Block incoming connections from bogus SMTP server

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Greetings

I came across an intresting method of spam blocking. It blocks the type of
spam that is a message that has been spoofed to resemble your own domain to
other addresses in your domain.

IE:
Company domain: hothead.ca
Company SMTP Server: mail.hothead.ca
Company SMTP Server: 172.16.1.12

Remote SMPT connects using:
Remote domain: hothead.ca
Remote SMTP server: mail.hothead.ca
Remote SMPT server: 10.25.36.47

In a single SMTP server setup you know exactly what server is supposed to
be sending mail on your behaf, so for this example the remote server is
definately not you. SPF can catch this if you have it enabled and
configered, but if you dont have an authentication process in place then
what to do?

The suggestion I encountered was to block incoming connections with your
domain name as the sending domain. Mail.hothead.ca receives a HELO from
mail.hothead.ca and the connection is dropped. Sounds like a heck on a plan.

What I want to know is how to get Exchange 2003 SP1 to do this?

Is it a DNS resolution thing or can a specific deny rule be setup without
impacting "normal" SMTP inbound connections?

If you have a working suggestion, please be specific on the location of the
process as I am still learning Exchange and dont always know where stuff is
yet.

Thank you for you time.


.



Relevant Pages

  • Re: Why Error 553 and how to fix it
    ... however it turned out to be a simple issue of the remote ... SMTP server rejecting the email. ... > the (insert latest virus name here) virus, all mail sent to my personal ...
    (microsoft.public.outlook)
  • Re: Free SMTP Class?
    ... My point was, local or remote, you have to send it to *AN* SMTP server. ... >> to have the class support sending directly without using a local server ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: sendmail
    ... > use elm or similar to send off email to my remote smtp server. ... You've had good advice on how to learn about setting up sendmail, ...
    (comp.unix.bsd.freebsd.misc)
  • Re: E-Mails
    ... Greg Keller ... If you are using a Cox SMTP server on Port 25 and are not connected to Cox's ... to get around the fact that ISPs block port 25 connections to 3rd ...
    (microsoft.public.windows.vista.mail)
  • two strange issues...
    ... Default setup rules for the Edge Firewall ... rules to publish web servers on the internal network. ... I see that it's attempted a few SMTP connections to my SMTP publish. ... SMTP server I use is a spam filter SMTP relay called ASSP. ...
    (microsoft.public.isa)