Sent from my Nokia phone -----Original Message----- From: Wietse Venema Sent: 24/04/2011, 6:23 PM To: Subject: Re: need help for controlling authenticated realy
Rajesh Kumar Mallah: [ Charset ISO-8859-1 unsupported, converting... ] > Hi, > > We allow relaying of email via our server to our clients using authentication. > The problem is that some miscreants have got hold of our clients password > and are using our email server to send SPAM after successfully authenticating. > > Please tell how to control this situation. > > I was thinking in lines of enforcing policies on even authenticated smtp > clients > that are pumping SPAM . Eg restrict clients not to send more than 10 emails > per minute , etc. Change the passwords. Then, google for policy, postfwd, etc. which support long-term rate limits. Wietse hi, thanks for the response, looks like you replied instead of replying all! i am using policyd but it looks like it has no control once the initial connection is established , authenticated and pipelining is being used to pump spam . Is it really so?. Also can anyone pls guide if/how it is possible to know what account was compromised by seeing the files that lie in the deferred section of postfix queue?