> Am I correct in thinking that if "relay mail for" only the ip of the
> server,  and then I also check "disable smtp Auth reporting". No one
> will  be  able to remotely send mail out through the server, to send
> mail they would need to log into the web interface? But delivery and
> web sending should still work correctly?

Not quite.

First,  you don't need to "relay mail for" the IP of the server, since
(a)  IMail  automatically  allows 127.0.0.1 to relay, so if you have a
third-party  app running on the server, it can just use localhost, and
(b)  web  messaging  does  not use the SMTPD daemon, so web users will
always  be allowed to send mail off the box, as they are unaffected by
the SMTPD settings.

Second,  disabling  SMTP AUTH reporting will not stop a dogged spammer
from  relaying  mail  using valid credentials. While well-behaved mail
clients--all  of the big ones in use, AFAIK--will assume that the lack
of  a  SMTP  AUTH  announcement in response to an EHLO means that SMTP
AUTH  is not supported on a functional level, a mail client _designed_
to  override  or  ignore  the  announcement  will be able to push mail
through.  You  _can_  use  Outbound  Rules  to defuse relaying of this
second  sort,  though you can't stop the mail from being submitted for
remote delivery.

--Sandy


------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
e-mail: [EMAIL PROTECTED]

SpamAssassin plugs into Declude!
    http://www.mailmage.com/download/software/freeutils/SPAMC32/Release/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to