- Use "relay for IP addresses" and detail just your internal networks - i.e.
people that should always typically be allowed to relay - that's about the
only anti-relay tactic that works well short of no relay and smtp auth in
Imail.  Relay for local is very easily spoofed. Don't use it.
- I don't have SMTP auth enabled at my site because of similar problems with
mail clients not authenticating reliably (if everyone was on one platform it
would be great, but tweaking a setting that fixed one client broke others,
etc. - Netscape was the worst offender), but not using SMTP AUTH doesn't
mean you have to leave your mail server open to relay.
- For users outside of your network, make them use webmail, or make them use
the SMTP server of the service they are connected to.  Many providers are
starting to block outgoing SMTP at their network edges anyway, chances are
they may have problems using your server even if you allow it.

I am not an open relay, even without SMTP AUTH (I wish I could use it but we
had too many client issues when we tried it - we're an ISP so we have to be
kinda flexible with supporting different client software).  You need to do
whatever it takes to close your open relay, or your users will look
elsewhere for service (if your an ISP - or if you're a corporate network the
upper mgmt will start questioning why their mail keeps bouncing - neither
result is good).

- Tony







> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of R. Scott Perry
> Sent: Friday, February 22, 2002 3:15 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] OT::Bint for NT
>
>
>
> >On the Black list subject , I am not sure what put us on there..
>
> You got listed in NJABL because you run an open relay.  You'll likely get
> listed in ORBZ, ORDB, and some others (any that list open relays,
> regardless of whether or not they have sent spam yet) before long.
>
> >I wish that one you use
> >let you know the tests it did against my server to blacklist it.
>
> http://njabl.org/~njabl/cgi-bin/lookup.cgi?query=65.217.132.137 shows the
> date and time that they determined that you were an open relay,
> so you can
> see how they did it.  But it's very easy; you've said yourself
> that you run
> an open relay, and allow any mail using an address of yours to be
> sent through:
>
> >Imail is set to local users only.. that's as tight as I can make it
> >because customers
> >had too much trouble with SMTP auth for some reason.
>
> Which will cost more, to teach customers how to use SMTP AUTH, or to deal
> with a spammer who blocks all E-mail access for 12+ hours, causes
> lots more
> mail to get blocked as you get added to the "hard time" spam
> lists, forces
> you to deal with getting out of all the anti-spam databases,
> responding to
> people who received the spam (after all, you've forced the spam to use an
> address on your domain, making it easy for the spamees to contact
> you), and
> dealing with customers of yours whose mail can no longer be
> delivered.  And, to get out of those spam databases, you'll have to close
> your relay anyways.  So it definitely costs more not to close it, unless
> you are willing to be listed in lots of spam databases.
>
>                                                     -Scott
> ---
> Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for
> IMail.  http://www.declude.com
>
> ---
> [This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]


Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
---
[This E-mail was scanned for viruses by http://www.intouchmi.com]


---
[This E-mail was scanned for viruses by http://www.intouchmi.com]


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to