Am I correct in thinking that if "relay mail for" only the ip of the server, and then I also check "disable smtp Auth reporting". No one will be able to remotely send mail out through the server, to send mail they would need to log into the web interface? But delivery and web sending should still work correctly?
Not quite.
First, you don't need to "relay mail for" the IP of the server, since (a) IMail automatically allows 127.0.0.1 to relay, so if you have a third-party app running on the server, it can just use localhost, and (b) web messaging does not use the SMTPD daemon, so web users will always be allowed to send mail off the box, as they are unaffected by the SMTPD settings.
If not that setting - then the no mail relay, right? Is there any advantage to one over the other?
Second, disabling SMTP AUTH reporting will not stop a dogged spammer from relaying mail using valid credentials. While well-behaved mail clients--all of the big ones in use, AFAIK--will assume that the lack of a SMTP AUTH announcement in response to an EHLO means that SMTP AUTH is not supported on a functional level, a mail client _designed_ to override or ignore the announcement will be able to push mail through. You _can_ use Outbound Rules to defuse relaying of this second sort, though you can't stop the mail from being submitted for remote delivery.
Is there a post or KB article about Outbound Rules that would handle this? Or some examples? We do use declude anti-spam standard edition for inbound spam rules.
I don't want anyone to be able to send mail using a client from their location, only to be able to send if they are on the server using webmail. If I understand correctly, of course anyone would always be able to send to the local users regardless, but I want to lock down the ability to send outside of our mail server.
Thanks so much.
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
