larslar
Verified User
I am having issues with my DirectAdmin installation. It would appear that anybody knowing a valid domain hosted on the system can send messages to a valid recipient with a forged from field.
For example, a malicious sender looks up the MX for domain.com and it points to my DA server. The sender connects to the mailserver and sends an email message from [email protected] to [email protected] and it is delivered.
This is not an open relay because it will not let you send outside of the server, but needless to say, this is annoying our email customers.
Should I enable authentication for senders in Exim? I though POP before send was the DA way?
Any advice would be most welcomed.
For example, a malicious sender looks up the MX for domain.com and it points to my DA server. The sender connects to the mailserver and sends an email message from [email protected] to [email protected] and it is delivered.
This is not an open relay because it will not let you send outside of the server, but needless to say, this is annoying our email customers.
Should I enable authentication for senders in Exim? I though POP before send was the DA way?
Any advice would be most welcomed.