I was checking my logs of the SAVSMTP server in front of my imail server and I saw these from a few days ago. I have checked my imail log files and saw that nothing got through (YEAH). But I was curious, is this what they call a dictionary attack?
Not in this case, actually. A dictionary attack is where a spammer tries guessing E-mail addresses on your domain, to see which ones are valid. In this case, someone is "just" trying to relay mail through your server.
FYI, there are a lot of IPS here if you want to add them to your blocking list on imail.
Do NOT block those. If you do, you will get listed in spam databases:
21-Feb-2003 14:52:27 Action: Message Rejected From: 62.79.38.252 To: <[EMAIL PROTECTED]>
The "[EMAIL PROTECTED]" E-mail address is used by the ORDB spam database to see if you are an open relay.
Although it is debatable whether a spam database should be allowed to test to see if you are an open relay (the debate gets trickier if you sent E-mail to someone who uses their spam database), they do it. If you block their mail and they catch you, they will almost certainly list you (since many people who run open relays for some odd reason think that they shouldn't be listed in databases of open relays). If you block them, they can't see whether or not you are an open relay.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
