Here's what the spammers are doing. They send a message to the BACKUP server with a known BAD primary mail address for a domain in the HOSTS file and a SPAM CC address that they want to send to.
the cc: header contents are not used for delivery
the "spam cc" domain is in the hosts file?
The backup server accepts the mail because it is addressed to a domain in the HOSTS file and needs to send it on to the primary mail server.
Here's the problem: It goes ahead and delivers the SPAM CC message right away.
The bad primary message will get bounced, but that doesn't matter... the spammer got his message delivered off my backup server.
How can I stop this? Any ideas?
If what you are saying really is happening (show the MTA's log lines for the bad main and good cc domains), it's not your fault, it's a bug in the MTA on the backup MX server.
The backup MX function should only work for the domains in the envelope RCPT TO: field (that's the only domain exposed during the SMTP session), not in the cc: __header__
Len
_____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
