>I have checked the archive and it clearly states in a couple messages that
>"closed relay" will not sed mail to outside hosts.
ie, mail sent to Imail will only be accepted if the "RCPT TO:
recipient" is local/known to Imail.
>Does this apply to webmail as well?
Webmail uses the HTTP protocol: 1. to display mgs read from mailboxes
and 2. to send mail by placing the http-posted msgs into Imail's
spool-queue for delivery with the usual SMTP protocol.
Does Imail web msging check the SMTP security setting and validate
the "RCPT TO: recipient" coming from a browser submission? dunno
>I have my server set to closed relay (as far as I can tell) and
>email comes in and out just fine via the web.
oops. ipswitch??
>If I am only allowing webmail, what type of attacks should I be concerned
>about and whaqt can I do to protect myself.
Like water and everything else, spammers take the path of least
resistance, and sending spam over http, aka web mail, is not easy
compared to hosing tons of msgs through an open relay. So there
really isn't much risk, and, afaik, no defenses in Imail for
anti-spam coming from web mail.
However, one list member here told me privately that when he combined
free web mail with automted sign-up, then he had a pb with spammers
spamming using SMTP, since SMTP service was also available.
If you provide only webmail and no SMTP/POP3, then I doubt you're
going to have trouble with spammers.
However, note that web msging/http server is much more "expensive"
for the server, so you will need a much more powerful machine (cpu,
ram, $$$) to support 20K web mail clients than you ever will with 20K
smtp/pop clients.
Len
http://BIND8NT.MEIway.com: ISC BIND 8.2.2 p5 installable binary for NT4
http://IMGate.MEIway.com: Build free, hi-perf, anti-spam mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/