Disabling VRFY and EXPN SMTP command
search cancel

Disabling VRFY and EXPN SMTP command

book

Article ID: 376177

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

How to disable VRFY and EXPN commands on the SMG scanner?

Environment

SMG 10.7 / 10.8 / 10.9

Cause

Some penetration testing can interpret 252 2.0.0 SMTP response from the SMG as a allowed command by seeing a response.

Resolution

VRFY and EXPN commands are restricted by default.

 

SMG response for VRFY and EXPN command:

VRFY [email protected]

252 2.0.0 VRFY restricted

EXPN [email protected]

252 2.0.0 EXPN restricted