>If i am understanding the documentation correctly, I can not set for relay >for local addresses only as >this is a public mail service..people on isps all across the US may be our >customers. > >So I figured local users plus smtp auth was the best option left. And of >course a big kill list. >This way in order to send mail from or through our servers, they must login >using smtp auth using their account name and password, AND the from address >must be a valid mail user. whoa, if they login successfully, what's the point of checking the "Mail From:" address?? The latter is perfectly, instantly, easily spoofable and so it totally untrustable. >Am i thinking about that the right way? no, the "relay for addresses" + "SMTP AUTH" is either/or. either: If the user is relaying from a trusted ip, the user is "treated as local" automatically and SMTP AUTH is not required (but it doesn't hurt to do it). or: If the user is relaying from an un-trusted ip, an SMTP AUTH success results it Imail treating the user as "local", ie, as if on a trusted, relay-for ip. you must have seen this phrase in the Imail logs. So switch to relay for addresses and save yourself the hassle of a kill list. Len http://BIND8NT.MEIway.com: ISC BIND 8.2.2 p5 installable binary for NT4 http://IMGate.MEIway.com: Build free, hi-perf, anti-spam mail gateways Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
