RE: [qmailtoaster] Re: SPAM Emails generating from server

2013-09-12 Thread Amit Dalia
I'm using roundcube webmail as well. Anyway I had already blacklisted 127.0.0.1 in my spamdyke configuration and it worked. Thanks. Amit Dalia   -Original Message- From: Eric Shubert [mailto:e...@shubes.net] Sent: 13 September 2013 06:42 To: qmailtoaster-list@qmailtoaster.com Subject:

Re: [qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Quinn Comendant
On Wed, 11 Sep 2013 15:07:31 +0200, Johannes Weberhofer wrote: > this line in the spec will remove CRAM-MD5 completely: > > %{__perl} -pi -e "s|\#define CRAM_MD5||g" qmail-smtpd.c I'd like to do this as well to remove the dependence on pw_clear_passwd. It's really this easy? And the clients that

[qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Eric Shubert
On 09/12/2013 06:48 PM, Eric Shubert wrote: I'll mention this to Sam, to see how this might work. Good thing I checked the documentation before I posted: http://www.spamdyke.org/documentation/README.html#SMTP_AUTH The "none" value will effectively turn off smtp-auth, disabling submissions on

[qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Eric Shubert
On 09/12/2013 05:16 AM, Dan McAllister wrote: Suggested options (not sure how to do it -- hurt my back and not thinking 100% this morning): - Users are the only ones who should be using SMTP AUTH, and they should NOT be using port 25 when they do it... so the SMTP daemon on port 25 should NOT AL

[qmailtoaster] Re: DENIED_RDNS_MISSING and DENIED_OTHER

2013-09-12 Thread Eric Shubert
On 09/12/2013 05:49 AM, Dan McAllister wrote: As for the "denied other" message, you should look at other nearby lines in the log file -- there is likely another program blocking it for virus content or because its in an RBL you're subscribed to, or something similar. Just to be clear, RBLs are

[qmailtoaster] Re: SPAM Emails generating from server

2013-09-12 Thread Eric Shubert
On 09/12/2013 05:20 AM, Amit wrote: Please find below SMTP log. 2013-09-12 17:08:05.533459500 CHKUSER relaying rcpt: from remote rcpt mailto:onessaad...@yahoo.com>> : client allowed to relay 2013-09-12 17:08:05.533460500 policy_check: remote internalrevenueserv...@internalrevenue.org

[qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Eric Shubert
On 09/12/2013 11:12 AM, Peter Peltonen wrote: Hi, My 2 cents: On Thu, Sep 12, 2013 at 7:22 PM, Johannes Weberhofer mailto:jweberho...@weberhofer.at>> wrote: Am 12.09.2013 14:21, schrieb Dan McAllister: Eric, Why wouldn't it be possible to keep the plaintext password fiel

[qmailtoaster] Re: how to move all failure notice message to one email address

2013-09-12 Thread Eric Shubert
On 09/12/2013 05:35 AM, Dan McAllister wrote: Actually, I usually see this when the "catchall" setting is set to an address that doesn't exist, or forwards to an address that doesn't exist. This also happens when, as Eric was alluding to, the "failure" is actually fake -- the message it's complai

Re: [qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Peter Peltonen
Hi, My 2 cents: On Thu, Sep 12, 2013 at 7:22 PM, Johannes Weberhofer < jweberho...@weberhofer.at> wrote: > Am 12.09.2013 14:21, schrieb Dan McAllister: > > Eric, >> >> Why wouldn't it be possible to keep the plaintext password field in the >> vpopmail database, but protect it? >> I would think

Re: [qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Johannes Weberhofer
Am 12.09.2013 14:21, schrieb Dan McAllister: Eric, Why wouldn't it be possible to keep the plaintext password field in the vpopmail database, but protect it? I would think you could compile vpopmail to keep the cleartext passwords, but then create an additional user in the DB (an "admin" user)

Re: [qmailtoaster] Re: how to move all failure notice message to one email address

2013-09-12 Thread Dan McAllister
If you want to include your ISP's mail services, you'll need to know if your ISP even uses SPF (most do). - You could call them... good luck getting to talk to someone who knows what SMTP even stands for with most ISPs!... - Or, you could dig around a little Locally, brighthouse networ

Re: [qmailtoaster] DENIED_RDNS_MISSING and DENIED_OTHER

2013-09-12 Thread Dan McAllister
Vivek: You appear to believe that every message your server receives is legitimate and should be delivered... a belief that was common in the 1980's and 1990's and resulted in SMTP (the protocol) being so very easy to use for SPAM. We've learned our lesson, but are stuck in "backward compatib

Re: [qmailtoaster] Re: how to move all failure notice message to one email address

2013-09-12 Thread Dan McAllister
Actually, I usually see this when the "catchall" setting is set to an address that doesn't exist, or forwards to an address that doesn't exist. This also happens when, as Eric was alluding to, the "failure" is actually fake -- the message it's complaining about wasn't your message to begin with

Re: [qmailtoaster] Fwd: ezmlm warning

2013-09-12 Thread Dan McAllister
Sorry about that -- I implemented DMARC for my own domain, and gmail was grabbing that because there was no DMARC record in qmailtoaster.com. Mail for the qmailtoaster.com domain doesn't go through my systems, so its odd that gmail is doing that... I've queried google about it (DMARC is kinda n

Re: [qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Dan McAllister
Eric, Why wouldn't it be possible to keep the plaintext password field in the vpopmail database, but protect it? I would think you could compile vpopmail to keep the cleartext passwords, but then create an additional user in the DB (an "admin" user) and restrict rights to view that field to th

[qmailtoaster] SPAM Emails generating from server

2013-09-12 Thread Amit
Please find below SMTP log. 2013-09-12 17:08:05.533459500 CHKUSER relaying rcpt: from remote rcpt : client allowed to relay 2013-09-12 17:08:05.533460500 policy_check: remote internalrevenueserv...@internalrevenue.org -> remote onessaad...@yahoo.com(UNAUTHENTICATED SENDER) 2013-09-12 17:08:05.5

Re: [qmailtoaster] Re: Can I disable CRAM-MD5 authentication for submission service?

2013-09-12 Thread Dan McAllister
Suggested options (not sure how to do it -- hurt my back and not thinking 100% this morning): - Users are the only ones who should be using SMTP AUTH, and they should NOT be using port 25 when they do it... so the SMTP daemon on port 25 should NOT ALLOW SMTP AUTH at all - Its up to you whether