"IP May Be Forged" - Sendmail Warning
Posted
by Mikey B
on Server Fault
See other posts from Server Fault
or by Mikey B
Published on 2010-06-07T21:17:04Z
Indexed on
2010/06/07
21:23 UTC
Read the original article
Hit count: 279
CentOS 5.x | SendMail 8
Can I get clarification on what exactly the warning "IP may be forged" means and what conditions cause it? I recently configured SendMail to relay email from my exchange server and it's showing that warning in the logs. The messages get delivered fine but I don't like the warnings.
I originally thought that there was an inconsistency between the servername used in the EHLO statement from Exchange and the respective PTR record for the source IP for Exchange. But upon examining a packet capture, I see exchange using "EHLO domain.com" and that the source IP has a PTR of "domain.com". Maybe sendmail doesn't like that the greeting only has the domain?
-M
© Server Fault or respective owner