Querying a userbase need not involve local storage at all, thus making the "bootable CD" a red herring.
Anyway, the list of public email addresses for the users is not a security risk if were stolen by cracking into the MX.
To avoid passing DoS level of queries from the MX to backend user database server (mail to unk recips at 10k to 20k/hour is not uncommon, the worst I've seen was 70K), the user list should be on the MX's disk.
Nor need it involve the ability to browse the entire userbase. Nor need it involve touching the mailbox server. IMO, a properly architected mail architecure deals with harvesting
Harvesting is non-issue, so SMTP defenses should assume that the spammers have the addresses. The question is why anyone thinks a spammer having a valid email address is a problem? Since when is having a valid recipient address sufficient for successful delivery?
Len
_____________________________________________________________________ http://MenAndMice.com/DNS-training: Atlanta; Orlando; San Jose IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
