>I have checked the archive and it clearly states in a couple messages that
>"closed relay" will not sed mail to outside hosts.

ie, mail sent to Imail will only be accepted if the "RCPT TO: 
recipient" is local/known to Imail.

>Does this apply to webmail as well?

Webmail uses the HTTP protocol: 1. to display mgs read from mailboxes 
and 2. to send mail by placing the http-posted msgs into Imail's 
spool-queue for delivery with the usual SMTP protocol.

Does Imail web msging check the SMTP security setting and validate 
the "RCPT TO: recipient" coming from a browser submission?  dunno

>I have my server set to closed relay (as far as I can tell) and 
>email comes in and out just fine via the web.

oops.  ipswitch??

>If I am only allowing webmail, what type of attacks should I be concerned
>about and whaqt can I do to protect myself.

Like water and everything else, spammers take the path of least 
resistance, and sending spam over http, aka web mail, is not easy 
compared to hosing tons of msgs through an open relay. So there 
really isn't much risk, and, afaik, no defenses in Imail for 
anti-spam coming from web mail.

However, one list member here told me privately that when he combined 
free web mail with automted sign-up, then he had a pb with spammers 
spamming using SMTP, since SMTP service was also available.

If you provide only webmail and no SMTP/POP3, then I doubt you're 
going to have trouble with spammers.

However, note that web msging/http server is much more "expensive" 
for the server, so you will need a much more powerful machine (cpu, 
ram, $$$) to support 20K web mail clients than you ever will with 20K 
smtp/pop clients.

Len


http://BIND8NT.MEIway.com: ISC BIND 8.2.2 p5  installable binary for NT4
http://IMGate.MEIway.com:  Build free, hi-perf, anti-spam mail gateways

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to