The ip's are in your "relay for addresses"?Yes, it's in the iMail log file. Now either he's pretty sharp or it's one of the users at the client's mail server which I don't think is the case.About 2 minutes after the client has disconnected then he's there with the same host name (EHLO) and the IP address. Any ideas?
You probably can't do this, but if you can, it will surely help you secure your system, and perhaps immediately shut down the abuser.
Advise your users and then just set you your security to "no relay" (or "relay for addresse" reduced only to only those machines, like web apps, that can't smtp auth).
Len
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
