Gentoo Archives: gentoo-server

From: "Vinícius Ferrão" <viniciusferrao@××××××××××.br>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Postfix Double Bounce Handling
Date: Mon, 14 May 2012 18:50:03
Message-Id: 0EB9FFAD-650F-4EF2-8EB8-3FCB572C3E91@cc.if.ufrj.br
In Reply to: Re: [gentoo-server] Postfix Double Bounce Handling by Michael Orlitzky
1 Thanks for your quick response Michael,
2
3 But I don't understand what can make my server a backscatter source.
4
5 I'm not relaying from outside, and I only accept messages from my domain, and only from my aging sendmail+dovecot server, so no relaying from outside.
6
7 What I don't have is what you said: check for local recipients. But this is a problem?
8
9 Thanks in advance,
10
11 On May 14, 2012, at 2:22 PM, Michael Orlitzky wrote:
12
13 > On 05/14/12 12:38, Vinícius Ferrão wrote:
14 >> Hello,
15 >>
16 >> I'm running a postfix mail filtering gateway in a hardened gentoo box
17 >> and I really don't know what to do with double-bounced messages.
18 >>
19 >> Since we have a lot of spam bots attacking our infrastructure, the
20 >> double bounce messages cannot be ignored and mail mail queue is growing
21 >> with undeliverable double bounce messages.
22 >>
23 >> Any thoughts on what should be done to handle this?
24 >>
25 >
26 > If you are accepting mail for addresses that don't belong to you, stop!
27 > That makes you a backscatter source, and will eventually (rightly) get
28 > you blacklisted.
29 >
30 > You said it's a mail filtering gateway... Usually the reason people
31 > backscatter on a gateway is because "it's hard" to get a list of all
32 > valid recipients; usually those recipients are on some other mail
33 > server. There are ways to do it, though, and you must, e.g.
34 >
35 > a) Run a cron job that pulls valid accounts every hour.
36 >
37 > b) Store the email accounts in a database, and allow the gateway to
38 > query the database to determine which users are valid.
39 >
40 > c) Use recipient verification[1]. When receiving mail, your gateway
41 > can open a connection to the real mail server in the background,
42 > and see if the recipient is valid.
43 >
44 >
45 > We use a combination of all three. We use (a) for an old Windows box,
46 > (b) for users stored in Dovecot, and (c) for customers with their own
47 > Exchange servers.
48 >
49 > If you ask over on postfix-users and provide the output of `postconf
50 > -n`, there are plenty of people who are able to give you tips relevant
51 > to your specific configuration.
52 >
53 >
54 > [1] http://www.postfix.org/ADDRESS_VERIFICATION_README.html#recipient
55 >
56 >

Attachments

File name MIME type
smime.p7s application/pkcs7-signature

Replies

Subject Author
Re: [gentoo-server] Postfix Double Bounce Handling Michael Orlitzky <michael@××××××××.com>
Re: [gentoo-server] Postfix Double Bounce Handling Tanstaafl <tanstaafl@×××××××××××.org>