Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SMTP and IMAP Strict Destination Question

    Scheduled Pinned Locked Moved DHCP and DNS
    unbound.confunbounddns resolutionsmtpimap
    3 Posts 1 Posters 331 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by JonathanLee

      Hello fellow Netgate community members can you please help?

      I have configured my firewall to do strict destination for mail it works for everything except gmail, gmail changes its ip addresses every couple of minutes, is there anyway I can possibly set unbound to bypass keeping this url in its dns resolver cache or possibly set it to always forward this request upstream to 8.8.8.8 or something.

      087a8316-18c1-49de-98e3-2877570e27e3-image.png

      Currernly I have my system set up to work like this it does work but at times google will not download until unbound updates the ip address in the cache.

      Screenshot 2025-01-16 at 09.57.48.png

      Screenshot 2025-01-16 at 09.57.59.png

      This works perfectly and secures this port from use of "any destination"

      again google changes ip addresses so fast that it sometimes is behind the current address in use.

      What I would like to do is set imap.gmail.com and smtp.gmail.com to an automatically resolve every time and never save the record.

      The other mail servers work perfectly, they can only mail to those urls and that is all I need. Google does not seem to like being configured like this.

      Any ideas for a custom unbound resolver setting just for gmail?

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee
        last edited by

        Keep in mind mail servers have been attacked when firewalls have an access control line that allows smtp and imap traffic to any destination all this does is specifically state you can only use the mail destination servers you use and block unknown ones.

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • JonathanLeeJ
          JonathanLee
          last edited by

          685ef897-9dfa-4656-81a3-8cb04f4c40f8-image.png

          I am aware of the resolver interval, is there a way to bypass one url

          example imap.gmail.com always forward to 8.8.8.8 do not save in firewall dns namesever for reuse

          thus every time it gets the new ip address google has for the mail server, they change so fast the firewall can't keep up so the mail app at times says error after 5 mins it will resolve but that is unacceptable for modern use.

          Make sure to upvote

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.