NGc> Could  anyone  help  us  by  explaining  this  phenomenon.

I  think  Scott  has  explained  %-based  source  routing  well. As he
mentioned,  this  is  not  a vulnerability unless you have two servers
that each must act as backup for the other (not a common setup).

However, I can't replicate what you describe in my testing. While

user

user@

user%

user%@

will  all  check  the  the default mailhost by design--and I don't see
much  harm in those, though there is a pretty simple workaround in not
having  your  default  mailhost have any users, setting up all of your
real  domains as [EMAIL PROTECTED] is rejected as an unauthorized relay
attempt. Are you testing against the always-whitelisted 127.0.0.1?

-Sandy


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to