Malcolm Weir wrote:
> So you can prevent the problem you experienced by having a local DNS server
> that resolves the Courier server's own details.

Besides mail specific settings (faked SPF or similar stuff), a 
dedicated DNS resolver for the MTA is a recommended security 
measure.

That conclusion is explained, e.g., in

    DNS-based Email Sender Authentication Mechanisms: a Critical
    Review
    http://amir.herzberg.googlepages.com/ea.pdf
    http://amir.herzberg.googlepages.com/somerecentpapers

that may be a good intro paper, and has several other links, 
including one to an MTA view of the Kaminsky attack that 
justifies the claim above.


------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to