This paper presents a basic design and principles to protect enterprise networks from spam mail after considering a taxonomy
of spam mail based on their delivery schemes as well as their message envelope formats. The analysis of MTA mail logs of a
mail gateway at a sample enterprise network provides a correlation between senders’ mail addresses and their IP addresses.
Thus, a mail filter for gateways of these networks is proposed to prevent them from receiving spam mail from the Internet.
Finally, the effectiveness of this filter is demonstrated based on the results of mail log analysis.