SMTP Banner James
    SMTP Banner Synametrics Support
        SMTP Banner James

From: James
Date: 4/8/25 2:02 PM
Topic: SMTP Banner
Type: General Discussions
Post a follow up

Hi Team,

Hope you are all well..!  Been a long time indeed! (Probably because your product is so great!)  :)

 

I've had a few people reach out to me on the following:

1. "Why is the EHLO banner displaying so much information and can an option be provided to have it removed asap as it exposes all the information required to profile and exploit the host for e.g."
"Xeams SMTP server; Version: 9.6 - build: 6361; 01/04/25"

 

2. When enabling forced HTTPS only mode (fair enough mistakenly) trying to get back into the system is a nightmare with the editing of files and using calculators.  Can a simple option be provided please?  Historic solution: forcing HTTPS problem lockout (xeams.com)

 

Once again, well done guys.  Fantastic product.  No complaints at all. 

Cheers,

James

Top

From: Synametrics Support
Date: 4/10/25 1:51 PM
Topic: SMTP Banner
Type: General Discussions
Post a follow up

  1. Check https://www.xeams.com/hidingsig.htm for instructions on how to hide this.
  2. The web interface is the only way to connect and configure Xeams (besides modifying the config files manually). Therefore, if you mistakenly enforce HTTPS with a broken certificate, you will be locked out. I will submit a feature request to ignore this rule if the client is connecting from localhost. That should allow you to fix the problems.

 

Top

From: James
Date: 6/9/25 4:31 AM
Topic: SMTP Banner
Type: General Discussions
Post a follow up

Thank you so much on both points.

Another option would be to simply white list the relay ip range as an acceptable configure range.  Although your suggestion is a little better being localhost and restricting to one computer.

Thanks again - When do you think we will get an update?

Top