354
This option checks the so called "Envelope From" and not the
"From" header as displayed to the user. See option "Tag faked
mails from own domain" in menu "Modules > Mail Server >
SMTP settings" on tab "Receiving filters" for a "From" header
check.
Enable this option only if all emails with local sender domains
are always sent to the Internet via local systems (SX-GATE or
internal mailserver).
14.5.3-B
Greylisting
Greylisting tries to defeat virus and SPAM mails already before the actual contents
are transmitted. The system load caused by virus scanner and spam filter will be
reduced, however greylisting is by no means a replacement for both ot them. Greylisting
takes advantage of the fact that often only one attempt is made to deliver a virus or
SPAM mail. If this attempt fails, no retransmission is tried and so the email has been
intercepted before it has even been transmitted.
Greylisting only makes sense if incoming emails are delivered
directly to SX-GATE with SMTP. Particularely if emails are polled
from a POP server, greylisting is useless.
With greylisting enabled, SX-GATE will collect the sender and the recipient address
of an incoming email. It will then terminate the connection with a temporary error.
The actual contents of the email have not been transmitted at that stage. Usually the
instance trying to deliver an incoming email is a mail relay server and not the senders's
mail client program. Hence the sender of an email will not become aware of the delay.
As SX-GATE indicated a temporary problem, the sending relay server will retry delivery
at a later point in time. This is the vital difference in comparison with the behaviour of
many spammers and most viruses.
Three parameters control the greylisting. After a configurable minimum period of time,
SX-GATE will start to accept retransmissions. The retransmission has to occur within a
time limit determined by an other parameter. Meanwhile an email originating from the
same source IP and with the same sender and recipient addresses will be accepted at
once. If there is no retransmission, the corresponding entry will be deleted. Otherwise
it is auto-whitelisted for a configurable period of time. Every use will reset the timeout
of the corresponding whitelist entry.
This strategy will quickly develop a database of "well known communication
relationships". An email using a registered combination of source IP, sender and