>We are running Imail V5.07. This last month we started seeing a lot of spam
>after two years as an open relay. We decided to change our stratagy a
>little. We set the Relay options to Relay mail for (all 15 of our class c
>address ranges)

good move, the best way.

>We also have allw remote mail to local groups checked, Check
>valid sender and Disable SMTP "VRFY" command checked. I have a lot of people
>that are in the field using our mail server but not logging into us.

try to get them to send mail through the ISP giving them access, is best, 
if they can't then all your dial-up clients "for their protection" must use 
SMTP AUTH for their outgoing SMTP mail to your server.

>I keep getting things like this. (Keep in mind that usmginc.com is a domain
>on our system and is is in the virtual host list.)
>
>04:25 08:33 SMTPD(14BD011E) [209.101.87.2] connect 208.61.164.63 port 1030
>220 X1 NT-ESMTP Server spacey.net (IMail 5.05 9503-3)
>HELO charles
>04:25 08:33 SMTPD(14BD011E) [208.61.164.63] HELO charles
>250 hello spacey.net
>MAIL FROM: <[EMAIL PROTECTED]>
>250 ok
>04:25 08:33 SMTPD(14BD011E) [208.61.164.63] MAIL FROM:
><[EMAIL PROTECTED]>
>RCPT TO: <[EMAIL PROTECTED]>
>04:25 08:33 SMTPD(14BD011E) [208.61.164.63] RCPT TO: <[EMAIL PROTECTED]>
>[x] looking up TSBI.ORG in HOSTS

means TSBI.org is not ok in NT HOSTS file for relaying,
Imail relaying denied for "RCTP TO: @TSBI.org"

and the SMTP client at 208.61.164.63 is an ADSL line at bellsouth, a 
"dial-up user", it's not a MX in DNS.

>I made this work by putting a check mark in the check valid sender box. This
>has now caused a flood of phone calls from people who do not have their from
>address or reply to address filled out properly.

hmm, your call there, they are being, maybe ignorantly, bad netizens and 
risk not having their mail accepted many places, so "for their own good", 
try to straighten their mail clients out.

>I have several companys that connect to us via Lan and they use our mail
>server but their domains are not hosted on our systems.

then you put their ip addresses in your "relay for addresses", assuming you 
"trust" them.

>Is the above configuration the best bet for us?

what's missing is you specifying to all your users to connect "for your and 
their own security and protection" to your mail server using SMTP AUTH in 
their mail clients. Then even the guy hanging out their on the end of a 
bellsouth adsl line can send AUTH'ed mail through you.

Len

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to