From: Willi Burmeister
Date: 2008-04-16 07:12:11 -0400
Subject: Re: milter-sender greylists unknown local users

Hi Anthony,

> milter-sender doesn't actually check local accounts, that is left to 
> sendmail to determine. The milter just records the tuple.

> > How about first checking for existing users and only do callback if
> > this didn't fail?
> This is not always possible especially when the milter is run on a mail 
> gateway that is not the mail store. Call-ahead would normally take care 
> of that,

milter-sender can do a call-ahead, so maybe it is possible to (mis)use 
this feature to check for local recipents?

> however call-backs aim to verify the sender regardless of the 
> recipient. The milter performs the call-back at MAIL FROM: time, not at 
> RCPT TO: time.

Thanks to make this clear.

We have lots of probes for unknown users. So I think it would be a good
idea to check the existence of a user and to block the sender if he
tries to deliver to too much wrong addresses. Maybe milter-error is
a starting point.

Thanks for your help.


