Re: [Exim] email identity usurpation

Top Page
Delete this message
Reply to this message
Author: David Woodhouse
Date:  
To: Tim Jackson
CC: exim-users, S. Ancelot
Subject: Re: [Exim] email identity usurpation
lists@??? said:
> C'mon, be fair to the guy. Clearly he's a bit behind the times and
> only just discovering that e-mail headers can be faked (!).


OK, I suppose if you only want to prevent your own users from faking each
others' addresses, and if they have a workstation each, you could arrange
to accept mail 'from' Fred only from Fred's workstation, etc.

Of course, you'd still have to accept mail 'from' Fred from the outside
world (think about mailing lists, etc), and if they share workstations you
can't do this unless you use SMTP AUTH and make them authenticate
themselves, etc.

To be honest, I don't think "you can't" was particularly unfair.
I've been crueler on many occasions :)

--
dwmw2