Documentation

Helpful Information to Configure Setting and Troubleshoot Issues

Documentation

Raptor Documentation

Table of Contents

Raptor Email Security End User Guide

Raptor Email Security only blocks email where we can be certain that the email is Spam or malicious. Otherwise, the email will be scored by our system and the subject changed for Spam.

Many competitors use techniques that delay mail flow and incorrectly block legitimate emails. PCCC is a vocal opponent of these techniques.

How do I find an email is missing from my Inbox?

We take missing email very seriously. First, please check your Spam and Junk folders. If you still don’t find the missing email, please email support@pccc.com with the sender’s email address, the subject and the date/time. We will perform a log review.

How do I get rid of Spam in my Inbox?

Using Raptor is the first step! If the subject has Spam in it, then Raptor is working correctly. You can use rules to move these to other folders.

If you receive emails that ARE Spam but are not marked as Spam, please see the instructions below to submit these to PCCC for review.

How do I fix it when there is an email incorrectly marked as Spam?

These emails are called False Positives (FPs). Please see the instructions below to submit these to PCCC for review.

How do I send PCCC an email for Review?

The best way to submit an email for review is to create a new email message and drag the email to review over to the new email message as an attachment.

IMPORTANT: To make sure we get your email and it isn’t filtered, you will need to email the sample to a special address. Please email support@pccc.com or call (703) 359-9700 to receive the email address for submissions.

How do I Allow or Block a Specific Email?

Raptor Email Security is fully managed. By submitting emails for review and emailing our support, PCCC will make all the necessary configuration and algorithmic changes needed to block the bad email while keeping good mail flowing.

Why do my emails say [New], [Spam], [External], [Phish], etc. in the Subject?

Raptor Email Security uses these tags to convey important information about the email. The [Spam] or the older *****SPAM***** tags means Raptor identified the email as spam. The [External] means the email came from external. The [Phish] tag means that there is a high potential this is a phishing attempt or someone with a similar name at your firm. [New] means that this is a new email address that is contacting you. Used in combination, these tags can help greatly to keep your email safe and secure!

Raptor Email Security Admin User Guide

The following information has been prepared for System Administrators.

     Raptor Headers & Rules:

Raptor does not delete Spam emails but rather scores and tags them. If your users don’t want to see these emails in their Inbox, most email clients can use rules to move the Spam to a folder. There are two Raptor headers that will be of interest: X-Spam-Status: & X-Spam-Level. X-Spam-Status will include a Yes or No if Raptor marked it as Spam along with the total hits, the required score, and all the Raptor rules & subrules. X-Spam-Level: will contain an asterisk for every integer in the email’s Raptor score. For example, a score of 5.99 would have a header of X-Spam-Level: *****. The X-Spam-Level header is useful with rules to organize your email into folders. PCCC recommends rules to move Spam scoring below 15 into a folder named SPAM and Spam scoring 15 and over into a folder named SPAM15 The spam scoring over 15 will rarely contain incorrectly tagged emails. If you use Microsoft Outlook, click here for instructions. If you use Mozilla Thunderbird, click here for instructions. If you use IMAP on PCCC’s cPanel infrastructure and would like rules added on the server for all of your users, please email support@pccc.com. NOTE: The process for creating rules is usually very straightforward and available in any modern mail client.

     Raptor Configuration

Raptor Email Security administrators can access https://Raptor.PCCC.com where you can do the following for your organization:
  • View Spam Statistics
  • Manage Raptor Continuity
  • Set a company-wide Auto-Responder
  • Block or Allow emails by Subject, Sender or Recipient
  • View Billing Information
  • Manage Raptor FAST Submissions
Raptor is designed around algorithms that are continuously improved and maintained by PCCC. You should NOT typically need to enter many entries into the welcomelists or blocklists. One exception to this rule is mailing lists and newsletters. IMPORTANT: Raptor Email Security is fully managed. We recommend that you instruct your users to submit emails for review and email our support. PCCC will make all the necessary configuration and algorithmic changes needed to block the bad email while keeping good mail flowing to save you time for other administrative duties.

Notice for Managed Service Providers

The following information has been prepared for Managed Service Providers (MSPs). 

Raptor Email Security MSPs can access https://Raptor.PCCC.com where you can view your overall billing information as well as easily impersonate the administrator of any of the organizations under your management

Raptor Continuity End User Guide

User Guide

  1. Obtain your continuity password and login URL from your administrator.
  2. Log in with your email address and the provided password at the login URL.
  3. Optionally, you may also setup a desktop mail client. (Steps Detailed below)

Setting up Continuity IMAP

Thunderbird
  1. Request your continuity password and mail server information from your Administrator.
  2. Go to File -> New -> Existing Email Account
  3. Enter your email address and continuity password then click Continue.
  4. Click Manual config.
  5. Change the server settings to those provided by your Administrator.
  6. Change the username to be your complete email address.
  7. Click Re-test.
  8. Click Advanced config.
  9. Click Outgoing Server (SMTP).
  10. Select the row that lists your username as your full email address and click Edit.
  11. Change the Authentication Method to No authentication.
  12. Click OK.
  13. Click OK.
Outlook
  1. Request your continuity password and mail server information from your Administrator.
  2. Go to File -> Add Account.
  3. Select Manually Configure and click Next.
  4. Select Internet E-Mail and click Next.
  5. Enter your name and email address.
  6. SELECT IMAP account type.
  7. Enter the server settings provided by your Administrator.
  8. Enter your full email address as the username and your continuity password.
  9. Click OK, then Next.

Raptor Continuity Admin User Guide

  1. Using raptor.pccc.com, enter your domain and click Next.
  2. Login to the Raptor Customer Dashboard with your Raptor Customer Admin credentials.
  3. In the top or bottom ribbon under Raptor Continuity, select the Raptor Continuity Management option in the drop-down menu.
  4. Decide if you want to mass generate credentials or set them per account
    1. If you want to mass generate credentials, click the Generate Continuity Credentials button. (This will only add a password if the account has no continuity password already set.)
    2. If you want to set the credentials per account:
      1. click Edit on the account you want to set credentials for.
      2. Type the new Continuity password into the box.
      3. To save the new password click Edit Account.
  5. Provide the users with the accounts credentials and the link to login to the Raptor Continuity Portal.
    1. The link can be copied from the address bar if you click the Raptor Continuity option in the ribbon.
    2. The username is the full email address of the user.
  6. When the outage ends, you can instruct your customers that they can return to using their normal email client.

Attachment Help

HELP! I received a notice that my email was altered and an attachment was removed.
  1. The email was received but an attachment or multiple attachments were stripped because of the attachment’s extension. Click here to view a list of blocked attachments.
  2. This behavior is by design. PCCC’s Raptor Anti-Spam / Anti-Malware system DOES block many attachments based on extension because of their predilection for exploits.
  3. The extensions we block are carefully chosen to prevent malware spreading.
  4. If you are working with a known sender or recipient, a simple way to allow the email to go through with attachments is to change the extension to .RENAME. The system will allow the email through and the recipient can just rename it to use the file.
  5. We handle quarantine retrievals as noted in the email very quickly. If you need an attachment retrieved even quicker, don’t hesitate to pick up the phone and call us!
  6. We filter millions and millions of emails but generally only receive a handful of quarantine retrieval requests per month. Even so, we routinely see users request attachments from quarantine that are in fact new viruses not yet picked up by virus scanners. Our manual intervention is purposeful to prevent this from harming our customers or their e-mail recipients!
In conclusion, we know stripping attachments is annoying but it is done as part of our job to protect email from spam and malware!

Attachment Sizes

The max email size we allow is 35MB (35882577 bytes).  15MB is usually a good limit for Attachments to make sure it has a high deliverability rate.  25MB inbound is usually very safe. Note that attachments sent via e-mail are larger than they are on a hard drive. On a hard drive, files are usually in binary or 8 bit format. However, e-mails are in a 7 bit format. The conversion that occurs increases the size of attachments, often by 30%. Keep in mind that it’s the size of an e-mail that matters, not the attachment. The largest e-mail that can be sent depends on the size limit of both the sender’s e-mail server and the recipient’s server. Most size limits are around 10 MB. Keep in mind that the size of an attachment is limited to the lowest limit in the chain of servers. Even if you have a 1 GB limit, if the other server has a 1 MB limit, the maximum size of the attachment is 1 MB. Also, note that attachments are larger than the original file due to conversion from 8 bit to 7 bit. http://www.answers.com/topic/binary-and-text-files http://en.wikipedia.org/wiki/Email_attachment

Attachment Retrieval 

To request retrieval of an attachment quarantined by the Raptor, please contact PCCC by email at pccc-dot-com@pccc.com, referencing your message’s Quarantine Directory and SMTP Queue ID within 60 days. Retrieval requests are typically completed within one business day.

Blocked Attachments

The following is a list of the file extensions which are blocked by Raptor Anti-Spam to help protect your computer from malicious attachments.

Dropped Files

Due to the likelihood of being malware, attachments with the following extensions are blocked entirely by Raptor by silently dropping the entire message, including files containing a class ID extension:
Extension  Description Threat
pif MS-DOS shortcut Can launch malware
com Executable file Can launch malware
scr Screen Saver Script Can launch malware
bat Executable batch file Can launch malware
{*} class ID extension Class IDs function the same way other extensions do, but without it being obvious what type of file is being used, and is commonly used to trick users into opening malware

Quarantined Files

The files below are quarantined and removed from the email. The original message with a note about the removed attachment will still be received, and the file can be retreived from the quarantine by contacting PCCC. Click here for more help with attachments and retrieval instructions. xllMicrosoft Windows ExecutablesCan launch malware or cause unexpected behavior
Extension  Description   Threat
7z 7z compressed file 7z compressed files can contain autoexecuting exploits
ade MS Access project extension Access project files Can contain autoexecuting macros
adp MS Access project description Macros
app Microsoft FoxPro application / OS X binary Executables may launch malware
asd Microsoft Office automatic backup file Macros
asf Streaming video Buffer overflow
asx Streaming video Buffer overflow
bas BASIC source file Code execution can launch malware
chm Compiled HTML help file Exploits a buffer overflow found in Internet Explorer.
cmd Executable batch file Can launch malware
cpl Control panel extension Can launch malware
crt Security certificate Can override SSL certificates and lead to Man-in-the-middle attacks
dll Dynamic Link Library Can launch malware
exe Executable file Can launch malware
ex Obfuscated form of exe Can launch malware
exee Obfuscated form of exe Can launch malware
ex_ Obfuscated form of exe Can launch malware
fxp Microsoft FoxPro executable Can launch malware
hlp Windows compiled help file Macros
hta HTML application (Java)script can launch malware
gz Compressed archive Compressed archive file format used to hide malware
img Img ISO images became popular for DVDs Some OSes will mount img ISO images as drives allowing for malicious software installation
inf Setup information Setup scripts can be changed to do unexpected things
ini Contains program options Program options can be accidentally installed and cause programs to do unexpected or malicious things
ins Internet Naming Service DNS hijacking/DNSChanger attacks
iso ISO images became popular for CDs Some OSes will mount ISO images as drives allowing for malicious software installation
isp Internet Settings DNS hijacking/DNSChanger, MITM attacks
jar Executable Java file Can launch malware
js Javascript source file Can launch malware
jse Javascript executable Can launch malware
lib Software library In theory, these files could be infected but to date no LIB-file virus has been identified
lnk Windows shortcut Can execute arbitrary code and run malware. Some people may accidentally attach a shortcut instead of the softlinked file
lzh Compressed archive Compressed archive file format used to hide malware
mdb Microsoft Access File Macros can launch malware
mde Microsoft Access database Macros can launch malware
mim MIME-encoded file Blocked due to an exploit in some versions of WinZip.
msc Microsoft Common Console Document Can be changed to point to unexpected places.
msi Windows installer executable Can launch malware
msp Microsoft Windows Installer Patch Can launch malware
mst Microsoft Visual Test Source Files and SDK Setup file Source can be changed to make your computer work unexpectedly
ocx Object Linking and Embedding (OLE) Control Extension Can launch malware.
pcd Kodak proprietary photo CD image Can launch malware.
prg FoxPro program source file Can launch malware
rar RAR compressed file Can lead to remote code exploits due to self-extracting archive capabilities
r00 RAR partial archive compressed file Can lead to remote code exploits due to self-extracting archive capabilities
reg Registry file Can change system settings and cause unexpected behaviour
sct Windows Script Component Can launch malware
sh UNIX shell script Can launch malware on UNIX workstations
shb Shell Scrap Object File Can launch malware
shs Shell Scrap Object Can launch malware
sys System Device Driver Can launch malware, kernel level.
uue UUE archive file Can be used to hide malware files
url Bookmarked URL File with a web URL that can open nefarious
vb VisualBASIC runtime can execute arbitrary code
vbe VisualBASIC can execute arbitrary code
vbs VisualBASIC script can execute arbitrary code
vcs Calendar file Buffer overflow in old Outlook versions
vxd Virtual Device Driver Can launch malware
wim Windows Image Format Can launch malware
wms Windows Media Player Skin Can launch malware
wsc Windows Script Component Can launch malware
wsf Windows Script File Can launch malware
wsh Windows Scripting Host Settings File Can launch malware or cause unexpected behavior
xll Microsoft Windows Executables Can launch malware

Conditionally Blocked Files

In addition to the above formats, some files are only blocked if certain conditions are met due to their widespread use.
Extension Description Conditions and Reason
zip File Archive ZIP archives contents are scanned using the same rules above. ZIP files which appear to be corrupted or in the wrong format (Files with a bad “magic file number”) are blocked, since they may contain exploits or executable malware.
eml Email message attachment Email forwarded in this manner without being marked as multipart alternative are quarantined, since a client may inadvertently open this extension automatically and execute malware.

Disabled HTML Tags

In addition to scanning message attachments, Raptor will also scan HTML messages for potentially malicious content including the following:
Tag Reason
iframe Iframe tags are used to “frame” or embed a remote website inside of an HTML email, and is blocked by Raptor due its use for phishing and tracking user email habits.
object The object tag is used to embed audio, video, ActiveX, PDF, Flash, and Java applets in an HTML document, which can be exploited on some clients to launch malware.
script The script tag is used to embed a Javascript or other executable program into an HTML document, and can be exploited to launch malware.

Previously Blocked Files

Below is a list of files which were previously blocked by our spam filters, but since have been removed. Reasons for their removal from the block list may include the widespread prevalence of a certain format, and the use of better secured software by clients.
Extension Removal  Date Reason
rar 2012-07-25 RAR files have had exploit vectors but the prevalence of the file format is too high. Please make sure you are using recent and secure software to handle RAR files.
vcs 2013-05-11 Old versions of Outlook contained buffer overflows which could be exploited when importing a calendar. The prevalence of the format and use of clients that no longer suffer from this vulnerability has prompted the removal of this file block.

Explanation of Threats

Macros
Macros are executable extensions of specific programs which are designed to automate long and tedious tasks. While some macro languages are limited from a programming perspective, many try to extend their usefulness by calling outside programs. Since some programs, such as document processors and office suites, allow the embedding of macros, it is possible to construct a malicious document that would download and run more capable malware as soon as it was opened.
We work to score Office documents with macros so they are considered spam due to the risk in receiving them.
Malware
Malware is a general term used to describe malicious software which causes unwanted, intrusive operation of a computer, normally unknown to the user. Malicious software includes but is not limited to virusesadwaretrojansworms, and spyware. Common infection vectors for malware include email attachments, intentional or driveby downloads, and removable media such as thumbdrives.
Viruses A computer virus is one type of malware which can spread by itself. As Wikipedia puts it, “the term “virus” is also commonly used, albeit erroneously, to refer to many different types of malware and adware programs.”
Virus

A computer virus is one type of malware which can spread by itself. As Wikipedia puts it, “the term “virus” is also commonly used, albeit erroneously, to refer to many different types of malware and adware programs.”

Adware
Adware is a type of software which displays or injects internet advertisments in an attempt to gain the author ad-revenue. Some adware may come from legitimate companies to support a business model, and may come bundled with your computer. Other sources may present unwanted pop-up ads, and generally are classified as having malicoius intent.
Trojans
A trojan, or “trojan horse”, is malware that masquerades as or is bundled with legitimate software. Sophisticated trojans, coupled with the implicit trust that a computer user unknowingly grants to the malware, is capable of cripling or disabling anti-virus software entirely, while consealing the problem from the user to evade detection.
Worms
A worm is a type of malware designed to replicate itself to spread to other computers or servers, usually relying on security flaws in physical networks to spread to as many computers as possible [1].
Spyware
Spyware is malware designed to silently steal information about an infected computer’s user by logging keystrokes, accessing local files, and collecting stored application data to be sent back to the spyware author. Some spyware is the direct payload of a trojan, although some has been known to spread as a virus.
Ransomware
Ransomware, sometimes known as cypherware, is a malicious program which encrypts personal documents stored on computers or otherwise restricts access to the computer, holding the computer “hostage” and demanding money in exchange for the decryption or access key. While some ransomware is trivial to defeat, the best defense against ransomware is to keep recent backups of your all personal documents.
Buffer Overflow
A buffer overflow is an unintentional flaw in software which can be exploited to run malware with the same privledges as the exploited program. An old or outdated browser may contain known buffer overflow exploits, which can be exploited to run malware through a specially crafted website. Keeping all installed software up to date is important to preventing security issues from buffer overflows.

Outlook Spam Folder Rules

 

Microsoft Outlook Raptor Anti-Spam Rule Recommendations
The Raptor Anti-Spam / Anti-Malware system labels unwanted emails with “[Spam]” in the Subject header. Some users receive hundreds and thousands of these unwanted emails per day so filing them away becomes imperative. These instructions will help you make two rules to filter out these emails with Microsoft Outlook.

1. Create 2 Folders to hold Spam marked by Raptor: 1 folder for Spam below a score of 15, and 1 for Spam scoring 15 and over.

A. On your Inbox you will Right Click and select “New Folder”.

B. Create another Folder and name it SPAM15. (If Outlook 2019 created a “spam” folder, name this new folder “spam15” for consistency.)

2. Now go to the File tab.

3. Click on Rules and alerts.

4. Click on New Rule and start from a blank rule.

5. Select “Apply rule on messages I receive” and click Next.

6.Check the condition “with specific words in the message header”

 

7. Click on “specific words” link in Step 2.

8. Enter “X-SPAM-Level: ***************” without the quotes in the Search Text box.

9. Click Add

10. Click OK

11. Click Next and select “move it to the specified folder”.

12. Click on “specified” link in Step 2.

13. Choose the “SPAM15” folder.

14. Click OK.

15. Click Finish.

16. Click on New Rule and start another rule from a blank rule.

17. Select “Apply rule on messages I receive” and click Next.

18. Check the condition “with specific words in the subject”

19. Click on “specific words” link in Step 2.

20. Enter “[Spam]” without the quotes in the Search Text box.

21. Click Add.

22. Click OK.

23. Click Next and select “move it to the specified folder”.

24. Click on “specified” link in Step 2.

25. Choose the “SPAM” folder.

26. Click OK.

27. Click Finish.

28. It’s important that you run the SPAM 15 & Over Rule first. If you created the rules in a different order, use the up/down arrows to change the order of the rules.

29. Click Apply

Periodically, you should check these folders and delete the unwanted e-mails. Also, if an email is missing, you check these folders (and the Junk Email folder if you use Outlook’s Junk Email Filter) first.  Because a higher score indicates an email is more likely to be spam, you should not have to check the SPAM15 folder as often as the SPAM folder.

Thunderbird Spam Folder Rules

Mozilla Thunderbird Raptor Anti-Spam Rule Recommendations

The Raptor Anti-Spam / Anti-Malware system labels unwanted emails with “[Spam]” in the Subject header. Some users receive hundreds and thousands of these unwanted emails per day so filing them away becomes imperative. These instructions will help you make two rules to filter out these emails with Mozilla Thunderbird

  1. On your inbox, Right Click and select “New Folder”.
  2. Name the new folder Spam
  3. Create another folder named Spam15.
  4. Left Click on the email account name above Inbox.
  5. Select “Message Filters”.
  6. Click New… to start from a blank filter rule.

  7. Ensure Getting New Mail: is checked.

  8. Click the drop-down that by default states Subject and select Customize.

  9. In the pop-up box, enter X-Spam-Level.

  10. Click Add

  11. Click OK to close the pop-up and X-Spam-Level will now be selected.

  12. Enter “***************” without quotes in the right-most text box

  13. Under “Perform these actions:”, select “Choose Folder…”
  14. In the drop-down, select your email account, select Inbox and then choose the Spam15 folder
  15.  


15. After verifying the information click OK to add the new Filter Rule


16. Next, click on New and start another blank rule.

17. Ensure Getting New Mail: is checked.

18. Ensure the far left drop-down states Subject and in the right-most text box enter, “[Spam]”

19. Under “Perform these actions:”, select “Choose Folder…”

20. In the drop-down, select your email account, select Inbox and then choose the Spam folder


21. After verifying the information click OK to add the new Filter Rule

22. It’s important that the Spam15 Rule is first. If you create them in a different order, use the Move Up and Move Down options to change the order.

23. Periodically, you should check these folders and delete the unwanted emails.

If an email is missing, you should check these folders first.

Because a higher score indicates an e-mail is more likely to be spam, you should not have to check the Spam15 folder as often as the Spam folder.

No Reply Address Setup for cPanel

If you legitimately use addresses like noreply@ to send emails, you need to ensure that address exists.

If you use cPanel, the following will do so and limit the storage for the account to 1 MB.

  1. Login to your cPanel account at :2083 (For example: cpanel.pccc.com:2083)
  2. Under the Email section, click Email Accounts.
  3. Click Create.
  4. Select the domain that needs the new account.
  5. Enter noreply as the username.
  6. Setup a password that meets the requirements or autogenerate. (This account should rarely/never be logged into.)
  7. Click Edit Settings.
  8. Set 1 MB storage space.
  9. Under the Automatically Create Folders for Plus Addressing, select Do Not Automatically Create Folders.
  10. Create the account.
  11. Under the Email section on the main dash, click Forwarders.
  12. Click Add Forwarder.
  13. Enter noreply in the address line.
  14. Click Advanced Options to reveal more options.
  15. Select Discard then Add Forwarder.

NOTE: Add other aliases to this account as needed.

Need Additional Help?

Let our experts take over!

Email Us

support@raptor.us

Call Us

+1.703.359.9700