Operating System - HP-UX
1848366 Members
3322 Online
104024 Solutions
New Discussion

Re: sendmail config question

 
Bill Costigan
Honored Contributor

sendmail config question

How do you configure sendmail to prevent accepting messages from someone who has configured their sendmail to claim it's in your domain.

E.g., your domain is foo.com and your mail server will relay for foo.com. The bad guys configure their host to claim it's system1.foo.com and they send you mail to relay.

Can sendmail be configured to do a reverse IP lookup to see if the sending IP address is really who they claim to be?
5 REPLIES 5
harry d brown jr
Honored Contributor

Re: sendmail config question

Bill

sendmail is the beast of hell to modify the configuration

try this link:
http://www2.hunter.com/~skh/spam/sendmail.adds.html

better yet, hire a sendmail expert.


:-))


live free or die
harry
Live Free or Die
Mike Hassell
Respected Contributor

Re: sendmail config question

Bill,

I don't have a real solid answer for you, but you may wish to look into FEATURE(relay_hosts_only), that is if you can define all the hosts in domain.com that you want to relay mail for. Take a look at the following link that may lead you in the right direction:

http://www.sendmail.org/tips/relaying.html

Hope that helps, but as Harry says, sendmail config can be a real pain in the ass, as I'm sure you're already aware of :-)

-Mike
The network is the computer, yeah I stole it from Sun, so what?
Jordan Bean
Honored Contributor

Re: sendmail config question

If you have version 8.9.3 (PHNE_18546), then have a look at the Anti-spamming section of /etc/mail/sendmail.cf (around line 560) for immediate options.

Otherwise, think about upgrading to the latest version and build a new config file with the really cool anti-spam and security features.

benoit Bruckert
Honored Contributor

Re: sendmail config question

The best way is to use anti-relay feature.
add in your cf file :
FR-o /etc/mail/relay-domains
and store in this file domains (or ip addresses may be it work with subnet ???) for which relay is enable.
sendmail is doing a reverse lookup (at least with version 8.11.6) because i'm using it.

hope it 'll help
Une application mal pansée aboutit à une usine à gaze (GHG)
Bill Costigan
Honored Contributor

Re: sendmail config question

Thanks for all the hints.

I'll go to the various links and see if I can figure out how to close the hole.

I'm already running 8.9.3 and are using some of the anti-spamming features. But I must have left something open.