OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Relaying mail for mobile users

From: Peter H. Coffin (hellsopninehells.com)
Date: Mon Mar 01 2004 - 11:10:41 CST


On Mon, Mar 01, 2004 at 03:51:40PM +0100, Javier Marcet wrote:
> >The second best is POP-before-SMTP explained here
> >http://sbserv.stahl.bau.tu-bs.de/~hildeb/postfix/postfix_pop-before-smtp_en.shtml
>
> I also know that one, but being my father the owner of the phone, I want
> to make it as easy as possible. Thus, I can't ask him to always manually
> check e-mail before sending a message.

Teaching him to do this WILL be less hassle than cleaning up after a
spammer abuses your mail relay. The simple rule of thumb is that
relaying should never be authorized solely on the basis of information
in the email that you don't have control over. Don't authorize for IP
addresses you don't own; don't authorize by sender, since those are
forgable and visible.

--
83. If I'm eating dinner with the hero, put poison in his goblet, then have to
    leave the table for any reason, I will order new drinks for both of us
    instead of trying to decide whether or not to switch with him.
                --Peter Anspach's list of things to do as an Evil Overlord