SMTP server allows fake hostnames in HELO

Risk Level: Low risk vulnerability  Low

Check or Attack Name: SMTPforgery

Platforms: Any, Sendmail
Description:

The SMTP server was found to accept any hostname issued to it in the HELO command. This lack of authorization could allow users to more easily forge mail from your server.

Remedy:

Upgrade your Mail Transfer Agent (MTA) to a package or version that supports more rigorous validation of hostnames. It may be possible to configure your server to do this; refer to your server's documentation.

References:

X-Force Logo
Know Your Risks