"IP May Be Forged" - Sendmail Warning

Posted by Mikey B on Server Fault See other posts from Server Fault or by Mikey B
Published on 2010-06-07T21:17:04Z Indexed on 2010/06/07 21:23 UTC
Read the original article Hit count: 259

Filed under:
|
|
|
|

CentOS 5.x | SendMail 8

Can I get clarification on what exactly the warning "IP may be forged" means and what conditions cause it? I recently configured SendMail to relay email from my exchange server and it's showing that warning in the logs. The messages get delivered fine but I don't like the warnings.

I originally thought that there was an inconsistency between the servername used in the EHLO statement from Exchange and the respective PTR record for the source IP for Exchange. But upon examining a packet capture, I see exchange using "EHLO domain.com" and that the source IP has a PTR of "domain.com". Maybe sendmail doesn't like that the greeting only has the domain?

-M

© Server Fault or respective owner

Related posts about dns

Related posts about email