[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cpx] Preparing for CPX [repost]



On Tue, Dec 07, 2004 at 07:07:53PM +0100, Andy McKell wrote:
> At 09:58 AM 12/7/2004 -0700, you wrote:
> 
> >How can I prepare my existing VPS v2 to run CPX?
> >
> >- Make sure you have domain catchalls in your virtusertable.
> 
> To reduce spam, I am moving my subhosts away from catchalls.
> Why does cpx force us to have them?

Without catchalls you are *increasing* the spam your server receives,
not reducing it.

Notice that the document I posted references a catchall like this:

    @domain.tld     Error:nouser Unknown user

This will *immediately* reject mail that is not destined for a real
user or alias on your server. If you remove the catchall line,
sendmail will start looking for aliases that match and then actual
Unix usernames to try to deliver the mail. This increases the effect
of dictionary attacks on your server and is another reason to use an
effective catchall.

(Perhaps you're thinking "catchall" refers to an entry where all
unresolved mail is accepted. A catchall can also be used to reject
unresolved mail, as demonstrated above).

Is that clear?

Scott
-- 
Scott Wiersdorf
scottw@xxxxxxxxxxxx
======================================================================
This is <cpx@xxxxxxxxxxxxx>      <http://www.groupmail.org/lists/cpx/>
Before posting a question, please search the archives (see above URL).


Home | Main Index | Thread Index
Match: Format: Sort by:
Search: