Jump to content

Recommended Posts

Posted

We use an on-prem Mdaemon Email Server and I've been advised that this would work a lot better in terms of security if we removed the upstream mail relay!

 

So I'm looking at removing the RM SMTP store and forward service from our portfolio.

 

Does anyone know what would be involved in removing this service and getting mail flowing directly to our own mail server?

Posted

Essentially you just need to make sure that your mail-server DNS record is pointing to the public IP of your server, and that the MX record for your e-mail domain is pointing to your mail server.

It is probably currently pointing to an RM server.

 

How you achieve that depends on where your domain is registered and how the registrar allows you to alter DNS settings.

We are with Zen, so can change the DNS settings for all our domains ourselves on a dashboard page. With other registrars, you may need to get them to do it.

 

We use MDaemon, have for years and I really like it. I am curious though, what aspects of the security have you been advised would work better without the relay ?

I would have assumed that the relay would have some security of its own that would deal with some nasties before it ever hit your server ?

Posted

Just get them to update your MX record for your MDaemon's IP address instead of the Store and Forward one, and check you have the ports on the firewall open.

 

Previously SWGfL only allowed port 25 via their relay and not direct.

Posted
Essentially you just need to make sure that your mail-server DNS record is pointing to the public IP of your server, and that the MX record for your e-mail domain is pointing to your mail server.

It is probably currently pointing to an RM server.

 

How you achieve that depends on where your domain is registered and how the registrar allows you to alter DNS settings.

We are with Zen, so can change the DNS settings for all our domains ourselves on a dashboard page. With other registrars, you may need to get them to do it.

 

We use MDaemon, have for years and I really like it. I am curious though, what aspects of the security have you been advised would work better without the relay ?

I would have assumed that the relay would have some security of its own that would deal with some nasties before it ever hit your server ?

 

We've had quite a few issues with mail being rejected.

 

Advice from our support people is "I’d always be recommending MDaemon is the one that holds the MX record as this way it performs all the spam filtering and IP level checks on the original mail server and you don’t see these problems."

 

- - - Updated - - -

 

Just get them to update your MX record for your MDaemon's IP address instead of the Store and Forward one, and check you have the ports on the firewall open.

 

Previously SWGfL only allowed port 25 via their relay and not direct.

 

Thanks.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...