Quantcast
Channel: iRedMail
Viewing all articles
Browse latest Browse all 14127

SMTP Allowed via telnet 25?

$
0
0

==== Required information ====
- iRedMail version: 0.8.4
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Linux/BSD distribution name and version: Debian 7
- Related log if you're reporting an issue:
====

I had a user of my mail server today inform me that he was able to telnet to port 25 externally to my mail server and send mail from any address to any of my users.  I was able to test this as well and he was correct. 

There was no prompt for authentication when connecting to postfix on 25 via telnet and as long as I was sending to anyone on the mail server it went through.  Is this correct? It does not seem secure to me as anyone can telnet and spam my users.

I realize it is somewhat secure as it will not allow me to telnet in and send to external hosts so it is not an open relay. 

Can someone tell me if this right or I need to lock it down more?

Thanks!


Viewing all articles
Browse latest Browse all 14127

Trending Articles