spf-discuss
[Top] [All Lists]

RE: Is anyone else getting DoS'd by relay attacks?

2005-01-09 10:28:18
Benjamin Franz [snowhare(_at_)nihongo(_dot_)org] wrote:
On Sun, 9 Jan 2005, Theo Schlossnagle wrote:
When a user is presented in the RCPT TO phase and that user does not
exist on the receiving system, then the mail server has two options:
 (1) accept the mail _knowing_ that it will send an MDN later
 (2) 550 5.0.1 user does not exist after RCPT TO:


(3) Accept it for delivery to the primary MX. Which _may_ trigger a MDN
    later.

It is non-trivial in many cases for a secondary MX to know whether or
not the left side of a address is valid or not - except by attempting to
deliver it to the primary MX.

(4) Before accepting the RCPT TO, try a live "call-forth" to the primary
MX to see whether the supposed recipient is valid.

Thus the receiving MTA would only have to risk a bounce to be generated
when the primary MX is actually down.  Which is usually not the case when
spammers submit their spam specifically to secondary MXes to circumvent
the primary MX's anti-spam measures.