RE: connection filtering on HELO/EHLO

  • From: "Michael B. Smith" <michael@xxxxxxxxxx>
  • To: "[ExchangeList]" <exchangelist@xxxxxxxxxxxxx>
  • Date: Fri, 17 Dec 2004 07:28:13 -0500

Sure, but you'll have to write a protocol event sink. And be careful -
this might be more dangerous to do than you think.

Not for the faint of heart. 

There are some examples in the Exchange 2003 SDK and on CDOLive and on
Siegfried Weber's site. 

-----Original Message-----
From: Dan HINCKLEY [mailto:dah@xxxxxxxxxxx] 
Sent: Friday, December 17, 2004 3:27 AM
To: [ExchangeList]
Subject: [exchangelist] RE: connection filtering on HELO/EHLO

I'm getting a bunch of spam, some w/viruses, spoofing a domain
(mail.domain.tld) in the HELO. I was trying to see if there is a way
built into ES 2003 to use the FQDN (spoofed) rather than an IP (since
these guys change their IPs) to drop the connection.

At 07:46 12/17/2004, you wrote:
>What kind of filtering?
>John Tolmachoff
>eServices For You
> > -----Original Message-----
> > From: Dan HINCKLEY [mailto:dah@xxxxxxxxxxx]
> > Sent: Thursday, December 16, 2004 12:32 AM
> > To: [ExchangeList]
> > Subject: [exchangelist] connection filtering on HELO/EHLO
> >
> >
> >
> > Have looked in the archives w/o luck. Can anyone point me to a 
> > method of doing filtering in ES 2003 at the HELO/EHLO command?
> >
> >

List Archives:
Exchange Newsletters:
Exchange FAQ:
Other Internet Software Marketing Sites:
World of Windows Networking: Leading
Network Software Directory:
No.1 ISA Server Resource Site: Windows Security
Resource Site: Network Security Library: Windows 2000/NT Fax Solutions:
You are currently subscribed to this Discussion List as:
michael@xxxxxxxxxx To unsubscribe visit
Report abuse to listadmin@xxxxxxxxxxxxxx

Other related posts: