Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XGS - Mail Security

Hey Sophos experts,

We are about to switch our UTM SG against XGS soon. Currently our reseller is not really advertising the Mail Gateway in XGS and is proposing to get another mail solution. The reason: according to them, the XGS has an open mail relay that ignoes SPF checks for internal domains - they say that someone could access the XGS from external via SMTP, and then send mails from addresses with our domain to the users in our domain, and SPF would ignore this.

Is this true? If so, why would there be no way to block this? According to our partner in other mail systems we can prevent this via policies, but XGS has no such feature.

Thanks for your insight

Tobias



This thread was automatically locked due to age.
Parents
  • "ignoes SPF checks for internal domains" -> completely wrong

    And who cares about the from field? It's the same trash-field like the display name, anybody can change it like he want.
    The important part is the envelope-from and on UTM, XGS (...) the SPF is working and protecting fine.

    By the way, because SFP is "default" and working nearly perfect, the most SPAMER / SCAMER even don't try it anymore:


  • By the way, Central Email can protect against Impersonation of the from of Emails.

    So to speak: The old "Printer@domain" Spoofing attacks with attachments like PDFs are protected in CEMA. 

    __________________________________________________________________________________________________________________

Reply
  • By the way, Central Email can protect against Impersonation of the from of Emails.

    So to speak: The old "Printer@domain" Spoofing attacks with attachments like PDFs are protected in CEMA. 

    __________________________________________________________________________________________________________________

Children
No Data