Re: OT: spammers are using my domain again

From: Thomas Zehetbauer (thomasz_at_hostmaster.org)
Date: 10/08/04

  • Next message: Richard Houston: "Duel Monitor (not a laptop)"
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    Date: Fri, 08 Oct 2004 22:27:04 +0200
    
    
    
    

    On Fre, 2004-10-08 at 15:45 -0300, Trevor Smith wrote:
    > When I'm at home, and I try to send mail through my haligonian.com
    > smtp server (hosted in Quebec, remember), I can not succeed (can't
    > recall the error and I'm not home now).

    This means that either the company hosting your domain does not allow
    you to relay mail from your home account or your telco filters smtp
    connections to foreign servers.

    The first is a good thing as it also prevents spammers from connecting
    to your hosting provider's mail server and forging messages from your
    domain. Some years ago the white house's mailserver did not have this
    kind of protection and allowed everyone to almost perfectly fake a mail
    from the president.

    In the latter case, if your telco does not allow connections to foreign
    smtp servers they do not provide full-featured internet access and you
    should ask them to cease and desist or change your provider.

    > So, if I understand SPF correctly (and I may not), the procedure is to list
    > the (IP) addresses of machines that may be running SMTP servers through which
    > I may ever legitimately send an email.

    Correct.

    > Now, I have no idea how many of those servers there are or what their
    > addresses are.

    Should be easy to figure out using an A query (host -t a $smtpserver).

    > UNLESS -- SPF only needs simple records (not IP addresses) like:

    You could use ptr type records.

    > And what about the reports that Microsoft's patents (pending) make the
    > whole system suspect?

    They affect Sender-ID which was therefore dropped by IETF's MARID
    working group.

    Tom

    -- 
      T h o m a s   Z e h e t b a u e r   ( TZ251 )
      PGP encrypted mail preferred - KeyID 96FFCB89
          finger thomasz@hostmaster.org for key
    We are tied to the ocean. And we go back to the sea, whether it is to sail or
    to watch it we are going back from whence we came. - John F. Kennedy
    
    

    
    

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    


  • Next message: Richard Houston: "Duel Monitor (not a laptop)"

    Relevant Pages

    • Outbound TCP issue, potentially related to FreeBSD-SA-05:08.kmem [REVISED]
      ... separate FreeBSD machine. ... Outbound TCP connections are randomly failing to connect. ... It only impacts outgoing connections from our web servers - no ... finding that the failures were not port-specific, ...
      (freebsd-net)
    • Re: How to stop two servers in different sites trying to replicate with each other
      ... communicate directly with Site C and vice versa. ... ADSS the DC in Site B keeps setting up one of its replication partners to ... ISTG for intersites connections using BH) ... the ISTG won't use the BH servers between Site C and SiteB to ...
      (microsoft.public.win2000.active_directory)
    • Re: RRAS Dial on demand
      ... One of the servers I tested previously is now accepting connections. ... > Created DOD interface with name DOD1 ...
      (microsoft.public.windows.server.sbs)
    • RE: I think Ive been hacked...please help!
      ... ./I have several machines that are using excessive bandwidth. ... I find multiple connections to servers with names like ... ./Incoming connections are random although 1067 seems to be a common one. ... Maybe they don't see eggdrops as a threat / trojan. ...
      (Incidents)
    • Re: IpFilter / IpFireWall
      ... except for ones which are related in connections that were established as ... some badly configured servers test for ident (port ... See the security section in the FreeBSD handbook, ... compiling your kernel, and the ipfw manpage, for more details. ...
      (FreeBSD-Security)