> 1. The article I referenced explains WHY the original sender's email > address appears in the messages that everyone receives, and that > there is no way to "hide" it, at least not within the scope of an > iMail setting. See item FOUR below for more.
If this is a vulnerability in IMAILSRV, it is one in 99% of lists, public or private, on the Internet. I understand that you did not have list serving experience before you purchased IMail, and it could be explained much better in the documentation (though the trial version provides ample evidence of this limitation). In sum, though, this is not a grevious oversight on Ipswitch's part, nor would implementing this feature be the first order of business in improving IMAILSRV. > 2. NO, I did *not* mean "not being able to NOT include it (the > trailer text)". I meant exactly what I said -- if I create a > trailer, the manual says it will NOT appear at the bottom of > messages that are delivered to accounts ON the iMail server. This applies to the global trailer.txt, not to list trailers, as I said in my reply. You were reading the wrong part of the manual, and did not test. > And if this is not something that the "majority" of list servers > support (I don't care about the majority, I care about the one I > purchased, which says it supports trailers), this appears to be an > opportunity for IpSwitch to offer something the others don't. List management is not a real cash cow, presumably...that's why Web Messaging and Web Calendaring have been emphasized in development. I agree that it would be good, but none of us have been holding our breath, since this module hasn't changed appreciably (except for some undocumented fixes) in four versions. > HTML/Rich Text messages are a fact of life, and more to the point > are implemented features by MANY internet users, and server products > should keep up with that. They should indeed. > 3. Being a good citizen has little to do with whether or not one sends an > email message in plain text or HTML. I'm speaking specifically of "Internet citizens," however outdated the concept. I'm sure that there are many, say, evil CEOs (well, maybe not that many) who use plain text. > Yes, I fully understand that HTML has higher overhead, but you're > burying your head in the sand if you think that this sometimes > useful way of transmitting well-formatted messages (how about tables > that some users wish to present in their messages, without having to > do an attachment? An attachment typically has more overhead than an > HTML message that serves the same purpose. How about automatically > generated HTML invoices? etc. etc.) doesn't have it's place, even on > a listserv. It's fine for a listserv, just not fine for tagging with a trailer. If I decide to send JPEG-only advertisements to my customers, IMAILSRV won't blink, but how it's supposed to add trailers without advanced MIME processing is beyond me. > 4. My claim that list member's email addresses are NOT private (in other > words, any list member can discover the email addresses of all other list > members on a MODERATED, "PRIVATE" list) is not an "allegation", it's a > tested frickin' fact. As has now been shown to you, you didn't "frickin'" test your "fact" with the correct laboratory setup, or you'd have known that USERS cannot get this information, like I said: it seems like a loophole from the docs, but it is not. I almost challenged you to get the membership of the IMail Forum, but I thought that'd be too blatant. > the email addresses are available to all list members who know how > to issue that command via email, even with the checkbox checked on a > moderated, Private List (that checkbox is also checked) Don't think you tested this. > the article I mentioned also demonstrates how list member email > addresses can be discovered, just by reading the messages to the > list using certain email clients. Like, say, ANY client? > What is so perplexing about wanting to keep list member's email > addresses private, especially when they can be delivered in BULK to > anyone who knows the LIST command? Everybody knows the LIST command is ripe for spammers--but, as has been shown to you, it can be disabled. What's left is subscribing to a list, gathering addresses over time, and selling them (or being) a spamhouse. This method is used infrequently at best. It's not a worry for the people on this list, most of whom are professional sysdmins, nor for those on the most popular security mailing lists. Full anonymity, for legal and practical reasons (forging is made infallible if all headers, including source IP, are erased), is rarely used on mailing lists, and IMAILSRV's lack of support of this is unsurprising. -Sandy To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
