Thank you, I'll go start reading up on that.
Thank you, I'll go start reading up on that.
Or you could go the other way, and block the port completely.
Literally NOTHING should be using unencrypted SMTP over the internet anymore. It's all ports 465 or 587 now. Anything on 25 is bad news. Port 25 is blocked on my network, and no one has complained about it in years. In fact, it's the only port here right now that's blocked outright for outbound.
Five time Microsoft ASP.Net MVP managing a Lenovo RD330 / E5-2420 / 16GB with Untangle 16.5 to protect a 1Gbps fiber link for ~450 residential college students and associated staff and faculty
TCP 25 is still the primary connection point to an email server. If you're hosting one yourself, most traffic is there.
But I agree, authenticated sessions have no place on it. And as much as is possible, TCP 25 even is happening with TLS now.
Rob Sandling, BS:SWE, MCP
NexgenAppliances.com
Phone: 866-794-8879 x201
Email: support@nexgenappliances.com
Already doing both of those suggestions. I have outbound port 25 blocked for all IPs on the network except for the email server.
Rob Sandling, BS:SWE, MCP
NexgenAppliances.com
Phone: 866-794-8879 x201
Email: support@nexgenappliances.com
<meme>It ain't much, but it's honest work.</meme>