It would be useful if there was a utility that would search the syslogs for lines like

11:18 08:08 SMTPD(008C0140) [66.222.200.6] MAIL FROM: <[EMAIL PROTECTED]>

and compare the 66.222.200.6 with pneumatictoolservices.co.uk

If they don't validate then write it to a text file. You could use this for your kill.lst and Control Access.

It works very well in theory, but not well in reality. SPF is going to be working on the shortfalls of this concept ("IPNOTINMX" in Declude JunkMail). The problem is that lots of legitimate companies will send out mail through mailservers that don't appear in the MX or A records for their domain (this is especially common with larger Internet providers that have separate mailservers for outgoing mail). Until there is a standard (like SPF) for domains to designate their allowed mailservers, blocking mail like this won't be very useful.



-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to