How To Disable DSN Success Messages (Doc ID 1950051.1)

Last updated on JUNE 10, 2017

Applies to:

Oracle Communications Messaging Server - Version 7.0.4 and later
Information in this document applies to any platform.

Goal

Spammers are creating large scale joe-job attacks by specifying an e-mail address for DSN-Success messages that does not belong to them. Spammer sends message to legit user and it gets through all filtering and is delivered. Spammer has set DSN-Notify for successful delivery to go to a third party, effectively joe-jobbing that third party with excessive amount of DSN-Notify success messages ...

So we want to stop that. I understand the NOTARY mechanism can't be completely turned off ... so what can we do? Maybe discard all DSN-Notify success messages at the outbound MTAs?

Also, could you give me a pointer on how we would implement the rejection just for unauthenticated senders?
 

Solution

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms