LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-27-2011, 09:15 AM   #1
manutdfan1988
LQ Newbie
 
Registered: Jan 2011
Location: Worcester, UK
Distribution: Red Hat 5.5
Posts: 28

Rep: Reputation: 0
Unsolicited Bulk Email - Sendmail SMTP


Have just setup Sendmail working as an SMTP mail server on our Red Hat linux production box.

However one of our users has got the error message below when trying to send to another domain, this does not happen for all it seem like a security policy of the specific domain.

I understand the message, the external IP showing from the client is 53 and the external from the mail server is 51 and there is obviously a mismatch.

Could this be to do with the access policy of sendmail in that it RELAY's mail for the local domain, should this be set to something different to allow the send to originate from the mail server rather than the client PC.

First upstream SMTP client IP address: [XX.XX.127.51] According to a 'Received:' trace, the message apparently originated at:
[XX.XX.127.53], XXXXXXX ip-XX-XX-127-53.easynet.co.uk [XX.XX.127.53] (may
be forged)



Regards,
 
Old 01-27-2011, 11:22 AM   #2
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
For starters you will need to look at the FULL header. I suspect you will see something along the lines of received by xxx.53 from xxx.51. In other words, showing that it came from .51, through .53 to the end client. However, from what you have provided and my experience with mail servers, I don't think that this is the cause of the problem. More than likely, either your IP range is listed in a block that is banned by someone and the recipient is picking this up OR this particular recipient declares everybody SPAM, unless you are specifically declared as NOT SPAM.
 
Old 02-09-2011, 09:02 AM   #3
manutdfan1988
LQ Newbie
 
Registered: Jan 2011
Location: Worcester, UK
Distribution: Red Hat 5.5
Posts: 28

Original Poster
Rep: Reputation: 0
Is there any way of making it look like the originator of the message is the server itself rather than the client PC?

The below appears in the message header

Code:
Received: from XXXCDT07 (ip-87-84-127-53.easynet.co.uk [87.84.127.53] (may be forged))
	by XXXWebServer.XXX.local (8.13.8/8.13.8) with ESMTP id p19FKFdj005100
Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Amavis and Unsolicited Bulk Email i_nomad Linux - Server 2 03-22-2010 09:49 AM
can't send email, smtp or sendmail dtra Linux - Software 1 11-19-2005 06:00 PM
Sending Email to an SMTP address from sendmail guilmetrp Linux - Newbie 6 03-01-2004 08:51 PM
Sending email to a smtp address through sendmail guilmetrp Linux - General 0 02-27-2004 08:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration