On Fri, 19 Oct 2007, M Core wrote:

> Sometimes I receive an email to my admin account stating that the email 
> I sent to an [EMAIL PROTECTED] was not sent.
> The message has an attachment and when you open them down eventually you 
> find a spam email that is FROM the [EMAIL PROTECTED] to a 
> [EMAIL PROTECTED]
>
> How is this happening? What do I look at?
>
>> From an external account I teleneted in and sent a message from the 
> [EMAIL PROTECTED] to [EMAIL PROTECTED] And it worked... 
> so I thought it is an open relay.
> But when I try any of the websites etc. to check for this none of them 
> can find an open relay on my mail server.

It's not an open relay. It accepts email for [EMAIL PROTECTED] 
That's where the bounce went to, because somebody forged the envelope from 
header to your valid account.

But now that you mentioned it - is there a way to make Courier make an 
additional check?

e.g. it receives a message:
From: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]

Normally, this is not too plausible to check if from is for a non-locally 
hosted domain, but if from is from a locally hosted domain, can we make 
Courier check if from is deliverable, and if not, reject with "unknown 
sender" or some such?

On a separate note, is it possible to get Courier to do return path 
verification? i.e. for the from address, look up mx, connect, and do:
HELO, MAIL FROM, RCPT TO, QUIT, just to see if the FROM address is 
deliverable?

Gordan

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to