Allow POP3 but block sending mail
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS and SMTP > Allow POP3 but block sending mail




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    Allow POP3 but block sending mail  
Jim Carlson


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
02-22-05 10:52 PM

I want our users to send mail through an ISP rather than our server but be
able to collect mail from our server using POP3. How might I configure
SMTP/POP3 to accomplish this?

Jim Carlson







[ Post a follow-up to this message ]



    RE: Allow POP3 but block sending mail  
WingFan


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
02-23-05 11:00 PM

In your e-mail client configuration, simply put your server name/address for
the POP3 server and put your ISP's SMTP server name/address for the STMP
server.  The only caveat is that your ISP may need to be configured to accep
t
relay requests from your users.  Most SMTP servers are configured to restric
t
relay access based on IP ADDRESS, EMAIL DOMAIN, or USER AUTHENTICATION (or a
combination). IP & DOMAIN are the most common methods used.  If your email
domain is not authorized to relay thru their system, then the mail will get
rejected.  If they host/manage your domain for you, then it shouldn't be a
problem.  For the most part POP3 & SMTP are basically unrelated, beyond the
point that they are e-mail protocols.  Often they are both on the same serve
r
and use mutual authenticaton information, but they by no means have to or
neet to be.

Eric


"Jim Carlson" wrote:

> I want our users to send mail through an ISP rather than our server but be
> able to collect mail from our server using POP3. How might I configure
> SMTP/POP3 to accomplish this?
>
> Jim Carlson
>
>
>





[ Post a follow-up to this message ]



    Re: Allow POP3 but block sending mail  
Jim Carlson


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
02-25-05 10:55 PM

Thank you for your reply. But what if a user doesn't change the outgoing
smtp server name? How can I insure their outgoing mail will be rejected by
our server?

Thanks,

Jim Carlson

"WingFan" <WingFan@discussions.microsoft.com> wrote in message
news:64DFD0EF-BDB8-46FD-A40D-2AEED8429B36@microsoft.com...[vbcol=seagreen]
> In your e-mail client configuration, simply put your server name/address
> for
> the POP3 server and put your ISP's SMTP server name/address for the STMP
> server.  The only caveat is that your ISP may need to be configured to
> accept
> relay requests from your users.  Most SMTP servers are configured to
> restrict
> relay access based on IP ADDRESS, EMAIL DOMAIN, or USER AUTHENTICATION (or
> a
> combination). IP & DOMAIN are the most common methods used.  If your email
> domain is not authorized to relay thru their system, then the mail will
> get
> rejected.  If they host/manage your domain for you, then it shouldn't be a
> problem.  For the most part POP3 & SMTP are basically unrelated, beyond
> the
> point that they are e-mail protocols.  Often they are both on the same
> server
> and use mutual authenticaton information, but they by no means have to or
> neet to be.
>
> Eric
>
>
> "Jim Carlson" wrote:
> 







[ Post a follow-up to this message ]



    Re: Allow POP3 but block sending mail  
WingFan


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
02-25-05 10:55 PM

Well, I'm not sure how your network is configured, but I'll assume you just
want to restrict your LAN users from using it.  I would just configure
Connection Control on the Virtual Server to restrict your LAN IP subnet, or
at least the portion of it that your users are on.  It can be confiigured to
restrict by individual IP address(es), by IP subnet(s), or by DNS domain
name.  You can find these setting on the Access tab of the SMTP Virtual
Server Properties page.  Just be sure to select the "All except the list
below" option (the list being your users' IP addresses), or you'll restrict
inbound connections that are trying to deliver mail to your server.  Then se
t
the Relay Restrictions to only allow your mail server and any specific
machines that you do want to use it for sending.  The relay restriction isn'
t
so much to prevent your users from sending thru it (if they can't connect,
then they obviously can't relay), but is more to avoid becoming a spam relay
.

Hope that helps.  Let me know if you have questions configuring either of
these.

Eric



"Jim Carlson" wrote:

> Thank you for your reply. But what if a user doesn't change the outgoing
> smtp server name? How can I insure their outgoing mail will be rejected by
> our server?
>
> Thanks,
>
> Jim Carlson
>
> "WingFan" <WingFan@discussions.microsoft.com> wrote in message
> news:64DFD0EF-BDB8-46FD-A40D-2AEED8429B36@microsoft.com... 
>
>
>





[ Post a follow-up to this message ]



    Re: Allow POP3 but block sending mail  
Jeff Cochran


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
02-25-05 10:55 PM

On Fri, 25 Feb 2005 15:17:56 -0500, "Jim Carlson" <jim@erwinroots.net>
wrote:

>Thank you for your reply. But what if a user doesn't change the outgoing
>smtp server name? How can I insure their outgoing mail will be rejected by
>our server?

Only relay for the server itself, forcing a login and authentication.
Then don't give them an account or password.

Jeff


>Jim Carlson
>
>"WingFan" <WingFan@discussions.microsoft.com> wrote in message
>news:64DFD0EF-BDB8-46FD-A40D-2AEED8429B36@microsoft.com... 
>






[ Post a follow-up to this message ]



    Re: Allow POP3 but block sending mail  
WingFan


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
02-25-05 10:55 PM

That would work, too.  I'm just not fond of using login authentication on
SMTP.  It makes it a target for dictionary attacks.  IP restrictions work
well for LAN's w/private IP scheme's since spoofing a private IP address
range from the WAN side won't get very far.


"Jeff Cochran" wrote:

> On Fri, 25 Feb 2005 15:17:56 -0500, "Jim Carlson" <jim@erwinroots.net>
> wrote:
> 
>
> Only relay for the server itself, forcing a login and authentication.
> Then don't give them an account or password.
>
> Jeff
>
> 
>
>





[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 10:53 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register