Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 05-05-2010, 01:25 PM
New Member
 
Posts: 3
Question Possible to verify outbound smtp 'from' address?

Hello,
In dealing with spambots we are trying to lock down our outbound smtp email transmissions to a given set of domains. E.g. if someone is using the smtp server to send emails, we want to check the 'from' line and verify that the address exists in zimbra or at least the domain is one of ours.
Is it possible to accomplish this in zimbra or the tools that comprise it?

Thanks,
--Christian

version: Zimbra Community Server 6.0.4

Last edited by gazumping; 05-05-2010 at 01:34 PM.. Reason: zimbra version
Reply With Quote
  #2 (permalink)  
Old 05-05-2010, 05:29 PM
Moderator
 
Posts: 1,209
Default

Not sure why you would need to do this?

Zimbra's Postfix is not an open relay. You can only send if you auth with credentials or have an IP listed in MTA Trusted Networks.

Have you added IPs to MTA Trusted Networks? Any compromised accounts on the system? I'd deal with those first...

Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #3 (permalink)  
Old 05-05-2010, 05:47 PM
New Member
 
Posts: 3
Default

I think we do have compromised accounts, people love to respond to falsified password requests.
I posted another thread asking for help in tracing down these compromised accounts. I do have trusted MTA IP blocks and user authenticated smtp.

Thanks for the quick reply,
--Christian
Reply With Quote
  #4 (permalink)  
Old 05-06-2010, 02:42 PM
Moderator
 
Posts: 1,209
Default

If you look at the Daily Mail Report you can see which of your mailbox accounts are sending out the most email; the ones that are sending way too much are likely compromised, yes?

You can then change the password on those accounts and call (by phone!) the "real" end-users to give them their new password.

I would really, really resist adding IPs to Trusted MTA. The only time we do this is for managed services clients of who have old emailing scanners that don't do auth. We require the client to devote a fixed public IP to the scanner, and we set up their firewall for them.

Once you get a compromised machine on your Trusted MTA list the chance of getting on RBLs increases significantly!

Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.