Setting inbound relay controls
To block relays to a specific domain or from a specific host, set restrictions in the inbound relay controls on the
tab of the Configuration Settings document.About this task
Use the inbound relay controls to define:
- The destination domains to which you allow and deny relays
- The originating hosts from which you allow and deny relays
In determining whether to allow a relay, Domino® checks the original sender, not just the last hop domain. This prevents people from routing from a denied source through an accepted one to your domain.
To set inbound relay controls
Procedure
Results
When there is a conflict between the allowed and denied relay destinations, and the allowed/denied relay sources, the entry in the Allow field takes precedence. Thus, a host that you explicitly allow to relay can always relay to any destination, including denied destinations. Similarly, if you allow relays to a given domain, all hosts can relay to that destination, including hosts to which you have explicitly denied relaying. Denied hosts cannot relay to domains other than those that you specifically list in the Allow field. The following table provides several examples of how Domino resolves conflicts between entries in the Allow and Deny fields of the Inbound relay controls.
Field | Entry | Results of Setting |
---|---|---|
Allow messages to be sent only to the following external internet domains | xyz.com | All hosts can relay to xyz.com, including smtp.efg.com, which is a denied host. |
Deny messages from the following internet hosts to be sent to external internet domains: (* means all) | smtp.efg.com | smtp.efg.com cannot relay to any destination, except xyz.com, which is explicitly allowed. |
Field | Entry | Results of Setting |
---|---|---|
Deny messages to be sent to the following external internet domains: (* means all) | qrs.com | No relays are allowed to qrs.com, except relays originating from relay.abc.com, which is specifically allowed. |
Allow messages only from the following internet hosts to be sent to external internet domains: | relay.abc.com | Relay.abc.com can relay to any destination, including qrs.com, which is a denied destination. |
If the same entry is placed in the list of allowed and denied destinations, or the list of allowed and denied sources, Domino honors the entry in the Deny list. For example, Domino rejects relays to xyz.com if you configure the relay controls as follows:
Field |
Entry |
---|---|
Allow messages to be sent only to the following external internet domains: |
xyz.com, abc.com, qrs.com |
Deny messages to be sent to the following external internet domains: (* means all) |
xyz.com |