Restricting open relay
search cancel

Restricting open relay

book

Article ID: 421058

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

The article describes on how to restrict open relay

Environment

Email security cloud

Resolution

For historical reasons, many SMTP mail servers accept email for domains other than their own and forward it on to the intended recipient. Third-party relay, also known as open relay 

Additional Information

1. For historical reasons, many SMTP mail servers accept email for domains other than their own and forward it on to the intended recipient. Third-party relay, also known as open relay or insecure relay, is when a mail server routes email for anybody in the world. An open relay is any computer that accepts email for any domain and forwards it regardless of who the sender is or what IP address the email is sent from.

2. Spammers hunt for and abuse these servers to try and cover their tracks. When spammers locate such a computer they can use it as a free distribution service for their junk email. This process often leads to the customer's IP address or domain being blacklisted. There is even a risk that the Email Services infrastructure can be blacklisted, considering the sheer volume of mail that is processed.

3. You must ensure that your SMTP server does not allow open relay. If it does allow open relay, your server can be used as a spam gateway. Most current SMTP servers and firewalls allow the restriction of SMTP relay in the following ways:

■ By IP Address- so that you only accept mail from the Email Services IP address ranges

■ By domain- so that you reject mail that is destined for domains other than your own