Koozali.org: home of the SME Server

Stripping SMTP Received: headers

Crome

Stripping SMTP Received: headers
« on: February 06, 2006, 04:48:41 PM »
Hi,

I'm running an internal mailserver on my LAN. Incoming and outgoing mails are passing through SME Server. I was wondering if there's a way to strip the SMTP Received: headers inside my outgoing mails because they are revealing way too much information about my network...

Thanks!

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Stripping SMTP Received: headers
« Reply #1 on: February 06, 2006, 06:29:15 PM »
Quote from: "Crome"

I'm running an internal mailserver on my LAN. Incoming and outgoing mails are passing through SME Server. I was wondering if there's a way to strip the SMTP Received: headers inside my outgoing mails because they are revealing way too much information about my network...


The SMTP received headers are useful, and required by the SMTP standards. If your system is secure, the information in Received headers is not valuable to an attacker. If your system is not secure, the problem is in the system insecurities, not in the information revealed in mail headers.

Crome

Re: Stripping SMTP Received: headers
« Reply #2 on: February 06, 2006, 07:27:19 PM »
Quote from: "CharlieBrady"
The SMTP received headers are useful, and required by the SMTP standards. If your system is secure, the information in Received headers is not valuable to an attacker. If your system is not secure, the problem is in the system insecurities, not in the information revealed in mail headers.

Thanks for the swift reply m8 but with all due respect that's not the reply I was hoping for. I'm not asking if I want certain information in my headers to be stripped, I asked for a way how to do it. If Received headers are preserved from the point where an email leaves my network, there is no way troubleshooting email flow is endangered and I am not violating SMTP standards in any way. Furthermore, whenever an outgoing email must cross several hosts on a private network before it leaves that network it automatically reveals internal IP-addressing schemes and maybe even DNS-names and mailserver ID's so that is information I HAVE to strip in order to have a secure infrastructure. All big companies do that.

So please, no more lectures about how I should secure my systems. Just tell me if there is a way qmail or a plugin to it can be used to strip certain fields out of an SMTP-header. Thank you!

Offline dmac

  • ****
  • 143
  • +0/-0
    • http://www.rylar.ca
Stripping SMTP Received: headers
« Reply #3 on: February 07, 2006, 03:02:42 PM »
What are you using for a mail server?

Perhaps you should be looking at the mail server to remove this information, not the router to the internet.
"In a world without Fences, why do we need Gates and Windows"