Re: Stopping Frequently Forged Domains

From: Robert Dalton (no email)
Date: Sun Jun 02 2002 - 04:29:34 EDT


Michael Tokarev wrote:
> For quite a long time, my main.cf contains:
>
> smtpd_restriction_classes = freeemail
>
> smtpd_recipient_restrictions =
> ...
> reject_unauth_destination,
> ...
> check_sender_access fnmatch:yahoo.com|hotmail.com|mail.ru|mail.com|...:freeemail,
> ...
>
> freeemail =
> check_client_access fnmatch:*.yahoo.com|*.hotmail.com|*.mail.ru|*.mail.com|...:OK,
> reject
>
> This works *almost* like the patch found @monkeys.com. But this is somewhat funny:
> I myself block SMTP access from our local users to outside, so they are forced to
> use our smtp server. So if anyone here has e.g. mail.ru account, email with that
> address will be sent by our server, not by mail.ru servers. Note that many ISPs
> now blocks outgoing SMTP port as well.
>
> `fnmatch' map (it is not in standard postfix) may be changed to hash or whatether,
> I use it here as it is easy to read.
>
> BTW, reject_unknown_client is the default here, but I don't recommend to use
> it.

Yes, with reject_unknown_client, I notice storms of 450's for some smtp clients,
even though I've specified unknown_client_reject_code = 554. I understand that
postfix does this in situations where the reverse lookup zone is delegated,
but the lookup times out, or the zone is otherwise broken. Im guessing on this.

Thanks,

Robert Dalton
AccessWest.com

-
To unsubscribe, send mail to with content
(not subject): unsubscribe postfix-users








Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD