Re: [Exim] tmda question

Top Page
Delete this message
Reply to this message
Author: Nigel Metheringham
Date:  
To: Jason R. Mastaler
CC: exim-users
Subject: Re: [Exim] tmda question
On Wed, 2001-11-07 at 00:37, Jason R. Mastaler wrote:
> Right. To clarify, when I send a message to this list for example,
> TMDA "tags" the message by changing the address in my "From:" header
> to <jason-list-exim-users@???>, and also sets the envelope
> sender address to the same using `sendmail -f'.
>
> If the user cannot use `-f', only the From: header address can be
> modified. This isn't the end of the world, but ideally the envelope
> sender should match so that bounces come back to the right place.

[...]
> Anyway, I personally don't feel the ability to set the envelope sender
> address is a security concern as one can always trace the message back
> to the true originator through the mail headers, logs, etc. Sendmail,
> qmail and Postfix have no such restrictions on the use of the `-f'
> option, so my I'm not alone in this belief.


Maybe a more interesting method is allow mangling of the sender address
*as* long as the sender address maps back (when run through the address
verify code) to the same user as the invoker.

    Nigel.