linux-admin.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Blocking mail from certain domains....
@ 2003-10-09 23:42 Daniel W
  2003-10-10  8:15 ` Tommy Tovbin
  0 siblings, 1 reply; 5+ messages in thread
From: Daniel W @ 2003-10-09 23:42 UTC (permalink / raw)
  To: linux-admin

although a bit more tricky than that perhaps.


Say i own domain1.com and domain2.com

My users on each domain are getting emails from admin@domain1.com and
admin@domain2.com which are viruses but actually quite believeable. these
originate outside of my server but from various IP addresses.

Is there some way to make a rule:

Block all email from admin@*
where the sending IP is not [list of ip addresses that I own]


Where would I put this rule and how would it be activated? I think i have
procmail...or am i barking up the wrong tree?

Thanks for helping this newbie.

Regards,
Daniel





^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Blocking mail from certain domains....
  2003-10-09 23:42 Blocking mail from certain domains Daniel W
@ 2003-10-10  8:15 ` Tommy Tovbin
  2003-10-10  8:56   ` urgrue
  0 siblings, 1 reply; 5+ messages in thread
From: Tommy Tovbin @ 2003-10-10  8:15 UTC (permalink / raw)
  To: Daniel W; +Cc: linux-admin

On Fri, 10 Oct 2003, Daniel W wrote:

> although a bit more tricky than that perhaps.
> 
> 
> Say i own domain1.com and domain2.com
> 
> My users on each domain are getting emails from admin@domain1.com and
> admin@domain2.com which are viruses but actually quite believeable. these
> originate outside of my server but from various IP addresses.
> 
> Is there some way to make a rule:
> 
> Block all email from admin@*
> where the sending IP is not [list of ip addresses that I own]
> 
> 
> Where would I put this rule and how would it be activated? I think i have
> procmail...or am i barking up the wrong tree?
If you have procmail, you can do it like this:

in .procmailrc or in global procmailrc put the next rules:
:0 :
* ^From: admin@*
<folder-where-u-want-save-these-messages> or /dev/null

by the way, see http://piology.org/.procmailrc.html or google.com+ 
.procmailrc

> 
> Thanks for helping this newbie.
> 
> Regards,
> Daniel
> 
> 
> 
> 
> -
> To unsubscribe from this list: send the line "unsubscribe linux-admin" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> 

-- 
"This is UNIX country.    //=\  Tommy Tovbin
 if you listen carefully, \=//
 you can hear            //=\  tovbin at niisi dot msk dot ru
 Windows reboot..."      \=//  http://m1.sm.bmstu.ru



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Blocking mail from certain domains....
  2003-10-10  8:15 ` Tommy Tovbin
@ 2003-10-10  8:56   ` urgrue
  2003-10-10 11:06     ` Sven Pfeifer
  0 siblings, 1 reply; 5+ messages in thread
From: urgrue @ 2003-10-10  8:56 UTC (permalink / raw)
  To: admin

i think its even easier to just put:
bad_domain.com	REJECT
in your access table. this is usually /etc/mail/access.
you may need to hash that table:
makemap hash /etc/mail/access.db < /etc/mail/access
but i am under the impression that most sendmails these days are 
configured to hash tables on start, so it may be sufficient to just 
restart sendmail.



On 2003.10.10 11:15, Tommy Tovbin wrote:
> On Fri, 10 Oct 2003, Daniel W wrote:
> 
> > although a bit more tricky than that perhaps.
> >
> >
> > Say i own domain1.com and domain2.com
> >
> > My users on each domain are getting emails from admin@domain1.com
> and
> > admin@domain2.com which are viruses but actually quite believeable.
> these
> > originate outside of my server but from various IP addresses.
> >
> > Is there some way to make a rule:
> >
> > Block all email from admin@*
> > where the sending IP is not [list of ip addresses that I own]
> >
> >
> > Where would I put this rule and how would it be activated? I think i
> have
> > procmail...or am i barking up the wrong tree?
> If you have procmail, you can do it like this:
> 
> in .procmailrc or in global procmailrc put the next rules:
> :0 :
> * ^From: admin@*
> <folder-where-u-want-save-these-messages> or /dev/null
> 
> by the way, see http://piology.org/.procmailrc.html or google.com+
> .procmailrc
> 
> >
> > Thanks for helping this newbie.
> >
> > Regards,
> > Daniel
> >
> >
> >
> >
> > -
> > To unsubscribe from this list: send the line "unsubscribe
> linux-admin" in
> > the body of a message to majordomo@vger.kernel.org
> > More majordomo info at  http://vger.kernel.org/majordomo-info.html
> >
> 
> --
> "This is UNIX country.    //=\  Tommy Tovbin
>  if you listen carefully, \=//
>  you can hear            //=\  tovbin at niisi dot msk dot ru
>  Windows reboot..."      \=//  http://m1.sm.bmstu.ru
> 
> 
> -
> To unsubscribe from this list: send the line "unsubscribe linux-
> admin"
> in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> 
> 

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Blocking mail from certain domains....
  2003-10-10  8:56   ` urgrue
@ 2003-10-10 11:06     ` Sven Pfeifer
  2003-10-10 16:20       ` Joakim Ryden
  0 siblings, 1 reply; 5+ messages in thread
From: Sven Pfeifer @ 2003-10-10 11:06 UTC (permalink / raw)
  To: linux-admin

Hi,

urgrue <urgrue@tumsan.fi> wrote:
> i think its even easier to just put:
> bad_domain.com	REJECT
> in your access table. this is usually /etc/mail/access.

but it only works if you have all the bad_domains.tld, not for
admin@some-domain.tld.

> you may need to hash that table:
> makemap hash /etc/mail/access.db < /etc/mail/access
> but i am under the impression that most sendmails these days are 
> configured to hash tables on start, so it may be sufficient to just 
> restart sendmail.

If i guess right, Daniel uses exim, then he can´t restart sendmail.
In this case i think procmail, or an exim-mailinglist would be the
better choice.

[...]

Cheers

	Sven

-- 
7. When I've captured my adversary and he says, "Look, before you
   kill me, will you at least tell me what this is all about?"
   I'll say, "No." and shoot him. No, on second thought I'll shoot
   him then say "No."
   --Peter Anspach's list of things to do as an Evil Overlord
------------------------------------------------------[rand. sig. #13]
-
To unsubscribe from this list: send the line "unsubscribe linux-admin" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Blocking mail from certain domains....
  2003-10-10 11:06     ` Sven Pfeifer
@ 2003-10-10 16:20       ` Joakim Ryden
  0 siblings, 0 replies; 5+ messages in thread
From: Joakim Ryden @ 2003-10-10 16:20 UTC (permalink / raw)
  To: linux-admin

On Friday 10 October 2003 04:06 am, Sven Pfeifer wrote:
SP> Hi,
SP>
SP> urgrue <urgrue@tumsan.fi> wrote:
SP> > i think its even easier to just put:
SP> > bad_domain.com	REJECT
SP> > in your access table. this is usually /etc/mail/access.
SP>
SP> but it only works if you have all the bad_domains.tld, not for
SP> admin@some-domain.tld.
SP>
SP> > you may need to hash that table:
SP> > makemap hash /etc/mail/access.db < /etc/mail/access
SP> > but i am under the impression that most sendmails these days are
SP> > configured to hash tables on start, so it may be sufficient to just
SP> > restart sendmail.
SP>
SP> If i guess right, Daniel uses exim, then he can´t restart sendmail.
SP> In this case i think procmail, or an exim-mailinglist would be the
SP> better choice.

Letting an e-mail enter into your mail system(s) instead of rejeceting it in 
the SMTP conversation is usually NOT a good choice.

--Jo

-
To unsubscribe from this list: send the line "unsubscribe linux-admin" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2003-10-10 16:20 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-09 23:42 Blocking mail from certain domains Daniel W
2003-10-10  8:15 ` Tommy Tovbin
2003-10-10  8:56   ` urgrue
2003-10-10 11:06     ` Sven Pfeifer
2003-10-10 16:20       ` Joakim Ryden

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).