Web Hosting Forum | Lunarpages
News: July 14, 2008 - New Contest! - Submit Your WordPress Theme Designs, Win BIG!
June 30, 2008 - Submit Your Site for the July 08 Site of the Month Award!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
July 25, 2008, 11:34:08 PM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: Email questions  (Read 899 times)
clearblue
Trekkie
**
Offline Offline

Posts: 11


« on: February 26, 2008, 08:50:54 AM »

I have been tinkering with SPF records and the like in an attempt to slow down the spoofing of my domains.  So far, my results have proven futile.  I have two specific questions.

1. Some time ago I came across a post with a configuration change that was to have helped in this matter.  If I recall corrctly, Plesk's default configuration invited others to spoof away.  Anyone have any idea of what I am talking about?

2. I have been studying email headers - both incoming and outgoing - and have been surprised to see other domains on my server showing up in my headers.  For example, in an email sent to MYDOMAIN_A.COM I see
Code:
RECEIVED: from senders.ip by MYDOMAIN_B.COM
I then see the SPF record info from the second domain.

Why is that?  Other than being on the same server, these domains have no relationship at all.  (In fact, they belong to separate clients).  This seems to happen randomly, with all of the domains.  That is, there is no consistency in which domain "b" will show up in the header.

Any thoughts?  Other suggestions for handling spoofing?

Thanks,
Robert Reed
Logged
perestrelka
Administrator
Jedi
*****
Offline Offline

Posts: 980



« Reply #1 on: February 26, 2008, 11:30:17 PM »

Hi Robert,

In reply on your questions:

1) AFAIK, default Plesk configuration is secure enough. It is possible there was small glitch in some Plesk release at some point, but it should be fixed if you have your Plesk version updated with the latest patches. As a side note, there is always something can be added to combat against domain spoofing more effectively.

2) It is better to have real headers and check server settings in reply on this question. I would recommend to open a ticket with that info in order we could investigate this and assist you. Feel free to send me a private message with the ticket number.

I hope this helps. Please respond, if you have any further questions.
Logged

Kind Regards,
Vlad Artamonov
clearblue
Trekkie
**
Offline Offline

Posts: 11


« Reply #2 on: February 27, 2008, 06:35:17 AM »

I am out of my office at the moment, but when I return I will open a ticket and send you the information.

I would also be curious to know some of those things "that can be added to combat against domain spoofing more effectively".

Thanks for your response and your assistance.
Logged
perestrelka
Administrator
Jedi
*****
Offline Offline

Posts: 980



« Reply #3 on: February 27, 2008, 08:51:26 PM »

Quote
I would also be curious to know some of those things "that can be added to combat against domain spoofing more effectively".

What comes in my mind is:

1) SPF (you already did it)
2) DomainKeys
3) Ensure that you don't have a catchall address setup on your domains. This way other mail servers that support sender's address verification will be able to check if email goes from existing sender on your server or not.

You could try to google for more tricks as well.
Logged

Kind Regards,
Vlad Artamonov
clearblue
Trekkie
**
Offline Offline

Posts: 11


« Reply #4 on: March 03, 2008, 07:30:36 AM »

Thanks,

I will continue to investigate.

In the meantime, I opened ticket #718600

Robert Reed
Logged
perestrelka
Administrator
Jedi
*****
Offline Offline

Posts: 980



« Reply #5 on: March 05, 2008, 01:11:50 AM »

Hi Robert,

I see that a tech replied to your ticket and I believe the adjustment he did should resolve the issue or at least get closer to the solution. Please update the ticket and PM me if mail headers still mention different domains for mails accepted by your VPS.
« Last Edit: March 05, 2008, 01:18:00 AM by perestrelka » Logged

Kind Regards,
Vlad Artamonov
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.3 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM