It seems that anyone can send mail through the SMTP server via Outlook, even with a non-existing mail ID.
For instance, I create in Outlook a new mail account [email protected], where mydomain.com obviously is a domain hosted with Jodo. The address is not created in Hsphere, so it actualy do not exists. If I perform a send and receive in the Outlook, I got the usual error message that it couldn’t contact the mail server… But if I wan to send a message via that account, it goes through without problem, which means that anybody could use the smtp server for spam or whatever else faking an address of a normal domain.
When I discovered that, I have contacted chat support and I was advised to open a ticket, which I did, the ticket HIK-66499-189, which was closed as solved, but the problem still persists, as I was replying to Maheep’s mail via an email sent from afake ID. I strongly believe that they didn’t understand what I have told them.
I’ll verify what you’ve said to be true zaboss. I just tested it out with my account and I was able to send mail from a non-existent address. They would have to turn on outgoing authentication to solve this, but for some reasons a lot of hosts don’t do that.
So it’s not only me. This may poses a huge problem as anybody could abuse this and legit domain may end up on spam lists without knowing what hit them.
so by checking email from a valid account beforehand, we can then send emails through invalid accounts afterwards? Is this domain specific? For instance, since my IP is a valid address that was authenticated recently, could I then send mail with and invalid address through someone elses domain that is also hosted here at jodo? Just curious.
Yes, authenticated users on the mailserver can do that.
If you create a website where you want to send greeting cards from one person to the other, this obviously is necessary.
The limited relay feature is given by all hosts in some form, to allow for this sort of flexibility. Obviously if we get complaints against your usage, we’ll disable your rights to it.
As initiator of the thread, I would kindly ask one of the moderators to change the title of the thread to something like “Potential problem on SMTP Servers” as it might lead people to wrong conclusions.
For me everything is clear now and I am satisfied with the explanations given by both Yash and Stephen. It was my mistake to jump to conclusions.
I would also suggest if we every do have a real security problem or other issue that we put it in the Customer only section so the general public doesn’t see it and try to utilize a potention risk. Not that this one is, but just in case.