Roland Schneider <[EMAIL PROTECTED]> writes:

> Someone else may be able to elaborate on the risk of allowing ESMTP, but one 
> example is the VRFY command which will tell the client whether a user 
> account actually exists on the server and sometimes replies with the user's 
> full name. 

VRFY (and EXPN) are both RFC821 commands, not ESMTP.

I note that courier-esmtp does implement them, unlike most modern
mailers.  They can be turned off with BOFHNOEXPN and BOFHNOVRFY in the
esmtpd config file, though.

-Matt


_______________________________________________
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to