Hi
I have a mail test environment here where a Sophos XG is configured as MTA (Mail Transfer Agent). In the relay settings, two internal mail servers are configured as "Allow" and "Block" is defined as any. Since the Sophos should be able to receive mails from outside, "Any" is allowed as the upstream host. "Authenticated Relay" is not activated.
This configuration seems to work in principle, but anyone on the WAN side can configure Sophos as a mail server, and then transfer emails to the internal mail servers on behalf of the domains defined in "Domains and routing target / Protected Domains" without authentication. The only condition is that the sender and recipient domains are entered in "Domains and routing target / Protected Domains".
Even activating the "Authenticated Relay" does not change this behaviour.
Is there anything I can do to prevent this?
Hi rexer,
Thank you for reaching out to Sophos Community.
Kindly check/share your configuration with regard to Relay Setting.
Set your Relay Setting to only specific/allowed and not to "Any".
For additional reference, kindly see the following documentation.
Erick Jan
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Hi Rexer,
Apologies for the typo. Setting "Any on the Upstream will result in an open relay. This should not be set to Any
You may check this guide for reference:
Erick Jan
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Hi Erick
This ist not true.
"any" in "Upstream host" is needed to receive Mails from any other Mailserver. If you remove "any" from "Upstream host", you're not able to receive any Mails and you have to enter every Mailserver from any domain that will send you an email as "aalowed". This is practically impossible to implement.
The solution for my problem was to activate SPF-Check and set a correct SPF-Entry.
This was "v=spf1 mx -all" and NOT "v=spf1 mx ~all".
I cannot reproduce this? What do you mean, everybody can use the protected domain?
__________________________________________________________________________________________________________________
yes, as long as both, sender and receiver, are the protected domain.
Tested with Thunderbird and used the Sophos XG userinterface IP as anonymous SMTP-Server.
Yeah because you have to set the SPF Record like you described above. It is not a open relay, instead you are sending an email to your protected domain.
__________________________________________________________________________________________________________________
Email > Policies & Exceptions > "Your" Mail Policie > Spam Protection
Add an SMTP route and scan policy (MTA mode) - Sophos Firewall