Re: SMTP server vs open relay
"Mike Easter" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.geeks |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Brad White wrote: > I sometimes use an external e-mail account besides my company account > to help keep mail sorted. > > Our local SMTP server locked up and had to be rebooted. > As a result (don't ask, long confusing story) my IT admin had > me install IIS and setup a local SMTP server on my local machine. There are some implications in the network topology 'non-description' there that need to be clarified. Does that mean that you are on a company network, and that company network is behind a genuine industrial strength firewall and is otherwise secured from the WAN internet at large? Does that also mean that your *own* network or machine are/is behind its *own* NAT device or other hardware firewall? I aks that because of a later statement you made about seeing your server. > To get it to work, I had to turn on relaying. Now I can send and > receive e-mail and everything seems to be working fine. Now you can send and receive email from whom or what? You can receive email from dynamic IPs direct to mx? You have your own MX inside of the company's network? Your mail is routed into the company's network past the firewall? None of the above? > Now I'm being accused of being a problem because I have relaying > turned on. No doubt that the IIS can be insecure. > I have it set to only allow mail from my IP, so I think > that I'm safe. That sounds good, except that we/I don't know/ can't tell/ what is set where behind what. > Now I just need to prove it. > A tech from my e-mail provider tried to relay something through > my SMTP server and couldn't even see it, so he thinks I'm safe, > but I'd like something more athoritative that I could show the admin > to calm him down. Now you can see why describing the network topology of your company and your IIS server as above is so important. I can't even tell where the email provider is compared to anything else. > How do I prove that this SMTP server can't be used as an open relay? Start by describing for sake of discussion where everything is, network-wise, and what kinds of firewalls or NAT devices are where. There's a IIS discussion here http://www.iis-resources.com/modules/AMS/article.php?storyid=5 how to set the SMTP Server security options. -- Mike Easter kibitzer, not SC admin