[77070] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: fixing insecure email infrastructure (was: Re: [eweek article]

daemon@ATHENA.MIT.EDU (Adi Linden)
Wed Jan 12 13:42:18 2005

Date: Wed, 12 Jan 2005 12:41:44 -0600
From: Adi Linden <adil@adis.on.ca>
To: Steven Champeon <schampeo@hesketh.com>
Cc: nanog@merit.edu
In-Reply-To: <20050112155943.GC1048@hesketh.com>
Errors-To: owner-nanog-outgoing@merit.edu


> 0) for the love of God, Montresor, just block port 25 outbound already.

What is wrong with dedicating port 25 to server to server communication
with some means of authentication (DNS?) to ensure that it is indeed a
vaild mail server. Mail clients should be using port 587 to submit
messages to their local MTA.

Adi

home help back first fref pref prev next nref lref last post