Re: [Exim] exim rejecting mails from sites that were ok.

Page principale
Supprimer ce message
Répondre à ce message
Auteur: Sujit Choudhury
Date:  
À: exim-users
Sujet: Re: [Exim] exim rejecting mails from sites that were ok.
> Sujit Choudhury wrote:
> > > > check_recipient:
> > > >   accept  hosts = :
> > > >   accept  recipients = postmaster@??? : \
> > > >       postmaster@???
> > > >   deny    hosts = ! /mail/exim/files/net_reject_except : \
> > > >           ! * : *

>
> Would you please explain what this particular ACL is supposed to do?
>
> You deny from hosts that are not in net_reject_except and no hosts and
> all hosts? No hosts will be blocked by this ACL because of "!*".
>
> > > Get rid of the above one - it serves no useful purpose. Or please
> > > explain how it is supposed to work. The check below does what you need
> > > if I understand your logic correctly.
> > >
> > > >   deny    hosts = ! /mail/exim/files/net_reject_except : \
> > > >       +include_unknown:partial-lsearch;/mail/exim/files/host_reject : \
> > > >       /mail/exim/files/net_reject

> > >
> > > This part seems ok. Can you show some examples on what net_reject_except,
> > > host_reject and net_reject files contain?
>
> As I said in a mail sent yesterday, this is not ok unless you want to
> reject RCPT commands from hosts that are not whitelisted by
> net_reject_except and whose IP address does't resolve to a hostname (and
> also hosts listed in host_reject and net_reject of course).
>


A bit puzzled here about what to do without offending various ISPs.
If I leave +include_unknown, then it falls apart as so many
machines in the net don't resolve to hostname.

What are the views of people who are using Exim 4.1x with ACL?

Many thanks

Sujit






> --
> Kirill Miazine, Stud. Jur.
> Faculty of Law, University of Oslo
>



----------------------
Sujit Choudhury
University of Westminster
E-Mail: S.Choudhury@???
Tel No: 020 - 7911 5000 Ext 3851

-
This e-mail and its attachments are intended for the above named
only and may be confidential. If they have come to you in error
you must not copy or show them to anyone, nor should you take any
action based on them, other than to notify the error by replying to
the sender.