[Mailman-Users] Non-member posting to the list
mailman at veggiechinese.net
Tue Nov 13 23:23:02 CET 2012
On Tue, Nov 13, 2012 at 04:03:32PM -0200, Rodrigo Abrantes Antunes wrote:
> In my case, I found that the return-path header is the address of the
> original sender, so how could I add a rule in mailman to deny posts with
> return-path's address that are not members?
The envelope-sender can also be spoofed trivially.
If you want to prevent someone from sending email as someone who *is*
approved to post to the list, I think your safest bet is to require
approval for all posts to the list -- in other words, set the action for
posts by moderated members allowed to post to 'hold', and have the
moderate bit set even for users who are allowed to post.
More information about the Mailman-Users