Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Registered User
    Join Date
    Nov 2003
    Location
    Floripa - Brazil
    Posts
    69

    Default Sending e-mail without authentication after logged

    Hello,

    I found a situation on our environment that is really unpleasant for us and our customers.

    Imagine this hypothetical situation:

    my hosting company domain is: myhostingcompany.com a
    and the customer domain is: customerdomain.com

    The customer create his e-mail account on outlook that is customer@customerdomain.com. He did a good authentication to send e-mails. From now his ip is allowed to send e-mail from our server for 30 minutes.

    Now this customer creates an account on outlook express without password, the account name he create is

    Iwill_play_with_my_host@myhostingcompany.com

    And then... the e-mail goes to any place he want.

    -------------------------------------------------
    I know this a hypothetical situation, but letīs face. Things like that can happen.

    What I want to know is, if Iwill_play_with_my_host@myhostingcompany.com doesnīt exist, is there anyway to prevent other users already autenticated send e-mails from other domains?

    I know disabling tailwatchd will force authentication all the time but, other than that, is there any other solution?

    I talked with cpanel's support about that and it was recommend me to use the "/etc/mailhelo" option, but I didnīt understand very well how itīs work

    Can anyone help?
    thank you

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by deieno View Post
    Hello,

    I found a situation on our environment that is really unpleasant for us and our customers.

    Imagine this hypothetical situation:

    my hosting company domain is: myhostingcompany.com a
    and the customer domain is: customerdomain.com

    The customer create his e-mail account on outlook that is customer@customerdomain.com. He did a good authentication to send e-mails. From now his ip is allowed to send e-mail from our server for 30 minutes.

    Now this customer creates an account on outlook express without password, the account name he create is

    Iwill_play_with_my_host@myhostingcompany.com

    And then... the e-mail goes to any place he want.

    -------------------------------------------------
    I know this a hypothetical situation, but letīs face. Things like that can happen.

    What I want to know is, if Iwill_play_with_my_host@myhostingcompany.com doesnīt exist, is there anyway to prevent other users already autenticated send e-mails from other domains?

    I know disabling tailwatchd will force authentication all the time but, other than that, is there any other solution?

    I talked with cpanel's support about that and it was recommend me to use the "/etc/mailhelo" option, but I didnīt understand very well how itīs work

    Can anyone help?
    thank you
    No other solutions are natively supported at this time.

Similar Threads & Tags
Similar threads

  1. Sending mail via authentication stopped working overnight [case 50280]
    By jerrybell in forum cPanel and WHM Discussions
    Replies: 16
    Last Post: 06-24-2011, 11:56 AM
  2. how to force sending email always use smtp authentication
    By wp11b in forum E-mail Discussions
    Replies: 3
    Last Post: 05-20-2009, 09:49 AM
  3. Sending mail without authentication
    By sh4ka in forum E-mail Discussions
    Replies: 2
    Last Post: 10-17-2007, 03:13 PM
  4. Problem sending with mutt - 550 Authentication error
    By jols in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 12-11-2006, 01:02 AM
  5. sending mails without authentication..!
    By wimp in forum cPanel and WHM Discussions
    Replies: 61
    Last Post: 07-07-2005, 08:36 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube