Re: Best practices for xss security in CMS? - Related Question

2014-03-05 Thread Nick Gleason
Hi Pete, I've been researching CSP and it sounds like a pretty cool option. But, I just wanted to follow up on this comment that you made below:-- it will also block inline scripts and style elements-- Are you

CF, SmarterMail, and DKIM

2014-03-05 Thread Michael Muller
Hey all, I am using SmarterMail to deliver my email from CF. However, emails that are generated don't seem to have the DKIM signing attached. I notice that they do if I send an email from my email program (Eudora), which connects directly to SmarterMail when sending. Currently, I have the

Re: CF, SmarterMail, and DKIM

2014-03-05 Thread Justin Scott
I am using SmarterMail to deliver my email from CF. However, emails that are generated don't seem to have the DKIM signing attached. Do you have a username and password entered into the Mail settings in the ColdFusion administrator for the connection to your mail server? -Justin

Re: CF, SmarterMail, and DKIM

2014-03-05 Thread Mik Muller
No. Will that fix it? Mik At 03:43 PM 3/5/2014, Justin Scott wrote: I am using SmarterMail to deliver my email from CF. However, emails that are generated don't seem to have the DKIM signing attached. Do you have a username and password entered into the Mail settings in the ColdFusion

Re: CF, SmarterMail, and DKIM

2014-03-05 Thread Russ Michaels
I think it might, as I think a requirement is you need to authenticate, so if you just have smartermail set to allow open relay from your web server, there is no authentication involved. give it a try. On Wed, Mar 5, 2014 at 9:27 PM, Mik Muller ad...@montaguema.net wrote: No. Will that

Re: CF, SmarterMail, and DKIM

2014-03-05 Thread e...@ebwebwork.com
In the past, this worked for me. I use a SmarterMail 12 / CF 9 combination too. *** Eric Bourland Internet Project Development Washington, DC www.ebwebwork.com kind | creative | professional From: Russ Michaels r...@michaels.me.uk

Re: CF, SmarterMail, and DKIM

2014-03-05 Thread Mik Muller
Right. That makes total sense. Rock on. Mik At 04:29 PM 3/5/2014, Russ Michaels wrote: I think it might, as I think a requirement is you need to authenticate, so if you just have smartermail set to allow open relay from your web server, there is no authentication involved. give it a try.

Re: CF, SmarterMail, and DKIM

2014-03-05 Thread Mik Muller
Fixed. Danke. Now to figure out why the public key is failing. Could just be propagation. BTW, if you ever want to see what mailservers see and possibly test for when they receive emails from your server, this is a BRILLIANT tool to use... http://www.brandonchecketts.com/emailtest.php

Re: CF, SmarterMail, and DKIM

2014-03-05 Thread e...@ebwebwork.com
Mik, I'm sure you've confirmed this already, but does the TXT Record value of the DKIM in SmarterMail match the value of the TXT Record Value you entered in the DNS record for your domain? I have found that sometimes it takes about a day for a DKIM TXT record to propagate -- dunno why.

slightly OT: Re: CF, SmarterMail, and DKIM

2014-03-05 Thread e...@ebwebwork.com
Slightly OT, but since some folks here use SmarterMail: There's a new version of SmarterMail 12 that apparently includes a security fix. http://www.smartertools.com/smartermail/releasenotes/v12.aspx http://portal.smartertools.com/kb/a2855/minor-upgrade-of-smartermail ***