vexim / vexim2

Virtual Exim 2
Other
70 stars 47 forks source link

Review order of RCPT-ACLs #205

Closed Udera closed 8 years ago

Udera commented 8 years ago

Changes:

Udera commented 8 years ago

Moved the relay-host block upwards. Only thing I'm not sure about, how does exim get the hostname? If it is just taken from the EHLO during the SMTP session, this value is not trustworthy. You could guess relay hosts. We should verify this to avoid someone becoming an open relay.

rimas-kudelis commented 8 years ago

DNS, I would guess?

Udera commented 8 years ago

Yes, perhaps. A reverse DNS lookup on the IP address. Or query the DNS name and check if one of the IPs is identical with the sender. Perhaps exim is already handling this, but we should check this.