> Am I correct in thinking that if "relay mail for" only the ip of the
> server, and then I also check "disable smtp Auth reporting". No one
> will be able to remotely send mail out through the server, to send
> mail they would need to log into the web interface? But delivery and
> web sending should still work correctly?
Not quite.
First, you don't need to "relay mail for" the IP of the server, since
(a) IMail automatically allows 127.0.0.1 to relay, so if you have a
third-party app running on the server, it can just use localhost, and
(b) web messaging does not use the SMTPD daemon, so web users will
always be allowed to send mail off the box, as they are unaffected by
the SMTPD settings.
Second, disabling SMTP AUTH reporting will not stop a dogged spammer
from relaying mail using valid credentials. While well-behaved mail
clients--all of the big ones in use, AFAIK--will assume that the lack
of a SMTP AUTH announcement in response to an EHLO means that SMTP
AUTH is not supported on a functional level, a mail client _designed_
to override or ignore the announcement will be able to push mail
through. You _can_ use Outbound Rules to defuse relaying of this
second sort, though you can't stop the mail from being submitted for
remote delivery.
--Sandy
------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
e-mail: [EMAIL PROTECTED]
SpamAssassin plugs into Declude!
http://www.mailmage.com/download/software/freeutils/SPAMC32/Release/
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/