Use SPF :)<br><br><div><span class="gmail_quote">On 10/26/06, <b class="gmail_sendername">Glenn Steen</b> <<a href="mailto:glenn.steen@gmail.com">glenn.steen@gmail.com</a>> wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
On 25/10/06, James Fagan <<a href="mailto:jfagan@firstlightnetworks.com">jfagan@firstlightnetworks.com</a>> wrote:<br>><br>><br>> > We plan to introduce some premium filtering options for some domains.<br>
> > This will result in all incoming mail to a given domain<br>> > arriving from a single known IP address. To prevent<br>> > "back-dooring" we'd like to lock that in so any incoming mail<br>> > to a given domain from any other IP address is rejected or
<br>> > dropped. Can I create a ruleset to achieve that?<br>> ><br>> > TIA<br>> > Brian<br>> > --<br>><br>> We do something similar, but we have it setup at the customers<br>> firewall/router
<br>> to only accept connects on port 25 from one of our IPs (MailScanner<br>> boxes). This<br>> does stop the drive-by spam. We do this for all our clients permitted<br>> they have the<br>> hardware to achive this. Not exactly as you want to do it, but its an
<br>> alternative.<br>> Besides most customers don't know anything about ports and routing so<br>> you could charge<br>> them a maintence fee or something for comfiguring their<br>> routers/firewall.<br>>
<br>> Other than that I think you would be looking at some fancy pants<br>> iptables.<br>><br>> Or maybe there are other solutions?<br>><br>> James<br><br>This should be done at MTA level (where you have all the necessary
<br>info _and_ the ability to really reject mail (saving resources....).<br>Might be easier with some MTAs than others though:-). Or at least as<br>close a facsimile of that function as possible:).<br><br>--<br>-- Glenn<br>
email: glenn < dot > steen < at > gmail < dot > com<br>work: glenn < dot > steen < at > ap1 < dot > se<br>--<br>MailScanner mailing list<br><a href="mailto:mailscanner@lists.mailscanner.info">
mailscanner@lists.mailscanner.info</a><br><a href="http://lists.mailscanner.info/mailman/listinfo/mailscanner">http://lists.mailscanner.info/mailman/listinfo/mailscanner</a><br><br>Before posting, read <a href="http://wiki.mailscanner.info/posting">
http://wiki.mailscanner.info/posting</a><br><br>Support MailScanner development - buy the book off the website!<br></blockquote></div><br><br clear="all"><br>-- <br>Regards<br><br>Pravin