LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 08-05-2005, 04:32 PM   #1
kemplej
Member
 
Registered: Dec 2003
Posts: 235

Rep: Reputation: 30
Guarding Against Forged Email Bounces


I currently run a qmail+spamassassin+clamAV+vpopmail on a Slackware 10.1 server. One of the domains we currently host is being hit with bounced emails from spammers that forged our domain in their email headers. Is there any way I can guard against this or lessen the damange or anything at all? Or am I forced to just ride it out?
Thanks!

Justyn
 
Old 08-05-2005, 05:25 PM   #2
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Well, if they're coming into unused mailboxes, you could just redirect those to /dev/null with the .qmail files.
 
Old 08-05-2005, 05:53 PM   #3
demian
Member
 
Registered: Apr 2001
Location: Bremen, Germany
Distribution: Debian
Posts: 303

Rep: Reputation: 30
I've had that happening with a site I once worked for. A few users were getting insane amounts (several thousand a day) of bounce messages. Management decided that moving the affected users to new addresses wasn't an option so we had to come up with a solution. Basically my idea was that bounce mail can only come from sites we actually send mail to. So what I ended up with was a script that parsed the log files and recorded every address the affected accounts sent mail to into a database and kept it there for a few days. On incoming bounce mail (checked with some typical regexp for bounce messages) the mta would do a database lookup and silently disregard the mail if the loopkup didn't return anything.
 
Old 08-05-2005, 08:16 PM   #4
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
demian - quite an ingenious solution. Of course, it breaks down if users check email at home where it might go out through SMTP on their ISP, but every situation is different.
 
Old 08-05-2005, 08:51 PM   #5
demian
Member
 
Registered: Apr 2001
Location: Bremen, Germany
Distribution: Debian
Posts: 303

Rep: Reputation: 30
Quote:
Originally posted by Matir
Of course, it breaks down if users check email at home where it might go out through SMTP on their ISP
Yeah, I could exclude that possibility. Every piece of mail went through our servers. I'd say that's the case in most all situations: Say you have an account joe@somesite.com and then go and send out your mail through yourisp.net. Wouldn't
a) the mailserver at yourisp.net reject the mail as unauthorized relay and
b) the receiving mailserver reject it since it claims to be from somesite.com but was in fact sent through yourisp.net???

I'd most probably reject such mail or at least increase it's spam score by quite a bit for such suspicious routing.
 
Old 08-05-2005, 09:16 PM   #6
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
I hope not. I send outgoing SMTP through my isp's mailserver, and most webhosts reccomend that. My ISP's mailserver just requires I be on their netblock or authenticate via SMTP-AUTH.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
safe guarding your system by not allowing anyone to login as root abhis_mail2002 Fedora 6 05-14-2006 02:58 AM
qmail bounces lyon4349 Linux - Software 3 11-18-2005 08:30 AM
Forged email inaki Linux - Security 6 07-21-2005 06:08 PM
starcraft slows.. then bounces brainlesspinkey Linux - Games 1 11-18-2004 08:17 PM
Forged Email address from my domain! vittibaby Linux - Newbie 10 11-30-2003 07:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration