Norman Maurer (JIRA) wrote:
i think the admin should check for correctness of the dns entries.. Such thinks 
teach admins ;-) But anyway if noone find this usefull i will discard it.. 
Maybe we should consider to add the feature of rcptchecks (lookup for valid 
users) .. This would be a good improvment, cause some blacklists (spamcop.net) 
blacklist severs if they accept such emails and sned a bounce after that.. So a 
permanent error on smtp level would be nice..

The problem arise with gateways/firewalls that uses NAT.
The MUA behind the firewall does not know the real public IP that will be presented to the outside servers, and the public IP is the one seen by the receiving MTA.

This is why I don't check for validity of the HELO argument.

This scenario happens too often in companies and given that most MTA will not enforce the validity of the helo argument most network administrator (of the sender network) thinks their configuration is good (they never had complaints before) and you start loosing too much time explaining they are wrong.

BTW, I'n not against this kind of patches. I simply say I'll not enable them because I think they don't increase my security, don't provide any improvement to my server and they make me spend more time explaining this kind of problems to others ;-)

Spammers seems the only ones that really take care to have a matching HELO argument.

Stefano


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to