четверг, 24 марта 2011 г.

Protecting MDaemon from relaying mail

KBA-01209



Purpose & Scope


This article describes protecting your server from relaying mail.

Procedure


The best way to prevent MDaemon from relaying mail is to use Domain/IP pairs. To configure this open MDaemon and from the menu bar:
IP Shielding
  1. Select Security
  2. Select IP Shielding/Auth/POP before SMTP...
  3. Check the box for Messages to valid local users are exempt from domain/IP matching
  4. In the Domain name field enter the domain name that you wish to associate with an IP address or range
  5. In the IP address field enter the IP address or range to associate the domain name with
  6. Click on the Add button
  7. Click the Apply button
  8. Click the OK button

When configured, a message that claims to be from one of the domains listed the IP address delivering the message must be listed in the domain IP pair. For Example, if you have “altn.com, 192.168.0.*” listed in your currently defined domain/IP pairs, a message from user@altn.com that is being received from 10.0.0.25 will not be accepted by MDaemon.
If you have users connecting from dynamic IP addresses on the internet that need to be able to send mail through MDaemon they will need to use ESMTP Authentication. To configure ESTMP Authentication:
  1. Select Security
  2. Select IP shielding/Auth/POP before SMTP
  3. Select the SMTP Authentication tab
  4. Check the box for Authenticated senders are valid regardless of the IP they are using
  5. Click the Apply button
  6. Click the OK button
Each user's email client will also need to be configured to use ESMTP Authentication. For specific information on how to configure ESMTP Authentication for your mail client please consult the Help system for your mail client.
RELAY CONTROL
Relay Control is used to prevent mail that is not TO or FROM a local user from being accepted in MDaemon.
  1. Select Security
  2. Select Relay/Trusts/Tarpit/Reverse Lookups/LAN IPs
  3. Select the Relay Settings tab
  4. Check the box for This server does not relay mail for foreign domains
  5. Check the box for Sender’s address must be valid if it claims to be from a local domain
  6. Click the Apply button
  7. Click the OK button
IP SCREENING
If you are receiving spam or other forms of abuse from a specific IP address, you configure MDaemon to drop connections coming from that IP address. Note: This will only work if you are receiving mail directly using SMTP. It will not work with mail received using DomainPOP or MultiPOP.
  1. Click Security
  2. Click Address suppression/IP screening/Host screening
  3. Click the IP Screening tab
  4. In the Remote IP box type the IP of the server that you wish to block
  5. Click the option This IP can not connect
  6. Click the Add button
  7. Click the Apply button
  8. Click the OK button
Note: If possible, it is better to block connections from IP addresses at your firewall, rather than accepting the connection and then blocking it in MDaemon.

Alt-n

0 коммент.:

Отправить комментарий