional header value to the checked data for improved efficacy. Click ? to learn.
4. Choose this box Sender Domain Reputation Query Timeout. Click ? to learn.
5. Choose Match Domain Exception List based On Domain in Envelope From - Enabled.
6. Click Submit > Commit as shown in the image.
Sender (Domain Reputation) Service
Security Services > Domain Reputation
1. The Domain Exception List can bypass Sender Domain Reputation Scanning for inbound mail flow.
2. The Domain Exception List can be applied at different locations in order to affect mail flow.
3. The Global application can apply to all mail scanned.
4. The more detailed application within content/message filters can affect only a configured filter(s).
5. The Domain Exception List provides 2 options to provide both a simple as well as a more secure option.
6. This document describes the options in order to successfully bypass SDR for a message that uses the Domain Exception List.
7. Domain Exception List Requirements Explained
Address List to be applied to the Domain Exception List
Choose an Address List from the dropdown
Incoming content filters:
1. Navigate to Condition > URL Reputation > Threat Feeds Option.
2. Condition Domain Reputation.
3. Click here:
Domain Exception List allows per policy action.
The Domain Exception List application within message filters would be included as an option within a condition.
Note: These samples include the domain_exception_list as a portion of the whole condition.
A more comprehensive explanation and samples of Message filter application can be found with the ESA User Guides under the headings:
5. The final option within the Domain Reputation Condition is the Domain Exception List.
6. The Domain Exception List function associated with an Address List adds more control to the application of the action by applying the list to the more detailed Mail Policy Level of message processing.
7. Navigate to Mail Policy > Incoming Content Filters > Add Filter > Add Condition > Domain Reputation.
8. Condition 1: Sender Domain Reputation Verdict.
SDR Verdict adjustable range slide bar.
Full view of the SDR Verdict Slide Bar.
9. Condition 2: Sender Domain Age.
Sender Domain Age. Lower values suggest more risk.
10. Condition 3: Sender Domain Reputation Unscannable.
SDR Unscannable
11. Condition 4: External threat feeds
External Threat Feeds can be used to scan the same headers used for SDR
12. Condition 5: Use domain exception list.
Domain Exception List allows per policy action.
13. The action combined with these conditions can range from minimal to extreme and it depends on the desired results of the administrator.
14. Some of the more popular actions are listed:
3. These conditions are associated with the SDR Message Filter:
Use this section to confirm that your configuration works properly.
Once the SDR Service has been enabled, the mail_logs and Message Tracking begin to show the SDR: log entries.
1. mail_logs contain the score of the SDR data collected.
2. The score is determined early in the mail flow, prior to determining the Mail Policy.
3. Actions taken on the verdict occur at the time of the message filter and content filter actions.
xxx.com> mail_logs sample including SDR verdict
Tue Dec 3 15:22:44 2019 Info: New SMTP ICID 5539460 interface Data 1 (10.10.10.170) address 55.1.x.y reverse dns host xxx1.xxx.com verified yes
Tue Dec 3 15:22:44 2019 Info: ICID 5539460 ACCEPT SG Production_INBOUND match xxx1.xxx.com SBRS 2.5 country United States
Tue Dec 3 15:22:44 2019 Info: ICID 5539460 TLS success protocol TLSv1.2 cipher ECDHE-RSA-AES128-GCM-SHA256
Tue Dec 3 15:22:44 2019 Info: Start MID 3291517 ICID 5539460
Tue Dec 3 15:22:44 2019 Info: MID 3291517 ICID 5539460 From: <customer@xxx.com>
Tue Dec 3 15:22:44 2019 Info: MID 3291517 ICID 5539460 RID 0 To: <owner@xxx.com>
Tue Dec 3 15:22:44 2019 Info: MID 3291517 IncomingRelay(PROD_TO_BETA): Header Received found, IP 172.20.245.245 being used, SBRS -1.9 country United States
Tue Dec 3 15:22:44 2019 Info: MID 3291517 Message-ID '<mail>'
Tue Dec 3 15:22:44 2019 Info: MID 3291517 Subject "You\\'ve Been Nominated for inclusion with Who\\'s Who"
Tue Dec 3 15:22:44 2019 Info: MID 3291517 SDR: Domains for which SDR is requested: reverse DNS host: Not Present, helo: xxx1.xxx.com, env-from: xxx.com, header-from: xxx.com, reply-to: Not Present
Tue Dec 3 15:22:46 2019 Info: MID 3291517 SDR: Consolidated Sender Reputation: Awful, Threat Category: N/A, Suspected Domain(s) : owner@xxx.com, owner=xxx.com@xxx.com. Youngest Domain Age: unknown for domain: owner@xxx.com
Tue Dec 3 15:22:46 2019 Info: MID 3291517 SDR: Tracker Header : 5Zrl76622ZDGPsS6cByUUXq7LTXXS3/wonoZb5cGe2AbRQKxXE5Fag5SfJuNyzii3UPRVoCasmgBq9G0UrsLt7i/omQxDae82pU/wJbLOD8akDJ7eq7cLFChOcPm0utOmSv9sFJ4K/K1dL4uNiB13e/pXHjGDAmZrKwo7A13/7HTMCZz8PaMgKl7AFKvwVuZc1oVn5OGQr95d0L5x6/ipHZi6/2oKPxMcovolx580SiJ29lJFv7qLjJ8jOlGZCEQOVBnzRHJ7X8wJrZKhGMiLgy
Tue Dec 3 15:22:46 2019 Info: MID 3291517 ready 10011 bytes from <owner@xxx.com>
Tue Dec 3 15:22:46 2019 Info: MID 3291517 Custom Log Entry: MF_URL_Category_all HIT
Tue Dec 3 15:22:46 2019 Info: MID 3291517 matched all recipients for per-recipient policy DEFAULT in the inbound table
Tue Dec 3 15:22:47 2019 Info: MID 3291517 interim verdict using engine: CASE spam positive
Tue Dec 3 15:22:47 2019 Info: MID 3291517 using engine: CASE spam positive
Tue Dec 3 15:22:47 2019 Info: MID 3291517 interim AV verdict using Sophos CLEAN
Tue Dec 3 15:22:47 2019 Info: MID 3291517 antivirus negative
Tue Dec 3 15:22:47 2019 Info: MID 3291517 AMP file reputation verdict : SKIPPED (no attachment in message)
Tue Dec 3 15:22:47 2019 Info: MID 3291517 using engine: GRAYMAIL negative
Tue Dec 3 15:22:47 2019 Info: MID 3291517 Custom Log Entry: SDR_Verdict_matched_Awful_Poor
Tue Dec 3 15:22:47 2019 Info: Start MID 3291519 ICID 0
4. Simple grep commands in order to check the frequency of, or existence of, specific verdicts.
5. Further, mail log details can be obtained with the use of the CLI findevent command in conjunction with the MID value.
xxx.com> grep "SDR: Domain Reputation.*Poor" mail_logs
Tue Dec 3 11:07:01 2019 Info: MID 3265844 SDR: Consolidated Sender Reputation: Poor, Threat Category: Spam, Suspected Domain(s) : xxx.com Youngest Domain Age: 21 days for domain: customer@xxx.net
Tue Dec 3 12:57:28 2019 Info: MID 3277401 SDR: Consolidated Sender Reputation: Poor, Threat Category: Spam, Suspected Domain(s) : xxxs.com@xxx.com, Youngest Domain Age: 6 months 29 days for domain: xxxs.com@xxx.com
xxx.com> grep "SDR: Domain Reputation.*Awful" mail_logs
Tue Dec 3 10:24:08 2019 Info: MID 3261075 SDR: Consolidated Sender Reputation: Awful, Threat Category: N/A, Suspected Domain(s) : owner@xxxxxx.us Youngest Domain Age: unknown for domain: owner@xxx.ca
Tue Dec 3 15:18:27 2019 Info: MID 3291182 SDR: Consolidated Sender Reputation: Awful, Threat Category: N/A, Suspected Domain(s) : example.com@xxx.info, xxx@.info. Youngest Domain Age: 1 day for domain: example.com@xxx.info
This section provides information you can use to troubleshoot your configuration.
2. SDR timed out:
The default is 2 seconds and a maximum setting of 10 seconds.
After the transition, the hostname v2.sds.cisco.com can still be available but can no longer be optimized for both URL Filtering and SDR.
You need to allow these hostnames and IP addresses on your firewall for outbound TCP port 443 traffic.
Hostnames:
IP address ranges:
These are Cisco Talos Intelligence Services endpoints used to obtain IP reputation, URL reputation and category, and to send Service Logs details.
| Revision | Publish Date | Comments |
|---|---|---|
4.0 |
27-Jul-2026
|
Updated Machine Translation, Style Requirements, and Formatting. |
3.0 |
01-Jun-2023
|
Removed PII.
Updated SEO, Alt Text, Machine Translation, Style Requirements, Gerunds and Formatting. |
2.0 |
21-Oct-2021
|
Corrected examples -- contained live customer data. |
1.0 |
04-Nov-2020
|
Initial Release |