Re: [suse-security] Email Spoofing
-----Original Message----- From: Alan Hadsell [mailto:ahadsell@MtDiablo.com] Sent: Thursday, July 22, 2004 5:32 PM
1) You don't have the Received: headers until the SMTP handshake is completed and the data is transferred. At that point in the protocol, there is no way to reject the mail; the receiving MTA has taken responsibility for it.
Thats not quite true, while its only reasonable for low traffic sites, with postfix you have the posibility using a before-queue content filter http://www.postfix.org/SMTPD_PROXY_README.html With a before-queue content filter you could inspect the received lines and accept the mail if a spf trusted mail server ist found. I would not recommend this, I just wanted to say theres a technical way to do it :) marc
participants (1)
-
Marc Samendinger