>I will try to explain the whole problem before anyone has a chance to
>respond
always good approach vbg
>The only conclusion I could come up with is this INAME.com account is using
>my domain1.com as a gateway.
An authenticated user is relaying mail through your Imail. He is not
using his Imail account sender@senderdomain in his "MAIL
FROM:". How is this person different from perhaps 100's or 1000's
of your Imail users who authenticate and relay through you using
their Imail account name as sender info?
>I had no way of tracing this so I put iname.com on the kill.lst.
trace what exactly?
That's one way, but as Scott said, that's your policy decision to
block your users from using non-Imail sender info. I would say that
as long as he's not abusing your server, then what harm is done? He
may have perfectly valid reasons for wanting to use other "mail from:" info.
>Now a member has called us and is complaining that he cannot send mail.
Unsurprising. I'd be complaining, too.
>This (from what I can gather) is his configuration. He has INAME setup to
>forward all incoming mail to domain1.com He then checks his domain1.com
>email with Outlook. He says he is using a PGP key (probably doesnt matter).
That's his business, not yours. Unless you have policy against
encrypted mail. If you have a policy against encrypted mail, how do
you detect policy violations?
>Am I right in saying that he is (whether he knows it or not) is using my
>server as a gateway?
More specifically, he's using your Imail as a relay. ALL of your
Imail accounts use your Imail as a outbound relay.
>Whether it is or is not spam or malicious email sending is not the point.
ok, so what is the point?
>We all have policy and will stick by that policy if we know
>something to be a fact or possible security risk.
If you have a policy that requires your users send only with their
Imail account info, then apply the policy (after you figure out
technically how to detect policy violations).
If you don't have a policy like that, then inventing one and applying
it retroactively is probably breaking your contract with your
clients, never a good idea.
>Please help me...
I fail to see the security risk to your company or your mail server
if Imail-AUTHENTICATED, paying customers want to relay mail through
your Imail server with a non-Imail "MAIL FROM:". Damn,
authenticated relaying is exactly what we RECOMMEND/require all users
to do to avoid relay hijacking!
If you define some behavior as abuse of policy, then to police it,
you have to detect it reliably so you can enforce the policy.
From what you've shown us in the logs, I can't see anything abusive
by this Iname account. People where lots of hats at times, and
change hats over time, same with mail accounts, so asking all their
correspondents to change their addresses for such a person is a pain.
Simpler for the others if the one person maintains several mail
addresses. Absolutely note abusive or risky.
What abuse or risk do you see in his use of Iname mail from: ?
Len
http://BIND8NT.MEIway.com : Binary for ISC BIND 8.2.3 T9B for NT4 & W2K
http://IMGate.MEIway.com : Build free, hi-perf, anti-spam mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/