Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 06 Sep 2001 12:58:49 -0700
From:      Terry Lambert <tlambert2@mindspring.com>
To:        Igor Podlesny <poige@morning.ru>
Cc:        Gregory Neil Shapiro <gshapiro@FreeBSD.ORG>, freebsd-isp@FreeBSD.ORG, hackers@FreeBSD.ORG
Subject:   Re: auto relaying for subdomains -- why?
Message-ID:  <3B97D579.921CBCE9@mindspring.com>
References:  <16615694707.20010905210719@morning.ru> <15254.22980.843972.348805@horsey.gshapiro.net> <8264494448.20010906104039@morning.ru>

next in thread | previous in thread | raw e-mail | index | archive | help
Igor Podlesny wrote:
> Yes,          I          saw          this          info         here:
> http://www.sendmail.org/m4/features.html#relay_mail_from    but   most
> valuable  part of my question was about the purpose or the idea behind
> this,  cause it's not too clear to me why allowing relaying for domain
> FOO.BAR  should  allow  relaying  for  SUB.FOO.BAR?  I  mentioned RFCs
> because  I had a hope to find out the answer from it but still haven't
> yet...

<bob@engr.sun.com>
<bob@mktg.sun.com>

Whose account name at your customer's site are you going to
intentionally render unintelligble, and force them to change
their business cards and stationary?

Alternately, why wouldn't they just say "screw you", and set
their masquerade features to make all the machines lie and
say they were sending from the domain?

What are you trying to accomplish by prohibiting some machines
legitimately in a delegated subdomain (for which account and
other authority has been vested in someone other than the main
site administrator, such as a departmental administrator) from
sending legitimate email?

Why do you want them to have to jump through hoops in order to
be able to send email which they will ultimately jump through
the hoops -- and send through your relay anyway?

What possible legitimate purpose is serves by letting <tom@xyz.edu>
send email, but prohibiting <tom@cs.xyz.edu> from sending mail?

I suspect that you are more concerned with having only a single
MAIL_HUB relaying email through you, rather than actually
prohibiting people from using delegated subdomains.  If so,
then your problem is because you are trying to use the wrong
tool to accomplish your task: do not use domain naming to try
to control relaying, or people will simply spoof their source
addresses, and relay an incredible amount of SPAM through your
mail relays, since they will leak like a sieve.

Also note: even if you prohibit outbound, you _can't_ do the
same for inbound, without prohibiting delegation of subdomains.

This would be like me insisting that you not use the email
address <poige@morning.ru>, because at the top level, I will
only allow relaying for <poige@ru>, since "morning.ru" is a
delegation from "ru".


In other words, if you are trying to solve a problem, tell us
the problem, don't ask us how to implement your proposed answer
to a secret problem you won't share with us.

-- Terry

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-hackers" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3B97D579.921CBCE9>