Microsoft® Office Outlook® 2003 provides two new features that can help users avoid receiving and reading junk e-mail messages — the new Junk E-mail Filter and the disabling of automatic content download from external servers:
- A new filtering manager helps users avoid reading junk e-mail messages. The filter is on by default and the protection level is set to Low, which is designed to catch the most obvious junk e-mail messages. The filter replaces the rules for processing junk e-mail messages in previous versions of Outlook.
- Outlook 2003 helps reduce the risk of Web beacons activating in e-mail messages by automatically blocking download of pictures, sounds, and other content from external servers in e-mail messages. Automatic content download is disabled by default.
You can configure settings to deploy these features to meet the needs of your organization. For example, you can configure the Junk E-mail Filter to be more aggressive, though it might catch more legitimate messages as well. Rules that are not part of junk e-mail management are not affected.
Configuring the Junk E-mail Filter
There are two parts to the Junk E-mail Filter:
- Three Junk e-mail Filter lists — Safe Senders, Safe Recipients, and Blocked Senders.
- State-of-the-art technology developed by Microsoft Research. This technology evaluates whether an unread message should be treated as junk e-mail based on several factors, including the message content and whether the sender is included in Junk E-mail Filter lists.
All settings for the Junk E-mail Filter are stored in each user's Outlook profile. You can override the profile settings by using policies for all options except the Junk E-mail Filter lists. However, you can create and deploy initial lists of Safe Senders, Safe Recipients, and Blocked Senders for your users.
The Junk E-mail Filter is provided for a subset of Outlook account types. The filter works best when used with Microsoft Exchange Server 2003 and later accounts, as described in detail later in this topic.
When Outlook users are upgraded to Outlook 2003 with the new Junk E-mail Filter, the old junk e-mail rules are removed and the rules information is not migrated.
Supported account types
Outlook 2003 supports junk e-mail filtering for the following account types:
- Microsoft Exchange Server e-mail accounts in Cached Exchange Mode
- Microsoft Exchange Server e-mail accounts when mail is delivered to a Personal Folders file (PST file)
- HTTP accounts
- POP accounts
- MSN® Hotmail® accounts
- IMAP accounts
The following account types are not supported for Outlook junk e-mail filtering:
- Microsoft Exchange Server e-mail accounts in Online (MDB) mode
- Third-party MAPI providers
Information about what junk-email filtering options are avalable with Exchange Server is included in the next section, "Support in different versions of Exchange Server."
In scenarios in which POP e-mail messages are downloaded into an Exchange Online (MDB) mailbox, Outlook blocks junk e-mail messages for the user's POP e-mail but does not block Exchange Online junk e-mail messages.
Support in different versions of Exchange Server
Junk E-mail Filter behavior varies depending on the Exchange Server version you use for messaging. Later versions of Exchange Server support more filtering options than earlier versions do.
The following list details Junk E-mail Filter behavior with different versions of Exchange Server.
- Versions earlier than Exchange Server 2003
If users use Cached Exchange Mode or download to a Personal Folders file (PST file): Users can create and use the Junk E-mail Filter lists, which are available from any computer that users use.
If users work online: The Junk E-mail Filter is not available.
If users use Cached Exchange Mode or download to a Personal Folders file (PST file): The Junk E-mail Filter lists that are available from any computer are also used by the server to evaluate mail. This means that if a sender is on a user's Blocked Senders list, mail is moved to the Junk E-mail folder on the server and is not evaluated by Outlook 2003. In addition, Outlook 2003 uses the Microsoft Research technology to evaluate e-mail messages.
If users work online: The Junk E-mail Filter lists that are available from any computer are also used by the server to evaluate mail. This means that if a sender is on a user's Blocked Senders list, mail is moved to the Junk E-mail folder on the server and is not evaluated by Outlook 2003.
Upgrading from a previous installation of Outlook
When users' older version of Outlook is upgraded to Outlook 2003, the rules that previously handled junk e-mail messages are removed. The existing rules and files used by the old filter are not migrated. The existing rules are handled as follows:
- Rules created by the old filter
With the old rules filter for junk e-mail messages, users could create up to three client-side rules for their mailbox — Adult Content Rule, Junk E-mail Rule, and Exception List.
Outlook removes these rules from the user's mailbox when Outlook 2003 is started for the first time on the user's computer. This means that Outlook 2003 always disables the old junk e-mail filter.
- Files that contain the Adult Senders list and the Blocked Senders list
These text files are left on the user's computer, but are no longer used by Outlook.
Configuring the Junk E-mail Filter user interface
You can specify several options to configure how the Junk E-mail Filter works for your users, including the following:
- Set the Junk E-mail Filter protection level.
- Permanently delete suspected junk e-mail messages or move them to the Junk E-mail folder.
- Trust e-mail messages from users' Contacts.
The default values for the Junk E-mail Filter are designed to help provide a good experience for users. However, you can configure these settings to different defaults when deploying Outlook to your organization, as well as set other options or policies, such as defining an alternative URL for the location of filter updates.
The junk e-mail settings are set only once. When the user first starts Outlook 2003, the settings are configured in the profile that the user chooses to use. Other profiles the user may have, or creates later, will not include the settings that you have configured. Instead, default settings will be used.
Default values for the Junk E-mail Filter settings are:
- Junk E-mail: Set to LOW
- Permanently delete: Set to OFF
- Trust my Contacts: Set to ON
These options can be configured by using the Custom Installation Wizard to specify default values for users, or the options can be enforced by policy.
If you configure default values by using the Custom Installation Wizard, a certain Junk E-mail setting must be configured for the new defaults to be applied.
To ensure default Junk E-mail settings are applied using the Custom Installation Wizard
- In the Custom Installation Wizard, on the Change Office User Options page, click the plus sign (+) next to Microsoft Office Outlook 2003.
- Click the plus sign (+) next to Tools | Options, then click the plus sign (+) next to Preferences.
- Under Junk E-mail, double-click Junk Mail Import list.
- Select the Apply Changes radio button.
- Leave the Check to turn off import of Junk Mail list check box cleared.
To enforce Outlook Junk E-mail Filter user interface options for users
- In Group Policy, load the Outlook 2003 template (Outlk11.adm).
- Under User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools | Options\Preferences, click Junk Mail.
- Double-click Junk E-mail protection level.
- Click the Enabled radio button to enable configuring the policy.
- In the Select level drop-down list, select a protection level to enforce.
- Click OK.
- Set other policies, such as specifying to permanently delete junk e-mail messages.
Creating and deploying the Junk E-mail Filter lists
You can deploy default Junk E-mail Filter lists to your users. The Junk E-mail Filter uses these lists as follows:
E-mail messages received from the e-mail addresses in the list or from any e-mail address that includes a domain name in the list will never be treated as junk e-mail.
E-mail messages sent to the e-mail addresses in the list or to any e-mail address that includes a domain name in the list will never be treated as junk e-mail.
E-mail messages received from the e-mail addresses in the list or from any e-mail address that includes a domain name in the list are always treated as junk e-mail.
If a domain name or e-mail address is on both the Blocked Senders list and the Safe Senders list, the Safe Senders list takes precedent over the Blocked Senders list to reduce the possibility of mail that users want mistakenly being marked as junk e-mail messages. The lists are stored on the server and so are available if users roam.
To deploy the Junk E-mail Filter lists, you create the lists on a test computer, and then distribute the lists to your users. The lists you provide are default lists; they cannot be locked down by policy.
The steps to create and deploy these lists are as follows:
- On a test computer, install Outlook 2003.
- Start Outlook and enter the desired entries for each Junk E-mail Filters list: Safe Senders, Safe Recipients, and Blocked Senders.
- Export each list to a separate text file.
- In the Custom Installation Wizard, on the Add/Remove Files page, include the three text files.
- Also in the Custom Installation Wizard, on the Change Office User Settings page, configure Junk E-mail Filter settings to turn on importing the filter list files and to specify the location of the files.
- After saving your customizations, deploy the transform (MST file) to users.
Start by installing Outlook on a test computer and creating the lists.
To create default Junk E-mail Filter lists to deploy to users
- In Outlook 2003, on the Tools menu, click Tools.
- On the Preferences tab, click Junk E-mail Options.
- On the Safe Senders tab, click Add.
- Enter an e-mail address or domain name. For example:
- Click OK.
- To add more e-mail addresses or domain names, repeat steps 3 through 5.
- Click Export to file.
- Enter a unique file name for the Safe Senders list, and then click OK.
- Repeat steps 3 through 8 with the Safe Recipients tab and the Blocked Senders tab to create Safe Recipients and Blocked Senders lists. Be sure to specify a unique file name for each of the three lists.
Next you configure your Outlook deployment so that the lists are distributed to users and imported when they start Outlook 2003 for the first time.
To customize Outlook deployment to install Junk E-mail Filter lists for users
- In the Custom Installation Wizard, on the Add/Remove Files page, click Add.
- In the Add Files to MST dialog box, select the three Junk E-mail Filter files that you created in the previous procedure.
Hold down the CONTROL or SHIFT key to select multiple files.
- Click Add.
- In the Destination path on the user's computer drop-down list, select the location where the files will be installed for users.
- Click OK.
- On the Change Office User Settings page, under Microsoft Office Outlook 2003\Tools | Options\Preferences, click Junk Mail.
Note This option must not be locked down by configuring the setting as a registry key in the Group Policy tree. Outlook must have read/write access to the registry key so that the value can be reset after the files have been imported.
- Double-click Junk Mail Import List and ensure that the check box is cleared so that the setting is applied and Junk E-mail Filter lists will be imported for users.
- To overwrite existing Junk E-mail Filter lists with new lists, double-click Overwrite or Append Junk Mail Import List.
- Click Apply Changes.
- Select the Check to overwrite list. Uncheck to append. check box.
- Click OK.
- To specify a path to each Junk E-mail Filter list, double-click the settings corresponding to each list (for example, Specify path to Trusted Senders list) and enter a path and file name in the box (for example, in the Specify path to Trusted Senders list box).
- Click OK (or click Next setting to specify the path for another Junk E-mail Filter list).
After completing your customizations for Outlook in the Custom Installation Wizard, click Finish to create a transform (MST file), and then deploy Outlook to your organization.
You can later update an existing Outlook 2003 installation to update the Junk E-mail Filter lists or to deploy the filter separately from your deployment of Outlook. To update current Outlook 2003 installations, use the Custom Maintenance Wizard to include the files and trigger an import for users (as described with the Custom Installation Wizard in the preceding procedure).
Configuring automatic picture download
To help protect users' privacy and to combat Web beacons — functionality embedded within items to detect when recipients have viewed an item — Outlook 2003 is configured by default to not automatically download pictures or other content from external servers on the Internet. You can configure options to change how automatic picture download works for your users by default, or lock down (enforce) settings for this feature by using Group Policy.
Messages in HTML format often include pictures or sounds, and sometimes these pictures or sounds are not included in the message itself, but are instead downloaded from a Web server when the e-mail message is opened or previewed. This is typically done by legitimate senders to avoid sending extra large messages.
However, junk e-mail senders can use a link to content on external servers to include a Web beacon in e-mail messages, which notifies the Web server when users read or preview the message. The Web beacon notification validates the user's e-mail address to the junk e-mail sender, which can result in more junk e-mail being sent to the user.
This feature to not automatically download pictures or other content can also help users to avoid viewing potentially offensive material (for external content linked to the message), and if they are on a low bandwidth connection, to decide whether an image warrants the time and bandwidth to download it. Users can view the blocked pictures or content in a message by clicking the InfoBar under the message header or right-clicking the blocked image.
By default, Outlook does not download pictures or other content automatically except when the external content comes from a Web site in the Trusted Sites zone or from an address or domain specified in the Safe Senders List. You can change this behavior so that content from any of the zones (Trusted Sites, Local Intranet, and Internet) will be downloaded automatically or blocked automatically.
You can also set other options to manage automatic content downloading, such as locking down the feature so that users cannot allow automatic content download for any content.
Automatic content download settings can be configured by default for users, or locked down by policy. To deploy default settings for users, go to the Change Office User Settings page in the Custom Installation Wizard. The settings to customize automatic content download behavior are in the same location in the Microsoft Office Outlook 2003 tree in the Custom Installation Wizard as they are in the Microsoft Office Outlook 2003 tree in the ADM template viewed in Group Policy.
To configure options for automatic picture download behavior in Outlook
- In Group Policy, load the Outlook 2003 template (Outlk11.adm).
- Under User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools | Options\Security, click HTML Mail External Content Settings.
- To change a policy for the automatic picture download feature, double-click an item in the Setting column.
For example, to lock down disabling automatic content downloading from all sites, double-click Block all external content.
- Click the Enabled radio button to enable configuring the policy.
- Select the check box in the policy, and then click OK.
You can configure a number of options for your Outlook deployment. To learn more about customizing your Outlook 2003 deployment, see Customizing Outlook Features and Installation With the Custom Installation Wizard.
You can use the Custom Maintenance Wizard to update your Outlook installation. For more information, see Updating Outlook 2003 by Using the Custom Maintenance Wizard.
The Outlook Junk E-Mail Filter uses intelligent spam-filtering technology to help prevent unauthorized or unwanted e-mail messages from reaching users. To learn more about how spam-filtering and other new features in Outlook 2003 work to reduce spam, download the Microsoft Office White Paper: Outlook 2003 Junk E-Mail Filter With Microsoft SmartScreen Technology whitepaper.
Updated versions of the Outlook Junk E-Mail Filter are released periodically. You can check for the latest filter on the Office 2003 Editions Administrative Updates page. You can also ensure that users have the latest version of the filter by regularly checking for and installing new Microsoft Office 2003 product updates.