Re: *panic* Open relay question..?

From: Ralf Hildebrandt (no email)
Date: Mon Apr 01 2002 - 13:21:24 EST


On Mon, Apr 01, 2002 at 07:44:01AM -0800, Bill Landry wrote:

> Search the named access database for the sender mail address, parent domain,
> or localpart at dot Reject the request if the result is REJECT or "[45]XX text".
> Permit the request if the result is OK or RELAY or all-numerical. Otherwise,
> treat the result as another list of UCE restrictions. The
> access_map_reject_code parameter specifies the result code for rejected
> requests (default: 554).

>
> I use the check_sender_access maptype under the smtpd_recipient_restrictions
> for customers that do not want their e-mail spam filtered by setting the
> "OK" flag after their e-mail address and it works great.

But you have to make sure you use reject_unauth_destination BEFORE
check_sender_access maptype , because otherwise you're an open relay.

-- 
Ralf Hildebrandt (Im Auftrag des Referat V A)   
Charite Campus Virchow-Klinikum                 Tel.  +49 (0)30-450 570-155
Referat V A - Kommunikationsnetze -             Fax.  +49 (0)30-450 570-916
Why you can't find your system administrators:
(S)he's out by the turnpike waiting for a case of Jolt to bounce out of the truck after it hits the speed bump. 
-
To unsubscribe, send mail to  with content
(not subject): unsubscribe postfix-users







Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD