Community Discussions and Support
Newbie question - Spammer faking local address...

Hello,

 to answer myself - to use 'Only authenticated SMTP connections may relay mail' was the solution for this.

Unclear to me was the exact meaning of 'relaying mail' in this context. I can send mail to external recipients, and I can receive mail from external senders. But if somebody fakes a local address, then he must be authenticated, which he will not be. Mail will be rejected. 

If the spammer does not fake, then he will be filtered by SpamCop and the local SpamHalter.

I hope this is correct now - seems to work.

jupiter11

<p>Hello,</p><p> to answer myself - to use 'Only authenticated SMTP connections may relay mail' was the solution for this.</p><p>Unclear to me was the exact meaning of 'relaying mail' in this context. I can send mail to external recipients, and I can receive mail from external senders. But if somebody fakes a local address, then he must be authenticated, which he will not be. Mail will be rejected. </p><p>If the spammer does not fake, then he will be filtered by SpamCop and the local SpamHalter.</p><p>I hope this is correct now - seems to work.</p><p>jupiter11 </p>

Hello,

we have a small game server and for adminstration, questions by players and so on we have a small Email server - Mercury 4.72.

Runs like a charm - but...

Staff (people who help me running our game server) are allowed to relay Email, so that players see the Email as coming from our domain. Everybody is allowed to send us Email, from the internet to local Email addresses. This works well,  especially since I upgraded to 4.72.

Before upgrade I saw a lot of Spam, where the 'From:' line was faked, so that it looked as if one of us had sent the Email. This disabled our Spam control.

Now with 4.72 I use the following configuration:

Relaying Email is only allowed for authenticated SMTP connections - so we can use our server to send Email.

SMTP  configuration tab 'Connnection control' has under relaying control

'Use strict local relaying rstrictions' - YES

' Authenticated SMTP connections may relay mail' - YES

'Only authenticated SMTP connections may relay mail' - NO

Now we have a mailing list configured, which is essentially an address like list_name@myhost.com and internally it is distributed to several local users. Everybody can send to this list, and all configured members receive the mail.

Now Spammers are sending to this list, in this form

From: Rolex.com <list_name@myhost.com>

To:  <list_name@myhost.com>

...

They seem to disable the local restriction, because they fake the 'From' address. What am I doing wrong?

Spam-mail with faked From-Lines (which emulated local, by using the same name as the Spam-addressee) have  stopped, but with the list it continues.

Should I use 

'Only authenticated SMTP connections may relay mail' - YES ?

Will we be able to send and receive mail normally with this configuration?

Thank you!

Jupiter11

 

&lt;p&gt;Hello,&lt;/p&gt;&lt;p&gt;we have a small game server and for adminstration, questions by players and so on we have a small Email server - Mercury 4.72.&lt;/p&gt;&lt;p&gt;Runs like a charm - but...&lt;/p&gt;&lt;p&gt;Staff (people who help me running our game server) are allowed to relay Email, so that players see the Email as coming from our domain. Everybody is allowed to send us Email, from the internet to local Email addresses. This works well,&amp;nbsp; especially since I upgraded to 4.72. &lt;/p&gt;&lt;p&gt;Before upgrade I saw a lot of Spam, where the &#039;From:&#039; line was faked, so that it looked as if one of us had sent the Email. This disabled our Spam control.&lt;/p&gt;&lt;p&gt;Now with 4.72 I use the following configuration:&lt;/p&gt;&lt;p&gt;Relaying Email is only allowed for authenticated SMTP connections - so we can use our server to send Email.&lt;/p&gt;&lt;p&gt;SMTP&amp;nbsp; configuration tab &#039;Connnection control&#039; has under relaying control&lt;/p&gt;&lt;p&gt;&#039;Use strict local relaying rstrictions&#039; - YES&lt;/p&gt;&lt;p&gt;&#039; Authenticated SMTP connections may relay mail&#039; - YES&lt;/p&gt;&lt;p&gt;&#039;Only authenticated SMTP connections may relay mail&#039; - NO&lt;/p&gt;&lt;p&gt;Now we have a mailing list configured, which is essentially an address like list_name@myhost.com and internally it is distributed to several local users. Everybody can send to this list, and all configured members receive the mail. &lt;/p&gt;&lt;p&gt;Now Spammers are sending to this list, in this form&lt;/p&gt;&lt;p&gt;From: Rolex.com &amp;lt;list_name@myhost.com&amp;gt;&lt;/p&gt;&lt;p&gt;To:&amp;nbsp; &amp;lt;list_name@myhost.com&amp;gt;&lt;/p&gt;&lt;p&gt;...&lt;/p&gt;&lt;p&gt;They seem to disable the local restriction, because they fake the &#039;From&#039; address. What am I doing wrong? &lt;/p&gt;&lt;p&gt;Spam-mail with faked From-Lines (which emulated local, by using the same name as the Spam-addressee) have&amp;nbsp; stopped, but with the list it continues.&lt;/p&gt;&lt;p&gt;Should I use&amp;nbsp; &lt;/p&gt;&lt;p&gt;&#039;Only authenticated SMTP connections may relay mail&#039; - YES ?&lt;/p&gt;&lt;p&gt;Will we be able to send and receive mail normally with this configuration?&lt;/p&gt;&lt;p&gt;Thank you!&lt;/p&gt;&lt;p&gt;Jupiter11 &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft