Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Blocking SMTP logins from particular countries

Discussion in 'E-mail Discussions' started by Silent Ninja, Mar 7, 2018.

  1. Silent Ninja

    Silent Ninja Well-Known Member

    Apr 18, 2006
    Likes Received:
    Trophy Points:
    Buenos Aires, Argentina
    I've noticed that every time an e-mail's password gets compromised, multiple servers from all around the world connect to it and start spamming, but it's almost never from the same countries were we offer services to (ie. bots connect from Russia, China, Ukraine, some country in Africa or Middle East).

    By disallowing these countries to login we would be adding a new layer of security since bots have already learned how to bypass LFD restrictions.

    I don't want to deny access via HTTP to the service (for now) and blocking entire countries using iptables is not very efficient (although I haven't tried it since IPSET was created).

    As far as I know cpHulk only affects cPanel services (which would help with the webmail except on the proxy subdomains) but it does not affect dovecot, so they're still able to spam using SMTP.

    Is there a way to add geo-detection and restrictions to dovecot logins?
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Apr 11, 2011
    Likes Received:
    Trophy Points:
    cPanel Access Level:
    Root Administrator

    We added new functionality to cPHulk in cPanel & WHM version 70 that appears to match what you are looking for:

    Email authentication is handled by dovecot, and dovecot is in-fact covered as one of the services protected by cPHulk.

    Thank you.

Share This Page