How can I tell the difference between being hijacked or joe-jobbed?

If you are hijacked, the spammer is sending millions of E-mails through your network.


If you are joe-jobbed, they are sending millions of E-mails through other networks.

Only you can figure out the best way of finding out which it is. If you haven't received any abuse complaints, it probably is not from your network.

Have you checked one of the bounces and looked at the headers to see if it came from your network?

And how can I really protect the server from attacks?

IMail's SMTP Security options have a number of relaying choices. Of them, only 2 can be used safely (the rest cause you to be an open relay). The two safe options are "Relay for Addresses" and "No Mail Relay".


If you use IMail's "Relay for addresses", you would enter a list of "safe" IP addresses that your users may come from; anyone not coming from those safe IPs would need to use SMTP AUTH. If you use "No mail relay", everyone must use SMTP AUTH to relay mail. Note that relay settings apply only to outgoing E-mail, so no matter what your settings are, your users will still be able to get mail.

So to reiterate: "Relay for Addresses" or "No Mail Relay" are safe; everything else will get you listed in a number of spam databases.

Of course, protecting *other* computers in the network is trickier (your firewall should probably block all outgoing port 25 packets except from your mailserver).

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to