Open Relay Checker before Opening MTA

Ben Elliston bje at redhat.com
Sun Feb 10 11:10:35 EST 2002


>>>>> "Michael" == Michael Still <mikal at stillhq.com> writes:

  Michael> Greg Lehey's mail server does something similar to this. It also looks up
  Michael> the reported IP address in DNS and checks that it resolves the the
  Michael> hostname that the machine claimed. I am not sure what MTA he is using to
  Michael> do all of this though.

He uses Postfix:

  Trying 192.109.197.80...
  Connected to mx1.lemis.com.
  Escape character is '^]'.
  220 wantadilla.lemis.com ESMTP Postfix

I tried using Postfix's anti-spam options to do the same thing.  In
the end, I had to revert the change because I was rejecting far too
much legimate mail.

Trivia question: how many mail servers out there do you think have no
PTR records or if they do, don't match the name presented in their
HELO/EHLO?  Answer: Lots.

Ben




More information about the linux mailing list