Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Help with a Mail Rule

Status
Not open for further replies.

jebenson

Technical User
Feb 4, 2002
2,956
US
Hello all,

My work has been getting a lot of spam (of course), but recently we have been seeing the return address as our domain. For example, say the domain is "mydomain.com". We have been getting email from "notauser@mydomain.com". The username on the return address is not in our company address book.

My question: is there a way (mail rule?) to block all incoming external email that has the domain "mydomain.com"?

Thanks,
JEB


I used to rock and roll every night and party every day. Then it was every other day. Now I'm lucky if I can find 30 minutes a week in which to get funky. - Homer Simpson
 
Anyone?

I used to rock and roll every night and party every day. Then it was every other day. Now I'm lucky if I can find 30 minutes a week in which to get funky. - Homer Simpson
 
The only thing that comes to mind would involve using the NAB to validate inbound mail. You'd have to have a setup that could validate the left-hand side of the destination address against valid addresses in the address book. Unfortunately, the simplest solution - using the SMTP MTA on the Domino server - exposes the public NAB to the outside world.

What I do is instead of exposing the public NAB via a Domino SMTP MTA, I have a relaying sendmail gateway (a load-balanced pair of Linux boxes, actually) that has a rule that compares the displayed sender host to what's actually in the packet header. I also extract the sender's host and validate it against a reverse-DNS lookup; I also process the sender host against four different RBLs, and after that I have a blacklist I built using entries from the Junk Mail block list in my Notes client.

Only then does a message get relayed to the Domino server for further processing, where I have moderate anti-spam rules. On a weekly basis, the primary gateway will reject 50 to 60% of inbound mail before it reaches the Domino server, and only get false positives once in a very great while (the last false positive was last November).
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top