In firewall mode, mail is only forwarded if user exist on xeams Tommy R
    In firewall mode, mail is only forwarded if user exist on xeams Tommy R
        In firewall mode, mail is only forwarded if user exist on xeams Synametrics Support
            In firewall mode, mail is only forwarded if user exist on xeams Tommy R

From: Tommy R
Date: 4/12/20 2:47 AM
Topic: In firewall mode, mail is only forwarded if user exist on xeams
Type: General Discussions
Post a follow up

I'm strugling here. As of my post a few days ago, i now have shut down SMTP Proxy. Configured SMTP with domain forwarding to port 2525 on the actual server. I also want some users to get spam-email reports once every day. Midnight is standard. For this to work, i have to add the users email address in xeams. Well enough. 

Now, xeams ONLY delivers mail to my actual server if the recipient matches with account on xeams... else, sender gets the message that user doesn't exist.

How do i prevent this? I have lots of users on the actual server and domain admins can create, edit and delete accounts as they wish. Xeams must deliver mails even if the user has no account in Xeams...

Top

From: Tommy R
Date: 4/12/20 4:17 AM
Topic: In firewall mode, mail is only forwarded if user exist on xeams
Type: General Discussions
Post a follow up

Eventually, I found out... the setting under Relay to "Reject emails for invalid users". I didn't see that this is used even if the domain is forwarded...Problem solved!

Top

From: Synametrics Support
Date: 4/12/20 7:55 AM
Topic: In firewall mode, mail is only forwarded if user exist on xeams
Type: General Discussions
Post a follow up

Tommy,

I have a feeling your configuration is not complete yet. Try running Tools / Diagnostic Check - Inbound. It is very likely the Invalid Recipient Check will fail. The correct way to configure Xeams in your scenario is:

  • Check "Reject email for invalid users". Unchecking this option will make your vulnerable to Reverse NDR attacks. Currently, your Xeams is most likely accepting emails for addresses like mickey.mouse@yourdomain.com, which is obviously not correct.
  • Instead, enable either DRV or AD/LDAP Lookup, which will ensure Xeams only accepts emails if it is a valid address in your downstream server.
Top

From: Tommy R
Date: 4/12/20 9:27 AM
Topic: In firewall mode, mail is only forwarded if user exist on xeams
Type: General Discussions
Post a follow up

Thank you! You are absolute right. There is a reason I suppose, but when i add a domain to forward to downstream server, why doesn't this happend by default or by option at the same place of setting? Now i have to add all my domains in two places.

Couple og other questions then: (hope i'm allmost done setting this ut now, so i won't have to bother you any more)

Is it possible to send quarantine-reports to domains so I don't have to make all the local accounts in xeams?

Top