Home page logo

basics logo Security Basics mailing list archives

Mail Servers blocking BAD Helo
From: brandon () xcodes net
Date: Thu, 30 Dec 2004 14:55:08 +0800

Hi People,

Not quite sure if this is OT but would require opinions to assist me in
making decision of whether to block "BAD HELO" at SMTP level.  Below is
a brief desciption of the situation:
My company's mail server are reciving alot of spams with non-DQDN HELO
greetings during the smtp conversation.  We are using 2 front-end MX
servers whcih does smtp routes to the relevant POP servers.  We have
actually tried to implement blocking of all helo greetings that are not
in FQDN format on one of the servers and the result seems to be good. 
However, the only problem that we faced is there other other ISP ain't
using FQDN in their HELO greetings.

We do have a couple of clients who are complaining that they are unable
to receive mails from certain ISPs, which from our checks in the SMTP
logs, the servers are using "MySMTP1" sort of HELO greetings.  

Now my management are asking me on this issue if we should fully
implement such feature across the other MX servers or should we
withdraw such feature fully from the MX servers.  From my readings on
the SMTP RFCs, they have indicated that SMTP servers must configure its
hostname to FQDN which will be used in HELO Greetings(if im not
wrong).  Im also wondering if there are any other ISP using such
implementation(Blocking BAD HELO greetings) on their SMTP Servers, any

Would welcome all opinions on this issue.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]