Spoofed addresses and Dead Mail

I have verified (too many times to count) that my server’s configuration document is set so both Inbound and Outbound DSN extensions are disabled. Normally, this would lead me to believe that if an inbound SMTP message has requested a delivery status notification, my server would not send one and if an outbound SMTP message has requested a dsn, my server would not allow the request.

Unfortunately, we are receiving NUMEROUS messages using spoofed addresses, a delivery status notification may have been requested, and my server is attempting to deliver one to the address in my domain. Since this address does not exist in my directory, I end up with a Dead message.

Can someone tell me why this is happening or if my thinking is flawed?

Thanks!

Subject: Spoofed addresses and Dead Mail

Did this just start or has it been going on for a while? Have you made any changes to the config doc? You can also set the configuration so that the server only accepts mail addressed to users whose names are listed in the directory. What about virus protection? I believe that one of the things that the Mydoom virus is doing is spoofing reply addresses.

Subject: RE: Spoofed addresses and Dead Mail

Oops, ignore my ability to try enabling the verification that local domains exist in the domino directory. I did find info that the Field Help for that field is incorrect and it was nice enough to point out that enabling this feature will not allow the use of a smarthost. Unfortunately, we need the smarthost, so, there you go, there you have it, there you are.

Subject: Spoofed addresses and Dead Mail - WORM

We are having the same since Monday afternoon.In our case it is the recent WORM attack.

Our antivrus software is removing the virus’s but the spoofed addresses and Dead mail is continuing.

Subject: RE: Spoofed addresses and Dead Mail - WORM

This actually started on a very small scale within the past 5 - 7 days. Now that the Worm has embarked on its mission it has gotten much worse.

We had not made any changes to the config document before the first few dead messages occurred.

The ‘help’ portion of ‘Verify that local domain recipients exist in the Domino Directory’ concerned me because it refers to performing a reverse DNS lookup, but I am willing to try that to see if it will help.

As for Virus protection, we are ‘quarantining’ messages that contain the most common ‘virus carrying’ attachments. The few extras that get through have all been zapped by our Norton Anti-virus. This has proved to be very successful for us so far.

Thanks for your input, and I’ll give it a go.

Subject: RE: Spoofed addresses and Dead Mail - WORM

I wonder if the help for that field may be an error. Enabling it is only supposed to verify that the recipient exists in the Domino Directory for your domain. I have been using it for about 5 months without any problems. I hope it helps you.