Re: Stopping Frequently Forged Domains

From: Len Conrad (no email)
Date: Tue Jun 04 2002 - 08:16:29 EDT


>Actually, I think the smtpd_recipient_restrictions rules should
>be ordered such that your MX's are permitted before any other
>restrictions. I would expect most MX's to be included in the
>$mynetworks list. You also want pop-before-smtp access lists to be
>checked before the strict_client_map restrictions.
>
>Something like the following seems to work. I got all of this from
>Ralph Hildebrandt and others on this list. It also has the benefit
>of holding off on most of the DNS lookup checks as long as possible.
>
>smtpd_recipient_restrictions =
> permit_mynetworks

here you are allowing your networks to send/receive to/from
unknown/unqualified domains, never a good idea.

Len

www.menandmice.com/DNS-training : DNS Training
BIND8NT.MEIway.com : ISC BIND for NT4 & W2K
IMGate.MEIway.com : Build free, hi-perf, anti-abuse mail gateways

-
To unsubscribe, send mail to with content
(not subject): unsubscribe postfix-users








Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD