Aliased domains bypass address verification

From: Sean Kennedy (no email)
Date: Tue May 01 2007 - 19:09:24 EDT

  • Next message: Dehnert James Sr: "Alias directory"

    Hello,

    I am running Postfix 2.3.3. I do recipient address verification with
    relay_recipient_maps that hooks up to an LDAP database. It recently
    came to my attention that aliased addresses aren't canonicalized and
    passed through relay_recipient_maps. So right now, anyone can send to a
    bogus and it would be accepted.

    Would adding all the aliases to my LDAP database then hooking that into
    virtual_alias_maps work? Is there any easier, perhaps more elegant way
    to do recipient verification on addresses that are aliases?

    Sean Kennedy


  • Next message: Dehnert James Sr: "Alias directory"





    Hosted Email Solutions

    Invaluement Anti-Spam DNSBLs



    Powered By FreeBSD   Powered By FreeBSD