Disable account instead of block IP

Issue #133 wontfix
Former user created an issue

some user always forget password caused others are blocked

Comments (4)

  1. Zhang Huangbin repo owner

    IP blocking for POP3/IMAP is more critical than SMTP.

    • For smtp service, cracker just tries to send spams to your mailbox.
    • For POP3/IMAP, cracker is trying to crack your password, then send out spams with your account. This may hugely impact your server reputation and cause blacklisting by other mail servers. Also, just reported by one client today that one cracker updated the sieve rules to "quietly" redirect all received emails to cracker's mailbox. this is horrible.

    By the way, Dovecot doesn't log email address of failed login attempts, so we need to turn on verbose logging in Dovecot to get the email address.

  2. Log in to comment