>If i am understanding the documentation correctly, I can not set for relay
>for local addresses only as
>this is a public mail service..people on isps all across the US may be our
>customers.
>
>So I figured local users plus smtp auth  was the best option left. And of
>course a big kill list.
>This way in order to send mail from or through our  servers, they must login
>using smtp auth using their account name and password, AND the from address
>must be a valid mail user.

whoa, if they login successfully, what's the point of checking the 
"Mail From:" address??  The latter is perfectly, instantly, easily 
spoofable and so it totally untrustable.

>Am i thinking about that the right way?

no, the "relay for addresses" + "SMTP AUTH" is either/or.

either:  If the user is relaying from a trusted ip, the user is 
"treated as local" automatically and SMTP AUTH is not required (but 
it doesn't hurt to do it).

or: If the user is relaying from an un-trusted ip, an SMTP AUTH 
success results it Imail treating the user as "local", ie, as if on a 
trusted, relay-for ip.  you must have seen this phrase in the Imail logs.

So switch to relay for addresses and save yourself the hassle of a kill list.

Len


http://BIND8NT.MEIway.com: ISC BIND 8.2.2 p5  installable binary for NT4
http://IMGate.MEIway.com:  Build free, hi-perf, anti-spam mail gateways

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to