From: Rob F. <rf...@fu...> - 2007-06-07 08:44:03
|
Rob MacGregor wrote: > On 6/7/07, Florian <ts...@ag...> wrote: > > "4.1.1.1 Extended HELLO (EHLO) or HELLO (HELO) > > [...] The argument field contains the fully-qualified domain name > > of the SMTP client if one is available." > > Given how few clients actually obey that, if you expect any clients to > connect to that server it's probably best to relax that check. In my experience it's actually best to relax it for yourself and authenticated (initial-submit) users, but enforce it for random internet clients. That blocks a lot of spam while still allowing the broken clients that are OK to be broken. Similarly, it's quite useful to have the MTA to block outside clients who use the *server's* FQDN in the HELO. Amazing how much spam that blocks without losing legitimate mail. -- ==============================| "A microscope locked in on one point Rob Funk <rf...@fu...> |Never sees what kind of room that it's in" http://www.funknet.net/rfunk | -- Chris Mars, "Stuck in Rewind" |