Sanford Whiteman wrote:
Am I correct in thinking that if "relay mail for" only the ip of the
server,  and then I also check "disable smtp Auth reporting". No one
will  be  able to remotely send mail out through the server, to send
mail they would need to log into the web interface? But delivery and
web sending should still work correctly?


Not quite.

First,  you don't need to "relay mail for" the IP of the server, since
(a)  IMail  automatically  allows 127.0.0.1 to relay, so if you have a
third-party  app running on the server, it can just use localhost, and
(b)  web  messaging  does  not use the SMTPD daemon, so web users will
always  be allowed to send mail off the box, as they are unaffected by
the SMTPD settings.

If not that setting - then the no mail relay, right? Is there any advantage to one over the other?



Second,  disabling  SMTP AUTH reporting will not stop a dogged spammer
from  relaying  mail  using valid credentials. While well-behaved mail
clients--all  of the big ones in use, AFAIK--will assume that the lack
of  a  SMTP  AUTH  announcement in response to an EHLO means that SMTP
AUTH  is not supported on a functional level, a mail client _designed_
to  override  or  ignore  the  announcement  will be able to push mail
through.  You  _can_  use  Outbound  Rules  to defuse relaying of this
second  sort,  though you can't stop the mail from being submitted for
remote delivery.

Is there a post or KB article about Outbound Rules that would handle this? Or some examples? We do use declude anti-spam standard edition for inbound spam rules.


I don't want anyone to be able to send mail using a client from their location, only to be able to send if they are on the server using webmail. If I understand correctly, of course anyone would always be able to send to the local users regardless, but I want to lock down the ability to send outside of our mail server.

Thanks so much.


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to