[TriLUG] Open Mail Relay - What Happened?

Kevin J. mrkevinj at yahoo.com
Thu Jun 28 09:44:04 EDT 2007


Not sure about the fix, but you may want to setup a free monitoring service such as http://www.mxtoolbox.com/ to let you know if/when there are any problems with your mail server. They'll also let you know if you've been added to any blacklists (though there are a few false positives generated from unavailable lists on occasion.)

Kevin


----- Original Message ----
From: Randy Barlow <randy at electronsweatshop.com>
To: trilug at trilug.org
Sent: Thursday, June 28, 2007 12:23:22 AM
Subject: [TriLUG] Open Mail Relay - What Happened?


So I'm running postfix on Gentoo, and have been doing so happily since 
about November.  Until today I got a rejection for relayed mail notice 
from Road Runner.  I read on their site that this happens when your IP 
address sends more than 1000 e-mails in 24 hours.  My first thought was 
my windows-using roommates, but then I checked my e-mail server from the 
outside and indeed it was open.  This is weird though, because I believe 
I have it configured for authenticated users only.  I even tried setting 
it to only allow connections from this host, and still it happily 
accepts connections from outside and tries to relay those e-mails to 
other domains (of course, I would expect it to accept mail for 
electronsweatshop.com.)  Here are some settings in /etc/postfix/main.cf 
that I think are relevant, anybody have any comments/criticisms/suggestions?

myorigin = $myhostname
mydestination = $myhostname, localhost.$mydomain, $mydomain
mynetworks_style = subnet # I tried setting to host to see if that would
                           # solve the problem (nope)
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
smtpd_sasl_local_domain =
broken_sasl_auth_clients = yes
# I've tried the following also adding 
reject_unauth_destination,reject_unknown_client, but that didn't solve 
the problem either
smtpd_client_restrictions = permit_sasl_authenticated
smtp_use_tls = yes
smtpd_use_tls=yes
smtpd_tls_auth_only = yes
relayhost = smtp-server.carolina.rr.com
# I actually have several domains listed here.  Does anyone know how to 
get it to allow me to relay to all domains once I have properly 
authenticated?
relay_domains = bunchofdomains.com
smtpd_tls_security_level = may

I fully appreciate any help anyone can offer.  I made this setup just by 
following some guides I found here and there online, and don't really 
have a good grasp on the 6 volume manual that is postfix docs :)

-- 
Randy Barlow
http://electronsweatshop.com

But you are a chosen race, a royal priesthood, a holy nation, a people 
for his own possession, that you may proclaim the excellencies of him 
who called you out of darkness into his marvelous light. Once you were 
not a people, but now you are God's people; once you had not received 
mercy, but now you have received mercy. ~1 Peter 2:9-10

-- 
TriLUG mailing list        : http://www.trilug.org/mailman/listinfo/trilug
TriLUG Organizational FAQ  : http://trilug.org/faq/
TriLUG Member Services FAQ : http://members.trilug.org/services_faq/


       
____________________________________________________________________________________
Building a website is a piece of cake. Yahoo! Small Business gives you all the tools to get online.
http://smallbusiness.yahoo.com/webhosting 


More information about the TriLUG mailing list