LSTOWN-L Archives

LISTSERV List Owners' Forum

LSTOWN-L

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Topic: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
"Eckstine, Nate" <[log in to unmask]>
Thu, 15 Jan 2015 08:05:02 -0800
text/plain (1 lines)
You have to have the confirm. The sending account doesn't need to be a real person but you need to be able to access it to ok the security OK mechanism of the email sent to it by the confirm.



-----Original Message-----

From: LISTSERV List Owners' Forum [mailto:[log in to unmask]] On Behalf Of Andrew Kelly

Sent: Wednesday, January 14, 2015 7:37 AM

To: [log in to unmask]

Subject: Re: Owner and Reply to Messages



Reviewing this thread I still need one point of clarification on this topic:



Background:

I've got a number of distribution lists that are used to send newsletters and items of similar content, sometimes to tens of thousands of subscribers. Yesterday for the first time in several years of use I experienced a successful mis-use if one of the lists. Somebody out "in the wild" successfully sent a mail to one of my major distribution lists by spoofing thier address. They had simply taken the sender address of a recent mail to the list, and sent their mail using that as the From: address. 



Is a Send=Owner really that trivial to bypass? Is my only protection against this type of thing to force a "confirm" as well? I hope not. I want these mailings to be sent by an umbrella account, that doen't really reach a real person. I'd much prefer being able to send with a given address, but have a totally different value delivered in the From:

field with the actual mail.



For example, if I had a list with the following:

[log in to unmask]

Send=Owner



Is there any way to send a mail as [log in to unmask] but have the mail reach recipients as

From: [log in to unmask]



Or am I forced to make all my lists send=owner,confirm?



Andy



############################



To unsubscribe from the LSTOWN-L list:

write to: mailto:[log in to unmask]

or click the following link:

http://peach.ease.lsoft.com/scripts/wa-PEACH.exe?SUBED1=LSTOWN-L&A=1



############################



To unsubscribe from the LSTOWN-L list:

write to: mailto:[log in to unmask]

or click the following link:

http://peach.ease.lsoft.com/scripts/wa-PEACH.exe?SUBED1=LSTOWN-L&A=1


ATOM RSS1 RSS2