MWEB SMTP Redirect Service - Is it legal?

Ben_D0ver

Well-Known Member
Joined
Feb 13, 2010
Messages
142
Reaction score
0
Was assisting a mate with issues on their machine and noticed that when you telnet into your hosting providers smtp server on port 25 mweb are catching the connection and redirecting it to one of their smtp servers.

This got me questioning what they are capturing. For example, most hosts require you to setup smtp auth and if MWEB are redirecting this traffic to one their smtp servers then it may be possible for them to capture this information and do what ever the hell they want with it.

I wonder what the legalities of this are, and where this information is stored and who has access to it.
All these questions considering the post that was made about WebAfrica's staff fiddling on client's database tables.

This is no attack on MWEB per say, as I know that SAIX does the same, its rather me asking as its been bugging me.
 
Was assisting a mate with issues on their machine and noticed that when you telnet into your hosting providers smtp server on port 25 mweb are catching the connection and redirecting it to one of their smtp servers.

This got me questioning what they are capturing. For example, most hosts require you to setup smtp auth and if MWEB are redirecting this traffic to one their smtp servers then it may be possible for them to capture this information and do what ever the hell they want with it.

I wonder what the legalities of this are, and where this information is stored and who has access to it.
All these questions considering the post that was made about WebAfrica's staff fiddling on client's database tables.

This is no attack on MWEB per say, as I know that SAIX does the same, its rather me asking as its been bugging me.

Good MOrning isp-insider

Please see the below paragraph for the reasons we are redirecting,


As a preventative measure to combat outbound spam and virus-generated email traffic, MWEB will no longer support the direct sending of mail on Port 25. All port 25 traffic will be silently redirected to our own relay servers so that we can effectively manage any malicious traffic, thereby protecting our network from blacklisting. Should you wish to send mail through an external relay server in future, you will have to use the mail submission port (587), which should be supported on all standards compliant relay servers. If your relay server does not support this, please mail the details to [email protected] and we will investigate an alternative solution for you.


Please note that data integrity is a very important factor within any industry, especially within the isp industry. If you can't trust your ISP, who can you trust?
 
Well done, Mweb for taking a hard line against spam.

Will this also enable you to see which customer(s) got issues with a spambot, and thereby notifying said customer of said problem(s)?
 
Well done, Mweb for taking a hard line against spam.

Will this also enable you to see which customer(s) got issues with a spambot, and thereby notifying said customer of said problem(s)?

Hi The_Librarian,

Correct, our mail engineers monitor the redirect server and if they pick up any spambot, they notify our abuse team who notifies customers.

Kind regards,
MWEB Guy
 
Hi MWEB Guy

I am well aware of the reasons behind this and its been done by SAIX for years. My concern is one thats raised around what information is collected. Im not referring to mail information but rather what measures are in place to ensure that authentication information is not stored, and if it is what procedures are in place do ensure that this information is secured
 
Hi isp-insider

I've confirmed with our engineers that the server logs would reflect this as a failed authentication attempt, but for obvious reasons no passwords are captured or stored in these logs.

hope that puts your mind at ease :)

Kind Regards
Will
 
I am well aware of the reasons behind this and its been done by SAIX for years. My concern is one thats raised around what information is collected. Im not referring to mail information but rather what measures are in place to ensure that authentication information is not stored, and if it is what procedures are in place do ensure that this information is secured
This is no more or less secure. Email is and always has been about as secure as sending a postcard and its trivial for your ISP to intercept if they want to. If you have security concerns than you should be using TLS to encrypt the connection between your mail client and the server and S-MIME or PGP to encrypt your actual messages.
 
This is no more or less secure. Email is and always has been about as secure as sending a postcard and its trivial for your ISP to intercept if they want to. If you have security concerns than you should be using TLS to encrypt the connection between your mail client and the server and S-MIME or PGP to encrypt your actual messages.
TLS and SSL is setup and available. within the context of this query we're assuming that one was not using either and the response from MWEB satisfies my queries.

Thanks MWEB Guy
 
How would this effect people who have syncs installed on their SMTP servers to, for example, make copies of emails for legal compliance - I'm assuming the mails wouldn't get archived by their server.
 
SMTP redirection is just not on. MWEB should allow you to opt out of this if you so desire. Many professional IT people use specific outgoing SMTP servers for various different reasons. This is one of the many reasons I don't use MWEB.
 
SMTP redirection is just not on. MWEB should allow you to opt out of this if you so desire. Many professional IT people use specific outgoing SMTP servers for various different reasons. This is one of the many reasons I don't use MWEB.

I don't think they are the only ISP.... I believe its a fairly common practice.
 
How would this effect people who have syncs installed on their SMTP servers to, for example, make copies of emails for legal compliance - I'm assuming the mails wouldn't get archived by their server.

The redirect is only active on Home accounts,not Business ^
 
The redirect is only active on Home accounts,not Business ^
we've tested from two lines
one a home account in cpt and we're unable to connect to the intended servers on ports 25 and 587
on a business account based in jozi we can connect to the servers on port 587 but get redirected on 25

seems the capetonian engineers took the instructions and did the complete opposite of JHB.
 
How would this effect people who have syncs installed on their SMTP servers to, for example, make copies of emails for legal compliance - I'm assuming the mails wouldn't get archived by their server.
the chances of your mail being delayed and intercepted are increased. auditors may have a wet **** about it

I don't think they are the only ISP.... I believe its a fairly common practice.
correct, saix / telkom do the same. and how much fun is it when their smtp servers go down for 2 days without them notifying any one. the support desk engineers at every other isp that host domains get crapped on for mail delays.

SMTP redirection is just not on. MWEB should allow you to opt out of this if you so desire. Many professional IT people use specific outgoing SMTP servers for various different reasons. This is one of the many reasons I don't use MWEB.
we understand the need for it and with all due respect mweb are responsible for their ip's and its the only way they can stop Nigerians from sending 419 related mails from every internet cafe in cpt.
 
ok for those that want to know.

we did a few tests to different mail servers and found very inconsistent results from different mweb lines..
I have sent the results to mweb guy and will@mweb for them to check out.
in the interim we wait and watch mail being flagged as spam due to spf failures
 
Hi isp-insider,

Thanks for all the info provided via PM.
As I advised, I will forward your findings to the relevant persons and provide you with feedback as soon as I can.

kind regards,
MWEB Guy
 
No no, thank you!

if only your data center guys were this helpful ;)
Hi isp-insider,

Thanks for all the info provided via PM.
As I advised, I will forward your findings to the relevant persons and provide you with feedback as soon as I can.

kind regards,
MWEB Guy
 
Top
Sign up to the MyBroadband newsletter
X