Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PostFix - Domain and Envelope Sender Address

Status
Not open for further replies.

scroome

Technical User
Jan 10, 2003
3
0
0
GB
Hi,

We use a sender_access file to prevent external users sending mail apeearing from our domain ( example.com ) so that only our internal networks can send mail from our domain, but we still receive messages externally that have our domain as part of the email address in the message from field.

Is there any any other configuration options I should be using to prevent this ?

TIA, Simon.
 
External, non authenticated users should NOT be able to send mail through your domain. You should not need to use a sender_access list to prevent this and if you do, it is a strong indication that you have something screwed up in your configuration. In most circumstances, the two restrictions that govern this are permit_mynetworks and permit_sasl_authenticated, which means that only achines that you designated by IP address range and authenticated remote clients are allowed to send mail through your system.

Lets start by asking what smtpd restrictions are you currently using (helo, client, recipient, sender, etc)?
Also, see this page: About halfway down (a bit more than), there is a nice chart that shows which group of restrictions operates on what part of the SMTP process.

One other possibility is that there is a difference between the mail envelope information and the true connection information, where the envelop information is easily spoofed. Think of spam you have recieved where the FROM in the message says something like "Bank XYZ Security" and yet it was from boing-boing@somehost.tw, an obvious spoof, probably through an open relay.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top