2.2.25 Ensure unrestricted mail relaying is prevented

Information

The operating system must be configured to prevent unrestricted mail relaying.

If unrestricted mail relaying is permitted, unauthorized senders could use this host as a mail relay for the purpose of sending spam or other unauthorized activity.

Solution

If postfix is installed, modify the /etc/postfix/main.cf file to restrict client connections to the local network with the following command:

Example: vim /etc/postfix/main.cf

Add this line:

# postconf -e 'smtpd_client_restrictions = permit_mynetworks,reject'

See Also

https://workbench.cisecurity.org/benchmarks/8415

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: fbb3342dbc86440b05525c18e92ef7e7da68393b58d638ac210b3980a91866df