I have a relay issue, i have 3 receive connectors configured, the two defaults connectors and a 3rd configured using the "INTERNET" template, now if i telnet on 25 to my ip or hostname and do mail from: xyz@xyz.com rcpt to: abc@abx.com i get unable to relay, so that works fine, now i have 1 accepted domain called trutecsolutions.com, and a user called john doe, wit h an email address of john.doe@trutecsolutions.com, if i telnet on 25 to ip or host name and do mail from: 123@123.com rcpt to: john.doe@trutecsolutions.com, then the message get delivered, what going on, and if i always do the same command but using mail from as administrator@trutecsolutions.com and rcpt to john.doe@trutecsolutions.com then john doe get an email from administrator, please help me, i am using the the recive connector with "internet" template
Posts: 6812
Joined: 9.Jun.2004
From: Philadelphia PA
Status: offline
I'm not seeing a problem right now. You have an accepted domain. You send a message to the accepted domain using a random sending address. The mail gets delivered. The relay messages you got is good. You would have had to do something unbelievably dumb to turn 2010 into an open relay - it's not just a click, click like it was 10 years ago.
the recive connector has ben set up as internet connector with internet template i have not change any thing on this connector and have not edited via power shell i.e extended rights
Posts: 6812
Joined: 9.Jun.2004
From: Philadelphia PA
Status: offline
That's perfect. Exchange doesn't check (by default) that the IP you are coming from is associated with xyz.com and since you 'own' trutec it's accepting the message. Again, by default Exchange will accept anything@yourdomain but you can tweak that so that if there isn't a nick@ but there is a nick.spender@ it will refuse the nick@ but accept the other one. Unless you're explaining badly or I'm not seeing it (it's early!) there's not a problem.
but let say you no my ost name which you do, lets say you no my email address which you do, and lets say you no my bosses email address you could use telnet to spoof an email from me to him, so surely that is a type of relay,, can u telnet to mailtrutecsolutions.com and send me an email nick@trutecsolutions.com from xyx@xyx.com and see if i get the email
Posts: 6812
Joined: 9.Jun.2004
From: Philadelphia PA
Status: offline
Right. So that's nothing to do with relay. You were just using the wrong word. IIRC you telnet and do a message 'from' your boss and 'to' joe in the mail room telling him that he's fired your joe will get the message but it will be from the SMTP address rather than the NAME of the boss. Now, there is a tweak you can do that refuses to accept messages that have a sender of your domain. Essentially you can block messages FROM your selves.
I can't put my hands on the thing you want right now but I'll see if I can dig it out later.
Posts: 6812
Joined: 9.Jun.2004
From: Philadelphia PA
Status: offline
Because that's the way SMTP works. If you want to restrict it you are free to do so but Exchange obeys the RFCs and the behaviour is by design. You'd be the first to jump all over Microsoft if they did (yet another) thing that didn't conform out of the box to the 'rules'.
Posts: 6812
Joined: 9.Jun.2004
From: Philadelphia PA
Status: offline
Depends. Depends on what your rules are. I don't know what you use. I don't know how you've got it configured (or intend to have). Bottom line. If you want to block your own domain name being in the "mail from" block that's all you have to configure. 99.9999999999999999% of people don't bother as the only people who "send as you" (to you) are also picked up as spam. They are ALSO picked up as spam; not BECAUSE they sent "as you"
well currently i dont have any anti spam in place , so i am either going to setup an edge server or enable anti spam on the hub server, so the bottom line is if a random person in lets says the USA telnets into mail.trutecsolutions.com and uses a vaild mailfrom and/or rcpt to,then the mails will be sumitted for delivery, ie
mail from: abc@abc.com rcpt to:nick@trutecsolutions.com