Skip to content

Disable VRFY and EXPN SMTP Commands for Improved Security #67

@maneeshaxyz

Description

@maneeshaxyz

Description:

Currently, we respond to the VRFY and EXPN SMTP commands, which can be exploited to:

  • Enumerate valid email addresses or system usernames (VRFY)

  • Reveal internal mailing list members (EXPN)

These commands are considered legacy and unnecessary for normal email operations.

Requirement

Disable VRFY and EXPN in the SMTP configuration by default

Expected Behavior:

  • No disruption to normal mail sending/receiving

  • Improved server hardening

  • Reduced attack surface

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions