spf-discuss
[Top] [All Lists]

Re: Is anyone else getting DoS'd by relay attacks?

2005-01-09 10:50:31

On Jan 9, 2005, at 12:14 PM, Benjamin Franz wrote:

On Sun, 9 Jan 2005, Theo Schlossnagle wrote:

When a user is presented in the RCPT TO phase and that user does not exist on the receiving system, then the mail server has two options:
 (1) accept the mail _knowing_ that it will send an MDN later
 (2) 550 5.0.1 user does not exist after RCPT TO:


(3) Accept it for delivery to the primary MX. Which _may_ trigger a MDN later.

It is non-trivial in many cases for a secondary MX to know whether or not the left side of a address is valid or not - except by attempting to deliver it to the primary MX.

It's trivial with the wide variety of MTAs that we've deployed and managed. (3) for all intensive purposes is (1), so it is _not_ best practices.

// Theo Schlossnagle
// Principal Engineer -- http://www.omniti.com/~jesus/
// OmniTI Computer Consulting, Inc. -- http://www.omniti.com/
// Ecelerity: fastest MTA on Earth


<Prev in Thread] Current Thread [Next in Thread>