By enabling SMTP VRFY, am I opening the server to harvest or dictionary
attacks? Is this really a risk?

It seems that spammers just by issuing several RCPT TO: lines in a pipeline
and looking at the replies can simulate the SMTP VRFY command.

exactly. SMTP VRFY is no defense, but turn it off anyway.

Len

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to