kennysarmy Posted November 15, 2018 Posted November 15, 2018 We use an on-prem Mdaemon Email Server and I've been advised that this would work a lot better in terms of security if we removed the upstream mail relay! So I'm looking at removing the RM SMTP store and forward service from our portfolio. Does anyone know what would be involved in removing this service and getting mail flowing directly to our own mail server?
Linfit Posted November 15, 2018 Posted November 15, 2018 Essentially you just need to make sure that your mail-server DNS record is pointing to the public IP of your server, and that the MX record for your e-mail domain is pointing to your mail server. It is probably currently pointing to an RM server. How you achieve that depends on where your domain is registered and how the registrar allows you to alter DNS settings. We are with Zen, so can change the DNS settings for all our domains ourselves on a dashboard page. With other registrars, you may need to get them to do it. We use MDaemon, have for years and I really like it. I am curious though, what aspects of the security have you been advised would work better without the relay ? I would have assumed that the relay would have some security of its own that would deal with some nasties before it ever hit your server ?
Boredguy Posted November 15, 2018 Posted November 15, 2018 Just get them to update your MX record for your MDaemon's IP address instead of the Store and Forward one, and check you have the ports on the firewall open. Previously SWGfL only allowed port 25 via their relay and not direct.
kennysarmy Posted November 15, 2018 Author Posted November 15, 2018 Essentially you just need to make sure that your mail-server DNS record is pointing to the public IP of your server, and that the MX record for your e-mail domain is pointing to your mail server. It is probably currently pointing to an RM server. How you achieve that depends on where your domain is registered and how the registrar allows you to alter DNS settings. We are with Zen, so can change the DNS settings for all our domains ourselves on a dashboard page. With other registrars, you may need to get them to do it. We use MDaemon, have for years and I really like it. I am curious though, what aspects of the security have you been advised would work better without the relay ? I would have assumed that the relay would have some security of its own that would deal with some nasties before it ever hit your server ? We've had quite a few issues with mail being rejected. Advice from our support people is "I’d always be recommending MDaemon is the one that holds the MX record as this way it performs all the spam filtering and IP level checks on the original mail server and you don’t see these problems." - - - Updated - - - Just get them to update your MX record for your MDaemon's IP address instead of the Store and Forward one, and check you have the ports on the firewall open. Previously SWGfL only allowed port 25 via their relay and not direct. Thanks.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now