[quoted text, click to view] "Sanford Whiteman" <swhitemanlistens-software@cypressintegrated.com> wrote
in message news:op.tukfpwcj6c17zw@gw02.broadleaf.local...
>> Is it possible to setup the SMTP server to allow inbound connections
>> from any machine for messages to my domain, but only allow outbound
>> messages from computers that successfully authenticate (via Windows
>> username/password)?
>
> Of course!
>
> I have posted quite extensively on related matters in just the past 2
> weeks. Take a look at those messages and post back with follow-up
> questions.
Thanks I'll look for those.
[quoted text, click to view] >> ...it looks like if I enable anonymous access (required for inbound
>> to my domain) then set the Allow computers to relay that
>> successfully authenticate then what I am doing is creating an open
>> relay...
>
> Briefly: no, not at all. If the unknown public is going to be allowed
> to connect to your VS (as it is your published MX), you have to allow
> anonymous connections. Those are not authenticated connections, and it
> doesn't mean you're letting them relay. Indeed, the settings you have
> described are what you want in those areas -- but you may have
> *additional* settings added to those that make your server more open
> (what makes you think it is open, anyway?).
>
> --Sandy
Because there were thousands and thousands of messages in my Queue folder
that I obviously didn't place there. I'm going to look at your other posts
but briefly this is how I had the VS set:
Under Access | Authentication, I had both Anonymous and Windows Integrated
checked.
Under Relay Restrictions, I had Only the list below, and Allow computers
that authenticate regardless of the list below. At least I think that is
what I had; now I'm not sure ;-(.