Defense against SMTP Smuggling?
-
Does MDaemon have, or are you working to provide, defenses against SMTP Smuggling, as referred to in this blog post by KnowBe4 which references info published by Timo Longin of SEC Consult?
https://blog.knowbe4.com/smtp-smuggling-email-security-impersonation
https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/
Thanks,
Dave
0 likes 0 likes
3
Posts138
Views
-
MDaemon 23.5.2, which is being released today, includes 2 changes to prevent SMTP smuggling.
- To prevent inbound SMTP smuggling, MDaemon now requires message data to end with <CRLF>.<CRLF>. Previously, it would allow <LF>.<LF>. To disable this, edit \MDaemon\App\MDaemon.ini and set [Special] SMTPRequireCRLFdotCRLF=No.
- To prevent outbound SMTP smuggling, MDaemon by default removes bare <CR> characters from messages. To disable this, edit \MDaemon\App\MDaemon.ini and set [Special] SMTPAllowBareCR=Yes.
--
Arron Caruth0 likes 0 likes
-
Terrific! Thanks!
Dave
0 likes 0 likes
Please login to reply to this topic!
Search
Latest topics
Latest posts
Forum statistics
- Page views (24h):
- 1,640
- Page views (30d):
- 11,007
- Topics:
- 601
- Posts:
- 3,741
- Members:
- 747
People who liked this
Invalid Password


