The way it is going to work in 8.2 is you will be able to set the number off RCPT TO ERR's to allow during an SMTPD session before dropping the connection. i.e with this setting at 5, IMail will drop the connection after the 5 rcpt to error of the session.'
Welcome, but insufficient, since most subscriber PCs don't send a lot of recips per session, and individual subscribers PCs don't typically bang on any one MX in great volume. It's a distributed DoS.
The most typical situation is bogus recipients, one or a few per SMTP session, coming from 1000's of different IPS, predominantally subscriber access networks.
The best defense is a separate MX front end with a list of legit recipients, so IMail sees only valid recipients.
I don't think dictionary attacks/harvesting is the main activity, certainly not the harvesting part. It's just millions of infected PCs banging away, open loop, stupidly, at all our MXs.
Perhaps the new 8.2 SMTPD will be less prone to being DoSed by large numbers of connections, and large numbers of unknown recips, but every IMail prior to 8.2 is vulnerable, which is, among other things, what drives many Imail admins to add IMGate as MX.
Len
_____________________________________________________________________ http://IMGate.MEIway.com : free anti-spam gateway, runs on 1000's of sites
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
