<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.pmail.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search Results matching tags 'connection control', 'smtp', 'MercuryS', and 'mercury/32'</title><link>http://community.pmail.com/search/SearchResults.aspx?o=DateDescending&amp;tag=connection+control,smtp,MercuryS,mercury%2F32&amp;orTags=0</link><description>Search Results matching tags 'connection control', 'smtp', 'MercuryS', and 'mercury/32'</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP3 (Build: 20423.1)</generator><item><title>Re: Confused about SMTP acceptance</title><link>http://community.pmail.com/forums/post/7560.aspx</link><pubDate>Tue, 18 Mar 2008 10:36:53 GMT</pubDate><guid isPermaLink="false">f3644243-e206-4fd5-9143-9b53a0e05f23:7560</guid><dc:creator>Sebby</dc:creator><description>&lt;P&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://community.pmail.com/Themes/default/images/icon-quote.gif"&gt; &lt;strong&gt;Greenman:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't understand how Mercury was able to accept the mail from 61.145.143.171 when it is outside the allowed range of IP addresses. Am I missing something here?&lt;/P&gt;
&lt;P&gt;Is there any further configuration I need to carry out to ensure that Mercury only accepts SMTP connections from the allowed ranges?&lt;/P&gt;
&lt;P&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's not clear from here why the spammer even connected directly to your MTA - apsarchaeology.co.uk uses MessageLabs MXs, and the host apsarchaeology.co.uk doesn't run a public MTA.&amp;nbsp; The record must be cached by some ratware somewhere; in that case it should go away soon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The MercuryS ACL consists in the allow and deny list (see the help for a full description).&amp;nbsp; The allow list specifies hosts allowed to send mail and optionally those allowed to relay when otherwise prohibitted by configuration.&amp;nbsp; Specifying an allow entry without relaying permission is useful because it allows you to override a more general deny entry, which does just that - ban outright any connection from that host.&amp;nbsp; However, it is otherwise assumed that all hosts are allowed to connect but not to relay (providing relaying control is correctly configured, of course).&amp;nbsp; That's a necessary assumption, of course - mail to local users must always be accepted, and your configuration is unusual in that respect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To get the effect you want, simply ban every IP address on the internet (0.0.0.0 to 255.255.255.255).&amp;nbsp; It is then EXTREMELY IMPORTANT that you ensure EVERY HOST THAT DELIVERS MAIL TO YOUR HOST is allowed to do so.&amp;nbsp; Every allow range overrides the global ban.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Sabahattin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item></channel></rss>