>I will try to explain the whole problem before anyone has a chance to
>respond

always good approach  vbg

>The only conclusion I could come up with is this INAME.com account is using
>my domain1.com as a gateway.

An authenticated user is relaying mail through your Imail.  He is not 
using his Imail account sender@senderdomain in his "MAIL 
FROM:".   How is this person different from perhaps 100's or 1000's 
of your Imail users who authenticate and relay through you using 
their Imail account name as sender info?

>I had no way of tracing this so I put iname.com on the kill.lst.

trace what exactly?

That's one way, but as Scott said, that's your policy decision to 
block your users from using non-Imail sender info.   I would say that 
as long as he's not abusing your server, then what harm is done?  He 
may have perfectly valid reasons for wanting to use other "mail from:" info.

>Now a member has called us and is complaining that he cannot send mail.

Unsurprising.  I'd be complaining, too.

>This (from what I can gather) is his configuration.  He has INAME setup to
>forward all incoming mail to domain1.com  He then checks his  domain1.com
>email with Outlook.  He says he is using a PGP key (probably doesnt matter).

That's his business, not yours.  Unless you have policy against 
encrypted mail.  If you have a policy against encrypted mail, how do 
you detect policy violations?

>Am I right in saying that he is (whether he knows it or not) is using my
>server as a gateway?

More specifically, he's using your Imail as a relay.  ALL of your 
Imail accounts use your Imail as a outbound relay.

>Whether it is or is not spam or malicious email sending is not the point.

ok, so what is the point?

>We all have policy and will stick by that policy if we know 
>something to be a fact or possible security risk.

If you have a policy that requires your users send only with their 
Imail account info, then apply the policy (after you figure out 
technically how to detect policy violations).

If you don't have a policy like that, then inventing one and applying 
it retroactively is probably breaking your contract with your 
clients, never a good idea.

>Please help me...

I fail to see the security risk to your company or your mail server 
if Imail-AUTHENTICATED, paying customers want to relay mail through 
your Imail server with a non-Imail "MAIL FROM:".   Damn, 
authenticated relaying is exactly what we RECOMMEND/require all users 
to do to avoid relay hijacking!

If you define some behavior as abuse of policy, then to police it, 
you have to detect it reliably so you can enforce the policy.

 From what you've shown us in the logs, I can't see anything abusive 
by this Iname account.  People where lots of hats at times, and 
change hats over time, same with mail accounts, so asking all their 
correspondents to change their addresses for such a person is a pain. 
Simpler for the others if the one person maintains several mail 
addresses.  Absolutely note abusive or risky.

What abuse or risk do you see in his use of Iname mail from: ?

Len



http://BIND8NT.MEIway.com : Binary for ISC BIND 8.2.3 T9B for NT4 & W2K
http://IMGate.MEIway.com  : Build free, hi-perf, anti-spam mail gateways


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to