Thanks
Which report is this then?
"fischste" <fisc...@discussions.microsoft.com> wrote in message
news:3686272A-AAAD-4824...@microsoft.com...
"fischste" <fisc...@discussions.microsoft.com> wrote in message
news:0D71D544-B04A-41B2...@microsoft.com...
You can't insist that the HELO matches the sender email domain as it often
doesn't, the SMTP RFCs aren't very strict about what a HELO can and can't
be.
What you could do is use some 3rd party software that can filter on HELO and
insist that it's RFC compliant, plus a lot of other criteria, however banks
often get very paranoid that they might be rejecting legitimate email.
As with most filtering for spam etc you can never achieve a 100% block rate
with a 0% false positive rate, it's always a balance made depending on your
circumstances. Banks usually go for 0% false positives and won't even
publish SPF/Sender ID records (which is a shame as they're the ones who
suffer from most phishing attacks.
You can probably head the auditors off if you point out that although you
can impliment very strict SMTP acceptance rules you will inevitably end up
rejecting some legitimate email ;-)
Peter Lawton
"fischste" <fisc...@discussions.microsoft.com> wrote in message
news:0D71D544-B04A-41B2...@microsoft.com...
Good question, I'm wondering if the message from the report is really
saying that it's not validating HELO lookups rather than it's accepting
any domain name.
James Chong
sorry, but i couldnt resist.
the " solution " reminded me a joke :
there was this guy on a hot air ballon, lost over a city. when he was over a
roof top, he shouted to the lady on it : " PLEASE, TELL ME WHERE I AM ?? "
she said, well, you are inside the basket of a hot air ballon, hovering at
about 150 ft over the whatever corp building, roughly at 42º 45' N and 12º
76' W.
he says, thank yooouuu very much, i bet you are a technician. you gave me a
totally technically correct answer but made me waste my time and i am no
better that before, actually, i'm even worse as i can't figure out how to
land.
hmmmmm, she says, i bet you are a manager, i gave a technically correct
answer. all the data was accurate. you didn't understand any of it. your
situation is no better that before, and somehow, it already my fault !!!!!
insist with them. if they audit, they must also give corrective feedback.
what should be the proper reply and action to fake_domain.
cheers
Pedro Leite from Portugal.
-------------------------------------------------------------
"fischste" <fisc...@discussions.microsoft.com> escreveu na mensagem
news:AAC8CBB7-0B7F-4FDD...@microsoft.com...
Peter Lawton
"fischste" <fisc...@discussions.microsoft.com> wrote in message
news:AAC8CBB7-0B7F-4FDD...@microsoft.com...