We currently have our MTA as first tier, and in sk114034 it is stated that this is not recommended.
We see the problems indicated, like invalid recipients not being detected.
Instead of just following the non-recommended solution, I wanted to know how other have their MTA and mail servers configured, and set up topology wise.
We use the checkpoint gateway as the first tier, and a secondary spam server as second tier, and then our mail server.
Do you have an additional spam filtering server in front of the firewall? how do you handle this?