38.5. Configuring Relaying

Qmail can be configured to restrict the destination domains to which it will relay email. This is typically done to stop spammers from using your system as an open mail relay, which allows them to hide their true addresses. There is no support in Qmail, however, for allowing clients from certain addresses to relay, so setting up relay domain restrictions will make the server useless for sending outgoing email. One solution to this problem is to run two SMTP servers—one for incoming messages that only relays mail for local domains, and another for outgoing email that uses TCP-wrapper or xinetd restrictions to limit access to trusted clients.

The solution recommended by the Qmail website is to use the tcpserver daemon to run the Qmail SMTP program, and have it set the RELAYCLIENT environment variable for certain clients. This tells the latter program to allow relaying no matter what is in the relay domains list, which achieves the desired objective of giving trusted clients full relay privileges. It is complex to set up, however, and does not work with inetd or xinetd. At the time of writing of this book, Webmin does not support the configuration of this kind of relaying access control.

By default, Qmail will allow relaying to any domain. The steps to follow to change this are:

1.
On the module's main page, click on the Accepted Domains icon. A page listing domain and hostnames to which relaying is allowed will be displayed.

2.
Select the Domains listed below radio button.

3.
Enter domains to which relaying should be allowed into the first text box on the page. All local domains (discussed in Section 38.3 “Editing Local Domains”) must be included as well, or mail to them will bounce.

4.
You can also enter less frequently used relay domains into the second text box. The only difference between the two is that email to domains in the first box will be processed faster.

5.
Click the Save button to make the relaying restrictions active.

To turn off relay domain limitations, select the Any domain checkbox on the Accepted Domains page and hit Save. Any domains that you have entered will be lost.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
52.14.62.197