[TriLUG] Open Mail Relay - What Happened?
Kevin J.
mrkevinj at yahoo.com
Thu Jun 28 09:44:04 EDT 2007
Not sure about the fix, but you may want to setup a free monitoring service such as http://www.mxtoolbox.com/ to let you know if/when there are any problems with your mail server. They'll also let you know if you've been added to any blacklists (though there are a few false positives generated from unavailable lists on occasion.)
Kevin
----- Original Message ----
From: Randy Barlow <randy at electronsweatshop.com>
To: trilug at trilug.org
Sent: Thursday, June 28, 2007 12:23:22 AM
Subject: [TriLUG] Open Mail Relay - What Happened?
So I'm running postfix on Gentoo, and have been doing so happily since
about November. Until today I got a rejection for relayed mail notice
from Road Runner. I read on their site that this happens when your IP
address sends more than 1000 e-mails in 24 hours. My first thought was
my windows-using roommates, but then I checked my e-mail server from the
outside and indeed it was open. This is weird though, because I believe
I have it configured for authenticated users only. I even tried setting
it to only allow connections from this host, and still it happily
accepts connections from outside and tries to relay those e-mails to
other domains (of course, I would expect it to accept mail for
electronsweatshop.com.) Here are some settings in /etc/postfix/main.cf
that I think are relevant, anybody have any comments/criticisms/suggestions?
myorigin = $myhostname
mydestination = $myhostname, localhost.$mydomain, $mydomain
mynetworks_style = subnet # I tried setting to host to see if that would
# solve the problem (nope)
smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
smtpd_sasl_local_domain =
broken_sasl_auth_clients = yes
# I've tried the following also adding
reject_unauth_destination,reject_unknown_client, but that didn't solve
the problem either
smtpd_client_restrictions = permit_sasl_authenticated
smtp_use_tls = yes
smtpd_use_tls=yes
smtpd_tls_auth_only = yes
relayhost = smtp-server.carolina.rr.com
# I actually have several domains listed here. Does anyone know how to
get it to allow me to relay to all domains once I have properly
authenticated?
relay_domains = bunchofdomains.com
smtpd_tls_security_level = may
I fully appreciate any help anyone can offer. I made this setup just by
following some guides I found here and there online, and don't really
have a good grasp on the 6 volume manual that is postfix docs :)
--
Randy Barlow
http://electronsweatshop.com
But you are a chosen race, a royal priesthood, a holy nation, a people
for his own possession, that you may proclaim the excellencies of him
who called you out of darkness into his marvelous light. Once you were
not a people, but now you are God's people; once you had not received
mercy, but now you have received mercy. ~1 Peter 2:9-10
--
TriLUG mailing list : http://www.trilug.org/mailman/listinfo/trilug
TriLUG Organizational FAQ : http://trilug.org/faq/
TriLUG Member Services FAQ : http://members.trilug.org/services_faq/
____________________________________________________________________________________
Building a website is a piece of cake. Yahoo! Small Business gives you all the tools to get online.
http://smallbusiness.yahoo.com/webhosting
More information about the TriLUG
mailing list