Bug#287581: splitting ACLs

Robert Millan rmh at aybabtu.com
Wed Jul 26 13:59:14 UTC 2006


On Wed, Jul 26, 2006 at 03:56:20PM +0200, Marc Haber wrote:
> On Thu, Jul 20, 2006 at 08:48:53AM +0200, Robert Millan wrote:
> > Btw, wrt splitting ACL files, note that #378935 adds a new one
> > (25_exim4-config_check_mail).  I think some of the rules currently in
> > 30_exim4-config_check_rcpt could be moved into this one, with the added
> > advantage that they would be performed earlier, saving time and bandwidth.
> > 
> > Some of them could even be moved to acl_smtp_helo, like local or remote IP-based
> > blacklists.
> 
> Some broken, but widely used MTAs get quite psychotic when you reject
> at HELO or MAIL time. This is the reason why we usually reject at RCPT
> time. This is also consistent with upstream.

Ok.

> Actually, it might be appropriate to move the "helo given?" check to
> the RCPT ACL as well.

Do any of these "broken, but widely used MTAs" skip helo?  So far the only
messages I've seen that skip helo are sent by spamware.

-- 
Robert Millan

My spam trap is honeypot at aybabtu.com.  Note: this address is only intended for
spam harvesters.  Writing to it will get you added to my black list.




More information about the Pkg-exim4-maintainers mailing list