OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: accepting mail for ""domain.com

From: Aaron Bennett (abennettclarku.edu)
Date: Mon Feb 25 2008 - 09:34:58 CST


Ralf Hildebrandt wrote:
> * Aaron Bennett <abennettclarku.edu>:
>
>
>> it gets accepted as "to=<clarku.edu>"
>>
>
> No "orig_to=" entries for 82D8B31CA53 before that?
>
>
ok, here's a complete example. I sent this message through gmail with
<""clarku.edu> as the recipient. Gmail disallows <clarku.edu> but it
allows <""clarku.edu>.

We have root redirected to three addresses in /etc/aliases on our mail
relays _and_ we have an inline mail filter (amavisd-maia).

[roothector ~]# grep A86FE2B99B0 /var/log/maillog
Feb 25 10:14:30 hector postfix/smtpd[12433]: A86FE2B99B0:
client=el-out-1112.google.com[209.85.162.182]
Feb 25 10:14:30 hector postfix/cleanup[13858]: A86FE2B99B0:
message-id=<41846a660802250714w1d3237b5jcd264dac3c71938mail.gmail.com>
Feb 25 10:14:30 hector postfix/qmgr[5074]: A86FE2B99B0:
from=<abennettsystemspoet.com>, size=2723, nrcpt=1 (queue active)
Feb 25 10:14:31 hector postfix/smtp[12309]: A86FE2B99B0:
to=<clarku.edu>, relay=127.0.0.1[127.0.0.1], delay=1, status=sent (250
2.6.0 Ok, id=13921-03-5, from MTA: 250 Ok: queued as E23202B9C65)
Feb 25 10:14:31 hector postfix/qmgr[5074]: A86FE2B99B0: removed

[roothector ~]# grep E23202B9C65 /var/log/maillog
Feb 25 10:14:30 hector postfix/smtpd[13548]: E23202B9C65:
client=localhost.localdomain[127.0.0.1]
Feb 25 10:14:30 hector postfix/cleanup[13635]: E23202B9C65:
message-id=<41846a660802250714w1d3237b5jcd264dac3c71938mail.gmail.com>
Feb 25 10:14:30 hector postfix/qmgr[5074]: E23202B9C65:
from=<abennettsystemspoet.com>, size=2964, nrcpt=1 (queue active)
Feb 25 10:14:31 hector postfix/local[14046]: E23202B9C65:
to=<MAILER-DAEMONclarku.edu>, orig_to=<clarku.edu>, relay=local,
delay=1, status=sent (forwarded as F31972B9E9F)
Feb 25 10:14:31 hector postfix/qmgr[5074]: E23202B9C65: removed

[roothector ~]# grep F31972B9E9F /var/log/maillog
Feb 25 10:14:31 hector postfix/cleanup[13634]: F31972B9E9F:
message-id=<41846a660802250714w1d3237b5jcd264dac3c71938mail.gmail.com>
Feb 25 10:14:31 hector postfix/qmgr[5074]: F31972B9E9F:
from=<abennettsystemspoet.com>, size=3100, nrcpt=3 (queue active)
Feb 25 10:14:31 hector postfix/smtp[13654]: F31972B9E9F:
to=<abennettclarku.edu>, orig_to=<clarku.edu>,
relay=george.clarku.edu[140.232.1.173], delay=1, status=sent (250 2.6.0
<41846a660802250714w1d3237b5jcd264dac3c71938mail.gmail.com> Queued mail
for delivery)
Feb 25 10:14:31 hector postfix/smtp[13654]: F31972B9E9F:
to=<jgiangrandeclarku.edu>, orig_to=<clarku.edu>,
relay=george.clarku.edu[140.232.1.173], delay=1, status=sent (250 2.6.0
<41846a660802250714w1d3237b5jcd264dac3c71938mail.gmail.com> Queued mail
for delivery)
Feb 25 10:14:31 hector postfix/smtp[13654]: F31972B9E9F:
to=<jvieiraclarku.edu>, orig_to=<clarku.edu>,
relay=george.clarku.edu[140.232.1.173], delay=1, status=sent (250 2.6.0
<41846a660802250714w1d3237b5jcd264dac3c71938mail.gmail.com> Queued mail
for delivery)
Feb 25 10:14:31 hector postfix/qmgr[5074]: F31972B9E9F: removed

I understand, as Wietse suggested, I can mandate strict rfc_821
envelopes and that will probably stop this, but I'm really interested in
understanding why ""clarku.edu ends up as root. I know it's not an
ldap map, it's happening in /etc/aliases which says:

mailer-daemon: postmaster
postmaster: root
root: jvieiraclarku.edu jgiangrandeclarku.edu
abennettclarku.edu