Skip to main content

Additional opportunities to prevent email abuse through domain matching?

Comments

6 comments

  • cPanelMichael
    Hello :) You may find the following option in "WHM Home " Service Configuration " Exim Configuration Manager" under the "Mail" tab useful: "EXPERIMENTAL: Rewrite From: header to match actual sender" Per it's description: "If you enabled this option, the From: header will be rewritten to be the email address of the actual message sender. If you choose the "remote" option, only messages that are being sent to remote destinations will be affected." Thank you.
    0
  • vanessa
    I didn't test this, but theoretically you can add this to the ACL section of exim.conf (WHM -> Exim Configuration Manager -> Advanced) acl_check_sender: accept authenticated = * deny !sender_domains = +local_domains
    This would basically make sure the sender is a local domain on the server, but will not go as far as matching the email addresses.
    0
  • brianoz
    [quote="vanessa, post: 1626102"> This would basically make sure the sender is a local domain on the server, but will not go as far as matching the email addresses.
    Vanessa - that's really useful. Is there a way to provide a specific message? I'd like to track a resulting log message and use that to disable that SMTP user as they've obviously been hacked.
    0
  • vanessa
    [quote="brianoz, post: 1628441">Vanessa - that's really useful. Is there a way to provide a specific message? I'd like to track a resulting log message and use that to disable that SMTP user as they've obviously been hacked.
    This might work (again, didn't test. I'm sorta lazy): acl_check_sender: accept authenticated = * deny !sender_domains = +local_domains log_message = "Sender domain does not match authenticated domain." message = "Sender domain does not match authenticated domain."
    0
  • Dayneuske
    I am having the same issue as OP and would love to implement the fix proposed by vanessa. However, I am not able to find the "acl_check_sender:" section of the advanced exim configuration manager. Doing a search for the setting has not helped any either. Can you tell me if this is a custom acl that needs to be added or if my version of the advanced exim configuration manager is messed up? If there is documentation on this setting can you provide the link and let me know the search terms used to find it? (Always looking to improve me search skills)
    0
  • cPanelMichael
    There is more discussion of that ACL here which you may find useful: acl_deny_sender Thank you.
    0

Please sign in to leave a comment.