Re: Stopping Frequently Forged Domains

From: Robert Dalton (no email)
Date: Mon Jun 03 2002 - 01:16:49 EDT


Stavros Patiniotis wrote:
> Hello,
>
>
>>Sure. For this, you should change last `reject' to something more complex.
>>E.g.:
>>
>>[]
>>
>>>>strict_client_domain =
>>>> check_client_access hash:/etc/postfix/strict_client_map, reject
>>>
>>strict_client_domain =
>> check_client_access hash:/etc/postfix/strict_client_map,
>> check_sender_access regexp:/etc/postfix/strict_sender_msg
>> ^^^^^^
>>
>>/etc/postfix/strict_sender_msg:
>>
>> /./ 554 use mailserver that handles your domain please
>>
>>This way, mail sent from some non-hotmail server with from address in hotmail
>>domain will be rejected with a message:
>>
>> 554 <>: Sender address rejected: use mailserver that
>> ^^^^^^
>> handles your domain please
>>
>>Or, more funny one:
>>
>>/etc/postfix/strict_sender_msg:
>>
>> /@([^@]*)$/ 554 use mailserver that handles $1 domain
>
>
>
> Won't this break your mail for the case in which one of your backup relays
> is delivering the mail to you?

add your mx backup to this file.

/etc/postfix/strict_client_map:
      yahoo.com OK
      hotmail.com OK
      friendly.com OK
      mxbackup.mydomain.com OK

;)

---
Robert Dalton
AccessWest.com
-
To unsubscribe, send mail to  with content
(not subject): unsubscribe postfix-users







Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD