Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Relaying - The Ugly Head Appears

Status
Not open for further replies.

TalentedFool

Programmer
Jul 23, 2001
214
GB

I'm going to hang my head in shame on this one.

Some unspeakable person out there has started to use my email server to spam emails to those poor people out there.

Basically what they are doing is sending from my domain as a totally garbage user to a list of email addresses.

e.g. sending from xyz@mydomain.com to youremail@domain.com

I'm sure that there is, but is there a way that I can stop this via the relay-domains file or the access file? Ideally what I want is a list of users who are allowed to send email and eveybody else is blocked

eg user1@mydomain.com - relay
user2@mydomain.com - reject

Does that make sense ?

Cheers


~ Remember - Nothing is Fool Proof to a Talented Fool ~
 
Make sure that your sendmail.mc does not contain
FEATURE(`relay_entire_domain')
This will allow a spammer to relay mail for entire class $m.
As long as your relay-domains and access files are set up the way they should be (i.e to accept and relay mail for your domain only) you should be OK.
You may want to check dsbl.org and make sure you are not blacklisted. This could prevent your own legitmate mail from being delivered if the intended recipient subscribes to "blacklists".

There is no God, only 10001010
 
Well, after much deliberation and testing I think I've got it cracked.

Problem we have is that the barstud was spaming from our domain .. so they were sending emails from xyz@mydomain.com which makes it a bit harder to lock down.

What I've done for now and hopefully it works is to remove the relay-entire-domain from the MC file, place all my users in the access file in the form

user1@ RELAY
user2@ RELAY

and at the end of it all put

From:mydomain.com REJECT

From what I've read about this and tested all my users will be allowed to relay and anybody who is not in the list will be blocked.

I've tested all the users and they are fine, now have to test the spam users that I've seen to see if they are blocked.

Not the best solution in the world I know but it if it works for now then hopefully they'll give up.

Will let you know how it progresses.



~ Remember - Nothing is Fool Proof to a Talented Fool ~
 
So will someone else who decided that he is also user1@realy

If you use a static IP then only allow those IP to relay mail and stop all others. If you have people on remote locales then you need a Webinterface or a tunnel

Dont allow ppp users to relay from the home accounts you will be spamming away again in no time.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top