* Blocking mail from certain domains....
@ 2003-10-09 23:42 Daniel W
2003-10-10 8:15 ` Tommy Tovbin
0 siblings, 1 reply; 5+ messages in thread
From: Daniel W @ 2003-10-09 23:42 UTC (permalink / raw)
To: linux-admin
although a bit more tricky than that perhaps.
Say i own domain1.com and domain2.com
My users on each domain are getting emails from admin@domain1.com and
admin@domain2.com which are viruses but actually quite believeable. these
originate outside of my server but from various IP addresses.
Is there some way to make a rule:
Block all email from admin@*
where the sending IP is not [list of ip addresses that I own]
Where would I put this rule and how would it be activated? I think i have
procmail...or am i barking up the wrong tree?
Thanks for helping this newbie.
Regards,
Daniel
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Blocking mail from certain domains....
2003-10-09 23:42 Blocking mail from certain domains Daniel W
@ 2003-10-10 8:15 ` Tommy Tovbin
2003-10-10 8:56 ` urgrue
0 siblings, 1 reply; 5+ messages in thread
From: Tommy Tovbin @ 2003-10-10 8:15 UTC (permalink / raw)
To: Daniel W; +Cc: linux-admin
On Fri, 10 Oct 2003, Daniel W wrote:
> although a bit more tricky than that perhaps.
>
>
> Say i own domain1.com and domain2.com
>
> My users on each domain are getting emails from admin@domain1.com and
> admin@domain2.com which are viruses but actually quite believeable. these
> originate outside of my server but from various IP addresses.
>
> Is there some way to make a rule:
>
> Block all email from admin@*
> where the sending IP is not [list of ip addresses that I own]
>
>
> Where would I put this rule and how would it be activated? I think i have
> procmail...or am i barking up the wrong tree?
If you have procmail, you can do it like this:
in .procmailrc or in global procmailrc put the next rules:
:0 :
* ^From: admin@*
<folder-where-u-want-save-these-messages> or /dev/null
by the way, see http://piology.org/.procmailrc.html or google.com+
.procmailrc
>
> Thanks for helping this newbie.
>
> Regards,
> Daniel
>
>
>
>
> -
> To unsubscribe from this list: send the line "unsubscribe linux-admin" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
--
"This is UNIX country. //=\ Tommy Tovbin
if you listen carefully, \=//
you can hear //=\ tovbin at niisi dot msk dot ru
Windows reboot..." \=// http://m1.sm.bmstu.ru
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Blocking mail from certain domains....
2003-10-10 8:15 ` Tommy Tovbin
@ 2003-10-10 8:56 ` urgrue
2003-10-10 11:06 ` Sven Pfeifer
0 siblings, 1 reply; 5+ messages in thread
From: urgrue @ 2003-10-10 8:56 UTC (permalink / raw)
To: admin
i think its even easier to just put:
bad_domain.com REJECT
in your access table. this is usually /etc/mail/access.
you may need to hash that table:
makemap hash /etc/mail/access.db < /etc/mail/access
but i am under the impression that most sendmails these days are
configured to hash tables on start, so it may be sufficient to just
restart sendmail.
On 2003.10.10 11:15, Tommy Tovbin wrote:
> On Fri, 10 Oct 2003, Daniel W wrote:
>
> > although a bit more tricky than that perhaps.
> >
> >
> > Say i own domain1.com and domain2.com
> >
> > My users on each domain are getting emails from admin@domain1.com
> and
> > admin@domain2.com which are viruses but actually quite believeable.
> these
> > originate outside of my server but from various IP addresses.
> >
> > Is there some way to make a rule:
> >
> > Block all email from admin@*
> > where the sending IP is not [list of ip addresses that I own]
> >
> >
> > Where would I put this rule and how would it be activated? I think i
> have
> > procmail...or am i barking up the wrong tree?
> If you have procmail, you can do it like this:
>
> in .procmailrc or in global procmailrc put the next rules:
> :0 :
> * ^From: admin@*
> <folder-where-u-want-save-these-messages> or /dev/null
>
> by the way, see http://piology.org/.procmailrc.html or google.com+
> .procmailrc
>
> >
> > Thanks for helping this newbie.
> >
> > Regards,
> > Daniel
> >
> >
> >
> >
> > -
> > To unsubscribe from this list: send the line "unsubscribe
> linux-admin" in
> > the body of a message to majordomo@vger.kernel.org
> > More majordomo info at http://vger.kernel.org/majordomo-info.html
> >
>
> --
> "This is UNIX country. //=\ Tommy Tovbin
> if you listen carefully, \=//
> you can hear //=\ tovbin at niisi dot msk dot ru
> Windows reboot..." \=// http://m1.sm.bmstu.ru
>
>
> -
> To unsubscribe from this list: send the line "unsubscribe linux-
> admin"
> in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Blocking mail from certain domains....
2003-10-10 8:56 ` urgrue
@ 2003-10-10 11:06 ` Sven Pfeifer
2003-10-10 16:20 ` Joakim Ryden
0 siblings, 1 reply; 5+ messages in thread
From: Sven Pfeifer @ 2003-10-10 11:06 UTC (permalink / raw)
To: linux-admin
Hi,
urgrue <urgrue@tumsan.fi> wrote:
> i think its even easier to just put:
> bad_domain.com REJECT
> in your access table. this is usually /etc/mail/access.
but it only works if you have all the bad_domains.tld, not for
admin@some-domain.tld.
> you may need to hash that table:
> makemap hash /etc/mail/access.db < /etc/mail/access
> but i am under the impression that most sendmails these days are
> configured to hash tables on start, so it may be sufficient to just
> restart sendmail.
If i guess right, Daniel uses exim, then he can´t restart sendmail.
In this case i think procmail, or an exim-mailinglist would be the
better choice.
[...]
Cheers
Sven
--
7. When I've captured my adversary and he says, "Look, before you
kill me, will you at least tell me what this is all about?"
I'll say, "No." and shoot him. No, on second thought I'll shoot
him then say "No."
--Peter Anspach's list of things to do as an Evil Overlord
------------------------------------------------------[rand. sig. #13]
-
To unsubscribe from this list: send the line "unsubscribe linux-admin" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Blocking mail from certain domains....
2003-10-10 11:06 ` Sven Pfeifer
@ 2003-10-10 16:20 ` Joakim Ryden
0 siblings, 0 replies; 5+ messages in thread
From: Joakim Ryden @ 2003-10-10 16:20 UTC (permalink / raw)
To: linux-admin
On Friday 10 October 2003 04:06 am, Sven Pfeifer wrote:
SP> Hi,
SP>
SP> urgrue <urgrue@tumsan.fi> wrote:
SP> > i think its even easier to just put:
SP> > bad_domain.com REJECT
SP> > in your access table. this is usually /etc/mail/access.
SP>
SP> but it only works if you have all the bad_domains.tld, not for
SP> admin@some-domain.tld.
SP>
SP> > you may need to hash that table:
SP> > makemap hash /etc/mail/access.db < /etc/mail/access
SP> > but i am under the impression that most sendmails these days are
SP> > configured to hash tables on start, so it may be sufficient to just
SP> > restart sendmail.
SP>
SP> If i guess right, Daniel uses exim, then he can´t restart sendmail.
SP> In this case i think procmail, or an exim-mailinglist would be the
SP> better choice.
Letting an e-mail enter into your mail system(s) instead of rejeceting it in
the SMTP conversation is usually NOT a good choice.
--Jo
-
To unsubscribe from this list: send the line "unsubscribe linux-admin" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2003-10-10 16:20 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-09 23:42 Blocking mail from certain domains Daniel W
2003-10-10 8:15 ` Tommy Tovbin
2003-10-10 8:56 ` urgrue
2003-10-10 11:06 ` Sven Pfeifer
2003-10-10 16:20 ` Joakim Ryden
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).