IBM AH0QXML User Guide - Page 75

Defending against active attacks, that Local Domain Recipients exist in the Domino Directory

Page 75 highlights

spammer marks the e-mail address as a valid target for spam. This type of attack simulates the transmission of an e-mail with a large list of recipients. This harvesting technique is especially effective for spammers when you configure Domino 6 to validate recipient addresses during transport by enabling the "Verify that Local Domain Recipients exist in the Domino Directory" setting in Inbound Intended Recipient Controls. For this reason, we do not recommend enabling this setting since it can assist spammers in targeting your domain for spam. However, if you must use the setting, you can reduce the effectiveness of this type of address harvesting by using the Domino 6 ini setting SMTPMaxForRecipients. The SMTPMaxForRecipients setting will not stop harvesting, but may slow it down or reduce it. The intention of the SMTPMaxForRecipients ini setting is to prevent messages with large lists of recipients, but it has the useful side effect of making it a little more difficult for spammers to harvest addresses. 4.5.4 Defending against active attacks We recommend that you configure Domino to hold undeliverable mail. This can be done from the Configuration Settings document, under Router/SMTP → Advanced → Controls. Change the value of the field "Hold undeliverable mail" to Enabled. The field is located in the Additional Controls (Delivery and Transfer) section shown in Figure 4-23. Figure 4-23 Undeliverable mail setting Chapter 4. Domino 6 Server anti-spam features 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120

Chapter 4. Domino 6 Server anti-spam features
63
spammer marks the e-mail address as a valid target for spam. This type of attack
simulates the transmission of an e-mail with a large list of recipients. This
harvesting technique is especially effective for spammers when you configure
Domino 6 to validate recipient addresses during transport by enabling the
Verify
that Local Domain Recipients exist in the Domino Directory
setting in Inbound
Intended Recipient Controls. For this reason, we
do not
recommend enabling this
setting since it can assist spammers in targeting your domain for spam. However,
if you must use the setting, you can reduce the effectiveness of this type of
address harvesting by using the Domino 6 ini setting
SMTPMaxForRecipients
. The
SMTPMaxForRecipients setting will not stop harvesting, but may slow it down or
reduce it. The intention of the SMTPMaxForRecipients ini setting is to prevent
messages with large lists of recipients, but it has the useful side effect of making
it a little more difficult for spammers to harvest addresses.
4.5.4
Defending against active attacks
We recommend that you configure Domino to hold undeliverable mail. This can
be done from the Configuration Settings document, under Router/SMTP
Advanced
Controls. Change the value of the field
Hold undeliverable mail
to
Enabled. The field is located in the Additional Controls (Delivery and Transfer)
section shown in Figure 4-23.
Figure 4-23
Undeliverable mail setting