Re: Domain spoofing



"Jim Schwartz" <shamusnc@xxxxxxxxxxxxxxxxx> wrote:

Except backscatter would come from <> and not their domain.

True. But refusing to accept mail addressed to /every/ mail-enabled
group you have is a good start. Even if it's not backscatter, stopping
spam to a big DL is a "good thing".

And if the message is disguised as a NDR, looking for your a
combination of your IP address with a bad server name is a good idea.

I agree that
accepting email from the internet "from" your domain isn't a good idea. Now
if I could just convince all those dumb developers and websites that it's a
bad idea.

Doesn't that just piss you off? Ever try getting a company like Cisco
to change? Or a telco? :-<

I like using IP connection based filtering for the lunkheads since they are
forced to tell me when they light up a new server. If I gave them some
authentication method, they'd end up posting it and using it wherever they
wanted.

That can be a lot of work in a big company, and error prone.

--
Rich Matheisen
MCSE+I, Exchange MVP
MS Exchange FAQ at http://www.swinc.com/resource/exch_faq.htm
Don't send mail to this address mailto:h.pott@xxxxxxxxxxxxx
Or to these, either: mailto:h.pott@xxxxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxx mailto:melvin.mcphucknuckle@xxxxxxxxxxxxxxx
.



Relevant Pages

  • Re: Very odd bounce
    ... This is an example of backscatter, it is spam, because the server at ... We literally receive thousands of these daily, they are blocked as spam. ... Jem Berkes ...
    (comp.mail.misc)
  • Re: How to do rDNS. WAS: RE: educating rDNS violators
    ... It's done in the DNS server. ... As a spam prevention measure, a lot of end-user Internet providers are ... Using your own mail server as a slave to the ISP's mail server will add ...
    (Security-Basics)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windows.server.sbs)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... When you enable recipient filtering on the SMTP virtual server, ...
    (microsoft.public.windows.server.sbs)
  • Re: Anyone succesfully stopped Reverse NDR Attacks in exchange 2000?
    ... to their filtering servers and the Spam stops filling your Exchange Queues ... and destined to an non existing address on your server. ... connecting addresses as there are spam sent. ...
    (microsoft.public.exchange2000.admin)