System Inetworking E-Mail
System Inetworking E-Mail
System i
Networking
E-mail
Version 5 Release 4
System i
Networking
E-mail
Version 5 Release 4
Note
Before using this information and the product it supports, read the information in “Notices,” on
page 45.
This information assumes that you have worked on the i5/OS® operating system before and have a
working knowledge of TCP/IP, Simple Mail Transfer Protocol (SMTP), and e-mail concepts.
Printable PDF
Use this to view and print a PDF of this information.
To view or download the PDF version of this document, select E-mail (about 661 KB).
| You need Adobe Reader installed on your system to view or print these PDFs. You can download a free
| copy from the Adobe Web site (www.adobe.com/products/acrobat/readstep.html) .
E-mail concepts
You depend on electronic mail (e-mail) as an essential business tool. The i5/OS operating system uses
protocols, like Simple Message Transfer Protocol (SMTP) and Post Office Protocol (POP), to make your
e-mail run smoothly and efficiently on the network.
SMTP is essentially the end-to-end delivery of mail from one mail server to another. There is a direct
connection between an SMTP sender (the client) and the destination SMTP receiver (the server). The
SMTP client keeps the mail at the sender until it transmits and copies it successfully to the SMTP receiver
(server).
SMTP on the i5/OS operating system supports the distribution of notes, messages, and ASCII text
documents. SMTP can support formats other than plain text by using the Multipurpose Internet Mail
Extensions (MIME) protocol. MIME is the Internet standard for sending mail with headers that describe
the contents of the mail messages to the receiving client. These messages can contain video, audio, or
binary parts.
In order for e-mail to reach its destination, SMTP must be able to deliver it to both the correct host and
user ID that resides on that host. Suppose that mail is sent to bobsmith@mycompany.com.
First, SMTP checks to see if the e-mail addressee (bobsmith) is a user on the local server. If SMTP
determines that it is not, SMTP forwards the e-mail to the next host server. The next host might or might
not be the final host. SMTP determines the name of the host from addressing information that is found in
the SMTP protocol.
SMTP then resolves the host’s address by using either the domain name server or the local host table.
The host name is what people use as a part of their e-mail account (mycompany.com); the IP address is
what SMTP uses to find the correct mail server to send mail to (192.1.1.10). See the DNS topic for
complete information about DNS.
For inbound e-mail, the SMTP server first converts the destination host name into an Internet Protocol
(IP) address. Because of the aliasing function, the server can have several host names. Therefore, the
The POP server provides electronic mailboxes on the i5/OS operating system from which clients can
retrieve mail. Any mail client that supports the POP3 protocol can use this server, such as Netscape Mail,
Outlook Express, or Eudora. Clients might be running on any platform, such as Windows®, Linux®, AIX®,
or Macintosh.
The POP server serves as a temporary holding area for mail until it is retrieved by the mail client. When
the mail client connects to the server, it queries the contents of its mailbox to see if there is any mail to
retrieve. If there is, it retrieves one mail message at a time. After a message has been retrieved, the client
instructs the server to mark that message for deletion when the client session is complete. The client
retrieves all of the messages in the mailbox and then issues a command that tells the server to delete all
of the messages that are marked for deletion and to disconnect from the client.
POP mail clients use verbs to communicate with the POP server. Verbs supported by the i5/OS POP
server are described in the POP protocol.
For more information about how the POP protocol works, use the RFC Index to look up RFC 1725, which
defines the POP Version 3 mail interface standard.
Related tasks
“Accessing e-mail servers with iSeries Navigator” on page 10
You can use iSeries™ Navigator to configure and manage Simple Mail Transfer Protocol (SMTP) and
Post Office Protocol (POP) e-mail servers.
“Configuring Simple Mail Transfer Protocol and Post Office Protocol servers for e-mail” on page 11
To use e-mail, you need to configure Simple Mail Transfer Protocol (SMTP) and Post Office Protocol
(POP) servers on your system.
Related reference
“Post Office Protocol” on page 38
The Post Office Protocol (POP) Version 3 mail interface is defined in Request for Comments (RFC)
1725. RFC is the mechanism used to define evolving Internet standards.
Related information
RFC Index
E-mail 3
Situation
Jane Smith, the Human Resources director, needs to send a message to Sam Jones in the Legal
department. They both work at MyCompany headquarters. By following this process, you will be able to
see how e-mail is handled on your i5/OS operating system.
Details
Jane is using the Netscape mail client. She writes a message and sends it to SamJones@mycompany.com.
The following figure illustrates the path the mail message takes through the network.
The following text describes each phase of the path the mail message takes through the network.
The SMTP client on Jane’s PC uses the configuration data that was entered for the outgoing server and
identity. The identity field is used for the From address. The outgoing server is the host that is contacted
by the PC SMTP client. Because the address is entered as a domain, the SMTP client queries Domain
Name System (DNS) to get the IP address of the SMTP server, and discovers that it is 192.1.1.8.
The SMTP client now contacts the SMTP server on the SMTP port (Port 25 at 192.1.1.8). The dialog that is
used between the client and the server is the SMTP protocol. The SMTP server accepts the delivery of the
mail, and the message is transmitted from the client to the server using TCP/IP.
The SMTP server tests the domain of the recipient to see if it is local. Because it is local, the mail is
written out to an integrated file system file and the QMSF Framework Create Message application
programming interface (API) is used to put the message information in the QMSF queue. The QMSF
framework allows the distribution of e-mail, calling exit programs or snap-ins to handle specific mail
types. The message information identifies Sam’s address as SMTP format, so the framework calls the
SMTP Address Resolution exit program. This program again checks that the message is local. Because it
is local, it uses the system distribution directory (data entered through WRKDIRE) to find the recipient’s
SMTP address. It finds Sam’s address, and finds the mail service level is system message store in the
directory entry for this user; therefore it recognizes it as a POP account. Then SMTP Address Resolution
adds his profile information to the message information. It marks the information as POP local delivery.
The QMSF Framework then calls the POP Local Delivery exit program, which finds the profile
information and the name of the integrated file system file and delivers the mail to Sam’s mailbox.
Phase 3: POP client retrieves message for Sam Jones from the POP server
Some time later, Sam decides to use his mail client (Netscape) to check his mailbox for e-mails. The POP
client on his PC is configured to check the POP server at mycompany.com for the user name SamJones
and password (******). The domain name is again changed to an IP address (using DNS). The POP client
contacts the POP server using the POP port and the POP3 protocol. The POP server on the i5/OS
operating system checks whether the mailbox user name and password match the profile and password
of an i5/OS user. After it is validated, the profile name is used to find Sam’s mailbox. The POP client
loads the message, and sends a request back to the POP server to delete the mail from the POP mailbox.
The message is then displayed in Netscape for Sam to read.
Related concepts
“Planning for e-mail” on page 6
Before setting up e-mail, you should have a basic plan for how to use e-mail on your system.
Related reference
“Simple Mail Transfer Protocol” on page 37
Simple Mail Transfer Protocol (SMTP) is a TCP/IP protocol used in sending and receiving e-mail. It is
typically used with POP3 or Internet Message Access Protocol to save messages in a server mailbox
and download them periodically from the server for the user.
“Post Office Protocol” on page 38
The Post Office Protocol (POP) Version 3 mail interface is defined in Request for Comments (RFC)
1725. RFC is the mechanism used to define evolving Internet standards.
E-mail 5
Planning for e-mail
Before setting up e-mail, you should have a basic plan for how to use e-mail on your system.
You might want to refer to the e-mail example for basic information about how e-mail works.
If you will be using the Domino server and the i5/OS SMTP server, refer to Hosting a Domino and SMTP
server on the same i5/OS operating system. For additional information about Domino, refer to the
Domino topic or the Lotus Domino for i5/OS Web site.
If you do not plan to use the SMTP or POP servers, disable them to ensure that they will not be used
without your knowledge.
Related concepts
“Scenario: Sending and receiving e-mail locally” on page 3
This scenario demonstrates how e-mail is processed between local users.
Domino
Related tasks
“Configuring e-mail” on page 10
To set up e-mail on your system, you need to configure TCP/IP, set up Simple Mail Transfer Protocol
(SMTP) and Post Office Protocol (POP) servers, and start the e-mail servers.
Related information
Control e-mail access provides tips for protecting your e-mail servers from flooding and spamming.
Related concepts
Independent disk pool examples
“Determining problems with e-mail” on page 39
You can use simple steps to determine what is causing a problem with e-mail.
Related tasks
“Restricting relays” on page 17
To prevent people from using your e-mail server for spamming or sending large amounts of bulk
e-mail, you can use the relay restriction function to specify as closely as possible who can use your
system for relays.
“Restricting connections” on page 19
To ensure the security of your system, you need to prevent the connection of users who might abuse
your e-mail server.
Related information
AS/400 Internet Security: Protecting Your AS/400 from HARM in the Internet
If you want to allow SMTP clients to access your system, you should protect your system from attack by
performing the following tasks:
v If possible, avoid using an *ANY *ANY entry in the system distribution directory. When your system
does not have an *ANY *ANY entry, it is more difficult for someone to attempt to use SMTP to
overwhelm your system or your network. When your auxiliary storage is filled with unwanted mail
that is being routed through your system to another system, your system or your network is
overwhelmed.
v Set adequate threshold limits for your auxiliary storage pools (ASPs) to prevent a user from
overwhelming your system with unwanted objects. You can display and set the thresholds for ASPs by
using either system service tools (SSTs) or dedicated service tools (DSTs).
v Tune the maximum number of prestart jobs that will be created by using the Change Prestart Job Entry
(CHGPJE) command. This will limit the number of jobs created during a denial of service attack. The
default is 256 for the maximum threshold.
v Prevent outsiders from using your connection to send unsolicited e-mail (spam) by restricting relays
and connections.
If you want to allow POP clients to access your system, be aware of the following security considerations:
v The POP mail server provides authentication for clients who attempt to access their mailboxes. The
client sends a user ID and password to the server.
Note: Typically, storage space is not a significant problem. When a client receives mail, the mail server
deletes the mail from the system.
Related concepts
“Determining problems with e-mail” on page 39
You can use simple steps to determine what is causing a problem with e-mail.
E-mail 7
Preventing e-mail access
Depending on how you use your system, you might want to prevent users from accessing e-mail through
SMTP and POP servers. You can prevent e-mail access entirely or allow access occasionally.
SMTP is configured by default to start automatically when TCP/IP starts. If you do not plan to use SMTP
at all, do not configure it on your system (or allow anyone else to configure it).
Preventing Simple Mail Transfer Protocol from starting when TCP/IP starts:
You might need to use Simple Mail Transfer Protocol (SMTP) occasionally, but want to limit the amount
of access users have to the SMTP server.
To prevent SMTP server jobs from starting automatically when you start TCP/IP, follow these steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Right-click SMTP and select Properties.
3. Clear Start when TCP/IP starts.
To secure your Simple Mail Transfer Protocol (SMTP) server from unknown applications, you might want
to prevent access to SMTP ports.
To prevent access to SMTP from starting and to prevent someone from associating a user application,
such as a socket application, with the port that the system normally uses for SMTP, perform the following
steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Right-click TCP/IP Configuration and select Properties.
3. In the TCP/IP Configuration Properties window, click the Port Restrictions tab.
4. On the Port Restrictions page, click Add.
5. On the Add Port Restriction page, specify the following settings:
v User name: Specify a user profile name that is protected on your system. (A protected user profile
is a user profile that does not own programs that adopt authority and does not have a password
that is known by other users.) By restricting the port to a specific user, you automatically exclude
all other users.
v Starting port: 25
v Ending port: 25
v Protocol: TCP
6. Click OK to add the restriction.
7. On the Port Restrictions page, click Add and repeat the procedure for UDP.
8. Click OK to save your port restrictions and close the TCP/IP Configuration Properties window. The
port restriction takes effect the next time that you start TCP/IP. If TCP/IP is active when you set the
port restrictions, you should end TCP/IP and start it again.
You can hold Systems Network Architecture Distribution Services (SNADS) distribution queues, which
the SMTP application uses to distribute e-mail. This will provide you with extra protection to limit
distribution of e-mail.
HLDDSTQ DSTQ(QSMTPQ)PTY(*NORMAL)
HLDDSTQ DSTQ(QSMTPQ)PTY(*HIGH)
Related concepts
“E-mail concepts” on page 1
You depend on electronic mail (e-mail) as an essential business tool. The i5/OS operating system uses
protocols, like Simple Message Transfer Protocol (SMTP) and Post Office Protocol (POP), to make your
e-mail run smoothly and efficiently on the network.
If you do not plan to use POP at all, do not configure it on your system (or allow anyone else to
configure it).
You might need to use Post Office Protocol (POP) occasionally, but want to limit the amount of access
users have the POP server.
The POP server is configured by default to start automatically when TCP/IP starts. To prevent POP
server jobs from starting automatically when you start TCP/IP, follow these steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Right-click POP and select Properties.
3. Clear Start when TCP/IP starts.
To secure your Post Office Protocol (POP) server from unknown applications, you might want to prevent
access to POP ports.
To prevent the POP server from starting and to prevent someone from associating a user application,
such as a socket application, with the port that the system normally uses for POP, complete the following
steps:
1. In iSeries Navigator, connect to your system, and expand Network → Servers → TCP/IP.
2. Right-click TCP/IP Configuration and select Properties.
3. In the TCP/IP Configuration Properties window, click the Port Restrictions tab.
4. On the Port Restrictions page, click Add.
5. On the Add Port Restriction page, specify the following settings:
v User name: Specify a user profile name that is protected on your system. (A protected user profile
is a user profile that does not own programs that adopt authority and does not have a password
that is known by other users.) By restricting the port to a specific user, you automatically exclude
all other users.
v Starting port: 109
v Ending port: 110
v Protocol: TCP
6. Click OK to add the restriction.
7. On the Port Restrictions page, click Add and repeat the procedure for UDP.
8. Click OK to save your port restrictions and close the TCP/IP Configuration Properties window.
E-mail 9
The port restriction takes effect the next time that you start TCP/IP. If TCP/IP is active when you set the
port restrictions, you should end TCP/IP and start it again.
Configuring e-mail
To set up e-mail on your system, you need to configure TCP/IP, set up Simple Mail Transfer Protocol
(SMTP) and Post Office Protocol (POP) servers, and start the e-mail servers.
Related concepts
“Simple Mail Transfer Protocol on i5/OS” on page 2
Simple Mail Transfer Protocol (SMTP) is the protocol that allows the i5/OS operating system to send
and receive e-mail.
“Planning for e-mail” on page 6
Before setting up e-mail, you should have a basic plan for how to use e-mail on your system.
You can click Help to see the help information about the dialog. You can also click the question mark
next to the Help button, and drag it onto a field to see the help information about that field.
Related concepts
“Post Office Protocol on i5/OS” on page 3
The Post Office Protocol (POP) server is the i5/OS implementation of the Post Office Protocol Version
3 mail interface.
If you are setting up e-mail on your system for the first time, complete the following steps. If you already
have TCP/IP configured on your system, you can proceed directly to Configure Simple Mail Transfer
Protocol (SMTP) and (POP) servers for e-mail.
1. In iSeries Navigator, expand your system → Network → TCP/IP Configuration.
2. Right-click Interfaces and select New Interface and the type of network the new interface represents.
Follow the wizard’s instructions to create a new TCP/IP interface. The wizard asks you to supply the
following information:
v Type of connection
v Hardware resource
v Line description
v IP address
v Host name
v Domain name
Note: Both the SMTP and the POP server must be correctly configured.
Related concepts
“Post Office Protocol on i5/OS” on page 3
The Post Office Protocol (POP) server is the i5/OS implementation of the Post Office Protocol Version
3 mail interface.
Related tasks
“Configuring TCP/IP for e-mail” on page 10
You need to set up TCP/IP before you can configure e-mail on your i5/OS operating system.
E-mail 11
Click this tab Then perform the following action
General If you have a mail router, enter the name of the mail router; for example,
mailrouter.company.com. The mail router name is the system name, where SMTP routes
the mail if the e-mail is not local mail. See the iSeries Navigator help for more details.
General If you have a firewall setup, select Forward outgoing mail to router through firewall.
General If you exchange e-mail with Domino servers, clear the Interpret percent sign as routing
character field.
Automatic Registration If you are using the SNDDST command to send e-mail and the RCVDST command to
receive e-mail, and you are using SNADS addressing instead of internet addressing,
select the Automatically add remote users to system distribution directory check box.
Automatic Registration If you are using the the SNDDST command to send e-mail and the RCVDST command
to receive e-mail, click System alias table in the Add users to field.
When requested by the POP client, the POP server delivers mail to a POP client from the user mailbox.
You must configure the POP server to completely prepare your system for e-mail.
To configure the POP server for a mail program such as Netscape Mail or Eudora Pro, complete the
following steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Double-click POP. The POP Properties dialog appears.
3. Refer to the following table to set the following parameters.
User profiles are how the i5/OS operating system identifies an addressee or sender of e-mail. Any user
you want as part of your e-mail system must have a user profile on the system.
By creating a user profile for each user, you enroll the users in the system distribution directory
automatically. The system distribution directory is what Simple Mail Transfer Protocol (SMTP) uses to
determine where to deliver local e-mail.
To create user profiles for Systems Network Architecture Distribution Services (SNADS) and Post Office
Protocol (POP) e-mail users, complete the following steps:
1. In iSeries Navigator, expand your system → Users and Groups.
12 System i: Networking E-mail
2. Right-click All Users and select New User. The New User dialog opens.
3. Type a user name and password for the user.
Note: This password will be used by POP users to access their POP mailboxes.
4. Click the Capabilities button.
5. Click the Privileges tab. Ensure that the Privilege class is User.
6. Click OK.
7. Click the Personal button.
8. Click the Mail tab.
9. Choose the Mail Service Level.
v If your user is a SNADS user, select OfficeVision® or JustMail.
v If your user is a POP mail user, select Lotus Mail or other POP3 client.
10. Choose the Preferred Address type.
v If your user is a SNADS user, select User ID and address.
v If your user is a Lotus Notes®, POP3 client, or Domino user, select SMTP Name.
11. Verify that the required domain name is displayed for the SMTP e-mail domain.
Note: The default name is typically correct, but if you have multiple local domains you might need
to change it.
12. Click OK. If you are enrolling a SNADS user, the enrollment is complete. If you are enrolling a POP
user who will use the i5/OS POP server only to retrieve e-mail, continue to the next step.
13. Click the Jobs button.
14. Click the Session Startup tab.
15. For the Initial Menu field, select Sign off. With this setting, any attempt to sign on the system, other
than to retrieve e-mail or change their password, automatically signs the user off.
16. Click OK.
17. Click OK.
18. Repeat these instructions until all of the e-mail users have user profiles.
Related concepts
“Sending and receiving e-mail” on page 20
Your system is a mail server and has e-mail users (SNADS, POP, or Lotus) enrolled on it. Your e-mail
users can send, receive, and read e-mail using either a POP client or a SNADS client.
Related tasks
“Using Systems Network Architecture distribution services to send e-mail” on page 24
You can send e-mail from your system using a System Network Architecture distribution services
(SNADS) client program.
E-mail 13
Starting the e-mail servers
You can start your servers and make your system an e-mail server with enrolled e-mail users.
You have started your servers and your system is now running an e-mail server with enrolled e-mail
users.
Note: If you have AT&T Global Network support, you can skip to Configuring the ISP Dial-up
Connection wizard.
1. In iSeries Navigator, expand your system → Network → Remote Access Services.
2. Right-click Receiver Connection Profiles and select New Profile.
3. Select PPP for the Protocol type.
4. Select Switched line for Connection type.
5. Expand TCP/IP Configuration and select Connections.
6. Expand Servers → TCP/IP.
7. Right-click SMTP and select Properties.
8. Click the Scheduler tab. Select the Start scheduler when SMTP is started check box, and specify the
connection profile that you created.
9. Click the ETRN page and select the Support ETRN (Dial-up mail retrieval) check box. Click Add to
specify the domain name for your ISP’s outgoing server’s address.
You can use the Internet service provider (ISP) Dial-up Connection wizard to configure the ISP dial-up
connection profile. If you do not have AT&T Global Network support, see Configuring a dial-up mail
connection profile for a preliminary step.
The connection wizard provides you with the IP addresses of the mail servers (SMTP and POP), their
assigned domain name, account name, and password.
To run the wizard and configure your SMTP scheduler, follow these steps:
1. In iSeries Navigator, expand your system → Network → Remote Access Services.
2. Right-click Originator Connection Profiles and select New AT&T Global Network Dial Connection.
3. On the Welcome panel, click Next to get started.
4. On the Application Type panel, select Mail exchange application and click Next.
5. Continue with the wizard to set up a new AT&T Global Network dial connection.
When you have configured the dial-up connection, you are ready to schedule batch ISP e-mail jobs.
Related tasks
“Configuring a dial-up mail connection profile” on page 14
If you do not have AT&T Global Network support, you must first configure a mail connection profile.
“Scheduling batch ISP e-mail jobs”
To limit the time required to establish a connection, you can schedule mail dial-up jobs to connect to
your Internet service provider (ISP) at regular intervals.
Use the ISP Dial-up Connection wizard to configure the connection. Then use the SMTP scheduler to set
the time intervals that you want your system to connect to your ISP and send your company’s e-mail.
To set the SMTP scheduler to send your e-mail to an ISP, complete the following steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Double-click SMTP. The SMTP Properties dialog opens.
3. Click the Scheduler tab.
4. Select the Start scheduler when SMTP is started check box.
5. Select the Point-to-point connection profile you configured with the AT&T Global Network Dialer
Wizard, or select a manually configured Point-to-point connection profile.
6. Set the Mail transfer interval to the number of minutes you want SMTP to deliver your queued
e-mail.
E-mail 15
7. If your ISP is not with the AT&T Global Network, select the Issue ETRN when connecting to remote
server check box.
8. Enter the Server IP address for the incoming mail server on the ISP’s network, and enter the
Registered ISP host.domain for which this SMTP server will issue an ETRN.
9. Click OK.
Related tasks
“Configuring the ISP Dial-up Connection wizard” on page 15
You need to configure a dial-up connection profile before using the Simple Mail Transfer Protocol
(SMTP) scheduler function to send large amounts of e-mail through an Internet service provider.
“Configuring the SMTP server for dial-up mail retrieval”
You can use the Simple Mail Transfer Protocol (SMTP) server to receive mail for remote dial-up
branch offices.
The system must have a fixed IP address and be registered with a DNS. Each host.domain for which the
remote dial-up servers will be retrieving mail must also have MX entries in the DNS pointing to this
system. The system must also have aliases for these host.domains in its local host table. If the remote
dial-up servers are running the i5/OS operating system, then they must be configured for scheduled
batch ISP e-mail jobs.
To receive e-mail requests from remote dial-up mail servers, complete the following steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Double-click SMTP. The SMTP Properties dialog opens.
3. Click the ETRN tab.
4. Select the Support ETRN (Dial-up mail retrieval) check box.
5. Click Add to specify your ISP’s host and domain name. This can be done multiple times if multiple
mail servers are requesting their mail.
6. Click OK.
Related tasks
“Scheduling batch ISP e-mail jobs” on page 15
To limit the time required to establish a connection, you can schedule mail dial-up jobs to connect to
your Internet service provider (ISP) at regular intervals.
For the SMTP server to host ISP functions, it is necessary for SMTP to appear to operate in multiple
domains. The SMTP client uses this configuration information to know which interface to bind to when it
sends the e-mail, and which mail to consider local (resolve and send on its own) or to forward to a
configured firewall mail daemon.
1. In iSeries Navigator, expand your system → TCP/IP → Network.
2. Right-click SMTP and select Properties.
3. Click the Multiple Domains tab.
4. Click Add to specify the domains and interfaces that you would like to support.
5. Click OK.
Related concepts
Securing e-mail
You can use firewalls, restrict relays and connections, and filter out viruses to help secure e-mail.
It is important to promote a secure environment in your Simple Mail Transfer Protocol (SMTP) server.
You must protect your SMTP server and your users from internal and external hindrances.
Before you follow these steps to configure a router, see the Prerequisites for an e-mail router.
The e-mail router routes the e-mail to the IP address or to another router. Route your outgoing e-mail to
an alternative system if your local server fails to deliver the e-mail to the system. If you have a firewall,
you can use the firewall as your router.
Restricting relays
To prevent people from using your e-mail server for spamming or sending large amounts of bulk e-mail,
you can use the relay restriction function to specify as closely as possible who can use your system for
relays.
To specify users that can send e-mail to the Internet, follow these steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Right-click SMTP and select Properties.
3. Click the Relay Restrictions tab.
4. Select the appropriate relay restriction from the six options offered here.
E-mail 17
Note: If you choose Accept relay messages for only recipients in the near domains list or Accept
relay messages using both the near domains and address relay lists, then you need to click
the General tab to list the near domains from which you are accepting relays.
5. Click OK.
6. If the SMTP server is currently running, you need to end and restart the SMTP server for the changes
to take effect:
a. Right-click SMTP and select Stop.
b. Right-click SMTP and select Start.
Related concepts
“Controlling e-mail access” on page 6
You should control who accesses your system through e-mail to protect your data from malicious
attacks.
One of the options for relay restriction enables Post Office Protocol (POP) clients to relay messages
through Simple Mail Transfer Protocol (SMTP) for a specified period of time after they log on to the POP
server.
This function is commonly called POP before SMTP. It is particularly useful for mobile employees that
use dynamic IP addresses, because security checking functions that use fixed IP addresses are not
effective for checking dynamic IP addresses. You can enable a mobile employee to authenticate once to
the POP server and to send e-mail for a designated period of time (15 - 65535 minutes) without
authenticating again.
For example, you might configure the system to allow your remote users to relay messages through the
SMTP server during a four-hour (240 minutes) period of time after they log on to the POP server. In this
example, a mobile worker logs on to the POP server to retrieve his e-mail. The POP server records the
user’s IP address and a time stamp in a queue. An hour later, the user decides to send an e-mail message.
When the user sends the e-mail message using SMTP, the SMTP server checks the queue to verify that
the user accessed the POP server to retrieve e-mail sometime during the configured time period. After the
user is verified, the SMTP server relays the e-mail message to the SMTP client for delivery to the e-mail
recipient.
Note: To more precisely control the users that can access your e-mail server, you can use the relay
restriction function and the connection restriction function together. For example, you might want
to restrict specific groups of users from connecting to your e-mail server but allow certain POP
clients within that group to use your SMTP server to send e-mail messages.
To enable POP clients to relay messages for a specified length of time, follow these steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Right-click SMTP and select Properties.
3. Click the Relay Restrictions tab.
4. For Allow relay messages, select Specified.
5. Select From the POP client for the following duration (15 - 655535) and enter a time value to specify
the number of minutes to allow a client to send mail using the SMTP server.
6. Click OK.
The i5/OS operating system enables you to use the relay restriction function along with the connection
restriction function to carefully control who can access your e-mail server.
For example, you know that users within a specific range of IP addresses routinely send spam e-mail.
Therefore, you want to restrict addresses in that range from connecting to your e-mail server. However,
several of the IP addresses in the IP address range represent trusted i5/OS users, and you want to enable
those users with i5/OS user profiles to relay messages for a specified period of time after they log on to
the POP server.
Fortunately, you can use the connection restriction function to restrict connections of the specific range of
IP addresses, and use the relay restriction function to allow certain trusted users (POP clients) within the
restricted range to send e-mail using your Simple Mail Transfer Protocol (SMTP) server. The i5/OS
operating system first checks to see if you configured the system to allow POP clients to relay messages
for a specified period of time. Then, it checks for restricted connections. This i5/OS capability enables
you to precisely control who can use your SMTP server to relay messages and who can connect to your
e-mail server.
If you choose to use the connection restriction function and the relay restriction functions together, you
need to create the appropriate data area in the QUSRSYS library to enable the POP server authentication
capability to override the connection restriction configuration. You need to create the data area before you
configure the relay restriction and connection restriction in iSeries Navigator. At a later date, you might
want to remove the relay restriction that allows the POP clients within the restricted group to use your
e-mail server. In that case, you need to delete the data area.
Note: After you create the data area, refer to the “Restricting relays” on page 17 and “Restricting
connections” topics for configuration details.
Restricting connections
To ensure the security of your system, you need to prevent the connection of users who might abuse
your e-mail server.
Unwanted users might connect to your system, and send unsolicited mail. This unsolicited e-mail takes a
great amount of processing unit cycles and space. Also, if your system allows others to relay unsolicited
mail, other systems might block the mail that comes from your system.
You can specify IP addresses of known unwanted users, or you can connect to a host that contains a
Realtime Blackhole List (RBL) server. These Realtime Blackhole Lists provide a listing of known IP
addresses that send unsolicited mail.
To specify known IP addresses or a host with a Realtime Blackhole List, complete the following steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Right-click SMTP and select Properties.
3. Click the Connection Restrictions page.
4. Click Add to add host names of servers with Realtime Blackhole Lists that you would like to use.
5. Click Add to add specific IP addresses to restrict attempted connections.
6. Click OK.
E-mail 19
Related concepts
“Controlling e-mail access” on page 6
You should control who accesses your system through e-mail to protect your data from malicious
attacks.
With virus filtering, questionable e-mails are automatically quarantined or discarded based on parameters
established by the administrator. E-mails can be filtered by any or all of the following criteria:
1. Address-individuals or domains
2. Subject - ILOVEYOU
3. Attachment name - lovebug.vbs or *.vbs
4. MIME type - image/* or image/jpg
The values can contain wildcard characters. One wildcard character is an asterisk (*), which specifies that
one or more arbitrary characters can be at the position of the wildcard. For example, *.vbs can be used to
check for filenames with an extension of .vbs. An originator of *@us.ibm.com filters all mail from IBM in
the United States, and a filter of image/* filters type image for all subtypes.
Note: In addition to these tools, you need to implement supplemental antivirus solutions.
Your users can send and receive e-mail in the following different ways:
Related concepts
“E-mail concepts” on page 1
You depend on electronic mail (e-mail) as an essential business tool. The i5/OS operating system uses
protocols, like Simple Message Transfer Protocol (SMTP) and Post Office Protocol (POP), to make your
e-mail run smoothly and efficiently on the network.
Related tasks
“Enrolling e-mail users” on page 12
You need to create user profiles to enroll e-mail users.
Note: On some clients, you might have to enter the host address several times: to specify the POP
server’s host for receiving mail, to specify SMTP’s host for sending mail, and to identify the
sender of the e-mail to the recipients.
v POP user or account name. This is the same as the i5/OS user profile name.
v The user password. This password must be the same as the i5/OS user profile password.
2. Identify the user and the user’s preferences. In Netscape Mail, for example, the user looks for Edit →
Preferences → Mail and News Groups → Identity.
v User name. This is the i5/OS user profile name.
v User’s e-mail address. This is the user ID and fully qualified domain name.
v Reply-to address. This can be the same as the user’s e-mail address that the network administrator
designates, but an i5/OS user profile must exist on the system.
3. Identify the outgoing mail (SMTP) server. You need to identify the SMTP server on the e-mail client
because it is the server that allows the client’s users to send mail out. In Netscape Mail, for example,
the user looks for Edit → Preferences → Mail and News Groups → Mail Servers.
v POP user or account name. This is the user ID on the user’s e-mail address; it is also the i5/OS user
profile name.
v Outgoing mail (SMTP) server. This is the system host name.
4. Identify the incoming mail (POP) server. In Netscape Mail, for example, the user looks for Edit →
Preferences → Mail and News Groups → Mail Servers.
v Incoming mail server. This is the system host name.
QtmmSendMail API
You can use the Send MIME Mail (QtmmSendMail) API to send e-mail from an i5/OS program.
The QtmmSendMail API supports sending multiple mail attachments at one time, but the Send
Distribution (SNDDST) command does not. This API is in the service program QTCP/QTMMSNDM.
Application programs must bind to this service program.
Authorities
The MIME integrated-file-system file must exist for the duration of the QMSF framework pass. The
conversion and delivery exit points that are called by the QMSF job must be able to read this file. A
built-in exit program removes (unlinks) the link. If this is the last link, the framework deletes the file.
Directory authority
The data authority must be *X for product QMSF.
E-mail 21
File authority
QTCP and QMSF must have:
v Data authority *RWX
v Object authority *ALL
ADDTO100 format
Related concepts
“Solving problems with the QtmmSendMail API” on page 42
You can use this troubleshooting process to resolve problems that you are having with the Send
MIME Mail (QtmmSendMail) API.
“Attaching files” on page 27
You can send e-mail with an attached file or document by using the Send Distribution (SNDDST)
command.
JavaMail
You can develop e-mail client applications by using JavaMail.
The JavaMail API provides a platform-independent and protocol-independent framework you can use to
build Java™ technology based e-mail client applications. You can use the JavaMail API to create a mail
client capable of sending multimedia mail messages, as well as enabling a full fledged Internet Mail
Access Protocol (IMAP) implementation supporting folders, authentication, and attachment handling.
Because SMTP only supports character data, it uses MIME to represent complex data such as formatted
text, file attachments (text and binary), and multimedia content. If you use the Send MIME Mail
(QtmmSendMail) API , your application must take care of converting the data into the appropriate
content. The JavaMail implementation provides MIME processing capabilities natively.
JavaMail components are included as part of the IBM Developer Kit for Java.
Related concepts
JavaMail
Using the Infoprint® Server for iSeries, you can produce Adobe Portable Document Format (PDF) files
from any i5/OS output. You can send these generated PDF files as e-mail attachments. You can send a
single spooled file to an address. You can also split up a spooled file into several PDFs and send each one
to a different address. Using this method, you can send customer invoices to separate PDF files and send
the appropriate invoice to each customer’s e-mail address. The Infoprint Server for iSeries licensed
program (5722-IP1) is required to use this output method.
For more information about using the Infoprint Server to send PDF files, including examples for
configuring e-mail distribution, refer to the following sources:
E-mail 23
v Chapter 4, ″Using the Infoprint Server for iSeries PDF transform″ in IBM eServer™ iSeries Printing
You can use IBM Directory Server for iSeries (LDAP) to replace the function previously served by MAPI.
Using LDAP, you can provide a single address book that can be accessed by all users from the client
application.
The following procedure describes how to send e-mail using the Send Distribution (SNDDST) command.
The sender of the e-mail must be a local SNADS user. A local SNADS user has a profile configured by a
local system distribution directory entry. For more information, see Enroll e-mail users.
Note: You can also use Internet addressing when you send mail with the Send Distribution (SNDDST)
command.
Related tasks
“Enrolling e-mail users” on page 12
You need to create user profiles to enroll e-mail users.
The Keep Recipient (KEEPRCP) parameter specifies which recipient information is stored and sent within
each mail distribution. The setting of this parameter affects how the MIME headers get created for a note
from SNDDST.
In order for CC and BCC tags to show up in MIME headers (and client screens), you must set the
KEEPRCP parameter to *ALL. BCC recipients are not shown regardless of the setting of this parameter
because they are not intended to be. The TO and CC recipients show up in the text of the SNDDST note.
Standard Internet text notes consist of a general header and a text body. Multipurpose Internet Mail
Extension (MIME) notes, however, can contain multiple parts, which allow multimedia attachments to be
included with the text.
If the general header contains a content type of Multipart/Mixed, one or more attachments follow. There
are beginning and ending boundaries for each attachment. The boundary identifier is set on the
boundary= parameter that follows the Content-Type header tag. See Figure 1 for an example of a multipart
MIME note. In this example, each part has a content type, and each text content type can optionally have
a character set (charset) defined.
E-mail 25
From
@SYSNAM6.CITY.COMPANY.COM:popct08@SYSNAM6.city.company.com Wed
Jan 10
11:33:18 1996 Return-Path:
<@SYSNAM6.CITY.COMPANY.COM:popct08@SYSNAM6.city.company.com> Received: from
SYSNAM6.city.company.com by
fakeps2.city.company.com (COMPANY
OS/2 SENDMAIL VERSION 1.3.2)/1.0) id AA0329; Wed, 10
Jan 96 11:33:18 -0500 Date: Wed, 10
Jan 96
11:33:18 -0500 Message-Id: <9601101633.AA0329@fakeps2.city.company.com> Received:
from endmail9 by SYSNAM6.CITY.COMPANY. (IBM i5/OS SMTP V03R02M00) with TCP;
Wed, 10
Jan 1996 10:23:42
+0000. X-Sender: popct08@SYSNAM6.city.ibm.com (Unverified) X-Mailer: Windows
Eudora Pro
Version 2.1.2
Mime-Version:1.0Content-Type:multipart/mixed;boundary="=====================_821301929==
_"
To: fake@fakeps2.city.company.com From:
endmail9 <popct08@SYSNAM6.city.company.com> Subject:
eudora attachments
X-Attachments:C:\EUDORA\ARGYLE.BMP;--=====================_821301929==_
Content-Type: text/plain; charset=
"ARGYLE.BMP"
Qk12AgAAAAAAAHYAAAAoAAAAIAAAACAAAAABAAQAAAAAAAACAAAAAAAAAAAAAAAAAAAQAAAAAAAA
AAAAgAAAgAAAAICAAIAAAACAAIAAgIAAAICAgADAwMAAAAD/AAD/AAAA//8A/wAAAP8A/wD//wAA
////AE1EREREREREZERERERERE1E1ERERERERsZERERERETURE1ERERERGxsZERERERNRERE1ERE
REbGxsZERERE1ERERE1ERERsbGxsZERETURERERE1ERGxsbGxsZERNRERERERE1EbGxsbGxsZE1E
RERERERE1sbGxsbGxsbURERERERERG1sbGxsbGxtZEREREREREbG1sbGxsbG1sZERERERERsbG1s
bGxsbWxsZERERERGxsbG1sbGxtbGxsZEREREbGxsbG1sbG1sbGxsZERERsbGxsbG1sbWxsbGxsZE
RGxsbGxsbG1tbGxsbGxsZEbGxsbGxsbG1sbGxsbGxsZEbGxsbGxsbW1sbGxsbGxkREbGxsbGxtbG
1sbGxsbGREREbGxsbG1sbG1sbGxsZEREREbGxsbWxsbG1sbGxkREREREbGxtbGxsbG1sbGRERERE
REbG1sbGxsbG1sZEREREREREbWxsbGxsbG1kRERERERERNbGxsbGxsbG1ERERERERE1EbGxsbGxs
ZE1ERERERETUREbGxsbGxkRE1ERERERNREREbGxsbGRERE1ERERE1EREREbGxsZERERE1ERETURE
REREbGxkRERERE1ERNREREREREbGRERERERE1E1EREREREREZERERERERE3URERERERERERERERERERE--=====================_821301929==_--
If your network uses SNA distribution services (SNADS) and an office application to send and receive
e-mail, you need to configure your mail system so your users can use Internet addresses with the
SNDDST command.
Now your SNADS users can send e-mail to the Internet with the SNDDST command by entering an
Internet e-mail address at the Internet Recipient prompt.
Related information
When sending e-mail using the SNDDST command, you might want to send a file or document with the
e-mail. SNDDST is only capable of sending a single document or file at a time. If you would like to send
multiple attachments, send MIME mail with the Send MIME Mail (QtmmSendMail) API.
To attach and send a document with your e-mail, in the character-based interface, type:
SNDDST TYPE(*DOC) DSTD(your description) TOUSRID(anyuser) DOC(yourdoc) FLR(yourfolder)
To attach and send a file with your e-mail, in the character-based interface, type:
SNDDST TYPE(*FILE) DSTD(description) TOUSRID(any user)
MSG(message optional) DOCFILE(youlib/yourfile) DOCMBR(yourmbr)
Note: If you receive error messages, you might be attempting to send a file or document that is in a
format that is not compatible with the Send Distribution (SNDDST) command. You can use the
i5/OS CL CPY commands to convert the file to a file or document that is compatible with the
SNDDST command.
Assuming that the spooled file is already created, and the physical file and folder already exist, you must
convert the file into a sendable format. The conversions are done by using i5/OS CL commands, as
shown in the following example:
1. Move the spooled file to a database physical file:
CPYSPLF FILE(splfile) TOFILE(dbfile) JOB(job3/job2/job1) SPLNBR(splnbr) TOMBR(mbr)
2. Move the physical database file to a folder:
CPYTOPCD FROMFILE(lib/dbfile) TOFLR(folder) FROMMBR(mbr) REPLACE(*YES)
3. Send the document:
SNDDST TYPE(*DOC) TOUSRID(user address) DSTD(MAIL) DOC(mbr) FLR(folder)
Related reference
“QtmmSendMail API” on page 21
You can use the Send MIME Mail (QtmmSendMail) API to send e-mail from an i5/OS program.
To receive e-mail, follow this procedure. The recipient of the e-mail must be a local SNADS user.
1. In the character-based interface, type QRYDST (the Query Distribution command) and press F4. The
list of distributions appears.
2. Press F10 to view additional parameters.
3. In the File to Receive Output field, type file and library names that are easy to remember and press
Enter. The system creates these physical files.
4. Type WRKF (the Work with Files command) and press Enter. The Work with Files display appears.
5. Type the file name and library you specified in step 3 and press F4.
6. The display lists all your distributions (e-mail). Type 5 next to the distribution you want to display
and press Enter.
7. At the Display Physical File Member (DSPPFM) display screen, press Enter.
E-mail 27
8. On the next display screen, there will be a long string of numbers for each piece of mail. Copy the
seventh through twenty-sixth characters.
9. Press F3 twice to exit.
10. Type RCVDST (the Receive Distribution command) and press Enter.
11. In the Distribution Identifier field, paste the seventh through twenty-sixth characters you copied.
12. In the File to receive output field, enter a new file name and the same library name you used
previously and press Enter.
13. Type DSPPFM (Display Physical File Member) to display the file you just created.
14. Press F20 (Shift + F8) to scroll left and read the message or messages.
Related tasks
“Using Systems Network Architecture distribution services to send e-mail” on page 24
You can send e-mail from your system using a System Network Architecture distribution services
(SNADS) client program.
Managing e-mail
As an experienced user or administrator, you can manage e-mail servers, users, and messages to ensure
distribution of e-mail in your network.
One of the most common problems with e-mail is that the proper servers are not started. Perform the
following procedure in iSeries Navigator to verify the status of the servers:
1. In iSeries Navigator, expand your system → Work Management → Server Jobs.
2. Verify that the SMTP server is active. Find Qtsmtp jobs in the Job Name column of the Active Server
Jobs list.
3. If there are no Qtsmtp jobs listed, start the SMTP servers.
4. Verify that the Mail Server Framework server is active. Find Qmsf jobs in the Job Name column of
the Active Server Jobs list.
5. If there are no Qmsf jobs listed, type STRMSF (the Start the Mail Server Framework command) in the
character-based interface.
6. Verify that the POP server is active. Find Qtpop jobs in the Job Name column of the Active Server
Jobs list.
7. If there are no Qtpop jobs listed, start the POP servers.
8. Verify that the SNADS server is active. Find Qsnads jobs in the Job Name column of the Active
Server Jobs list.
9. If no QSNADS jobs are listed, start SNADS. In the character-based interface, type STRSBS QSNADS.
To remove an e-mail user from the i5/OS operating system, you must delete this system distribution
directory entry.
1. In the character-based interface, type WRKDIRE (the Work with Directory Entries command). The
System Distribution Directory display appears.
2. Tab down until you are in the Opt field by the user you want to delete.
3. Type a 4 (Remove) and press Enter. Press Enter again to confirm. This prevents any more e-mail from
being delivered to the user’s POP mailbox.
4. Sign on to a POP mail client program as that user. Receive and delete any e-mail.
Simple Mail Transfer Protocol (SMTP) can be configured to split large messages into smaller pieces.
However, many mail clients cannot reassemble the pieces, resulting in unreadable messages. If you find
that your recipients cannot read large messages because they are broken into several pieces, you might
want to disable the SMTP splitting function.
Note: Turning e-mail message splitting off might cause problems when sending large e-mail to networks
that cannot handle large messages.
Related concepts
“Troubleshooting e-mail” on page 39
This information is designed to help you solve problems related to e-mail that you might experience.
Delivery Status Notification allows your mail clients to request to receive status messages when mail is
delivered, relayed, or fails. If you want to allow your mail clients to make this request, you must enable
Delivery Status Notification.
Notes:
E-mail 29
1. Using Delivery Status Notification takes up resources that can affect the maximum number of
recipients on a piece of e-mail.
2. You are only allowing Delivery Status Notification to be employed by your users. If users
want to use the Delivery Status Notification function, they must set the parameters in their
mail clients. The parameters vary from mail client to mail client.
When hosting Domino and SMTP servers on the same system, you should bind each server to an IP
address. Mail is then sent to users of Domino or SMTP using the appropriate IP address and although it
shares a port, the mail is only handled by the system for which it is intended.
To force the SMTP server to use a specific Internet address, follow these steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Right-click SMTP and select Properties.
3. Click the Bindings tab.
4. Select the Use all interfaces radio button to bind all interfaces to port 25.
5. Select the Select an interface radio button to specify the client and server bound interfaces that you
would like to bind.
Note: If you want to use network address translation (NAT) either on the system or on your firewall,
you must force the i5/OS SMTP client to use one specific Internet address.
6. Click OK.
Now, SMTP receives only mail that is addressed to this Internet address. Check the Domain Name
System (DNS) server, local host table, and system distribution directory to ensure that this forced Internet
address is present.
Refer to the Lotus Domino Reference Library for instructions on how to bind Domino SMTP to a
specific TCP/IP address.
Related concepts
IP filtering and network address translation (NAT)
When hosting Domino LDAP and Directory Server on the same system, you can either set a different
port number for each server or you can bind each server to an IP address. Changing the port number can
be disruptive to your clients, so specifying a specific IP address for each server might be the best
solution. Domino and Simple Mail Transfer Protocol (SMTP) each use the appropriate LDAP server for
e-mail addressing.
To force the Directory Server to use a specific Internet address, follow these steps:
1. In iSeries Navigator, select your system → Network → Servers → TCP/IP.
2. Right-click Directory and select Properties.
3. Click the Network tab.
4. Click IP Addresses.
5. Select Use selected IP addresses and specify from the list which interfaces you want to bind.
Your SMTP server might be busy because it uses all its capacity for adding and ending prestart jobs for
each e-mail request.
If you find that the number of prestart jobs is affecting system performance, you can set the threshold
lower. If you want more jobs, you can set the number of prestart jobs higher.
With prestart jobs, every e-mail request runs as its own job. This method allows each job to focus solely
on its client or server program’s needs and requests. Each job can make longer time-out calls to enable
the posting of host names for the purpose of not receiving unsolicited bulk e-mail.
To manage a busy SMTP server, you can change the following values:
v The number of jobs to start on initialization
v A threshold number for jobs
v The number of jobs to add when the system reaches the threshold
v A maximum for the number of running jobs to allow
v Selecting a subsystem for jobs
To manage a busy system, you need to change values on the SMTP server and the SMTP client.
The SMTP server works with the daemon and prestart jobs: QTSMTPSRVD and QTMSMTPSRVP. The
SMTP client works with the daemon and prestart jobs: QTSMTPCLTD and QTSMTPCLTP.
Prompt Value
Subsystem QSYSWRK
Library QSYS
Program QTMSSRCP
Library QTCP
Start jobs *SAME
Initial number of jobs 4
Threshold 2
Additional number of jobs 2
Maximum number of jobs 20
E-mail 31
These values guarantee that the system starts four prestart jobs, starts two additional jobs when the
available jobs fall below two, and allows a maximum of twenty prestart jobs.
Prompt Value
Subsystem QSYSWRK
Library QSYS
Program QTMSSRCP
Library QTCP
Start jobs *SAME
Initial number of jobs 4
Threshold 2
Additional number of jobs 2
Maximum number of jobs 20
These values guarantee that the system will start four prestart jobs, start two additional jobs when the
available jobs fall below two, and allow a maximum of twenty prestart jobs.
Prompt Value
Subsystem QSYSWRK
Library QSYS
Program QTMSCLCP
Library QTCP
Start jobs *SAME
Initial number of jobs 4
Threshold 2
Additional number of jobs 2
Maximum number of jobs 20
These values guarantee that the SMTP client starts four prestart jobs, starts two additional jobs when the
available jobs fall below two, and allows twenty prestart jobs as the maximum.
Selecting new subsystem for Simple Mail Transfer Protocol server jobs
Use this procedure to select new subsystem for Simple Mail Transfer Protocol (SMTP) server jobs
The program will check for existence of the specified subsystem. If it does not exist, the program will
create it along with routing table entries, auto-start job entries, pre-start job entries and job descriptions.
Even if the subsystem does not already exist, the library for the subsystem description and job queue
must already exist. When the startup job for the server is processed, it will specify the parameters for the
newly created subsystem and then submit the server jobs for batch startup in that subsystem.
Protocol information
v Simple Mail Transfer Protocol (SMTP)
v Post Office Protocol (POP)
The following table provides the definitions for abbreviations used in journal entries.
Abbreviation Definition
LIN Local in, received a note for local delivery. The IP
address that follows is the host that sent the note.
RIN Relay in, received a note to relay to another SMTP
daemon. The IP address that sent it follows.
R Recipient
O Originator
U Undelivered recipient
QTMSINQ Input queue of SMTP
QTMSOUTQ Output queue of SMTP
QTMSBSSQ Holding queue where messages are placed when system
storage threshold is exceeded.
QTMSRTQ1 First level retry queue
QTMSRTQ2 Second level retry queue
RRSL Recipient resolved
Each journal entry has a two-character SubTypes or codes preceding it. The first character of the
SubTypes or code consists of the function identifier for the entry. The second character of the SubTypes or
E-mail 33
codes consists of the action that this journal entry is documenting. The function identifiers are listed in
the following table.
The following tables provide more detailed information about reading the component journal entries.
They are divided as follows:
v “Log entries for the SMTP client”
v “Log entries for the SMTP server” on page 35
v “Log entries for the bridge server” on page 36
v “Message Switching Facility (MSF) exits and creates functions” on page 36
Note: All of the journal entries documented here use the log entry (LG) type.
E-mail 35
Log entries for the bridge server
Type Action SubTypes or Codes Comments
LG Getting mail off of the IN 7A Log mail being dequeue
queue from QTMSINQ
LG Passing off mail to SNADS 7O Record successful transfer
to QSNADS
LG Putting container on the 7L Record when mail is
BUSY queue because of enqueued on QTMSBSSQ
space usage because of threshold
overflow
LG Getting mail off of BUSY 7M Record dequeuing mail
queue from QTMSBSSQ, space
was reclaimed and the mail
can now be processed
LG Passing message to MSF 7H Record when message gets
71 inserted into framework
72
LG Creation of COD message 7R Record when COD message
7G gets inserted into
framework Log the MSF
MSGID because the new
COD message is being
created
LG Cannot deliver this piece of 7P Log the fact that you were
mail to a recipient 7G creating an undeliverable
notice Log the MSGID of
the new undeliverable msg
notice
Related tasks
“Checking component journals” on page 40
You can check journals that record errors to determine how to solve a particular e-mail problem.
E-mail 37
SMTP commands
The following table describes the SMTP commands, the command functions, and whether the i5/OS
SMTP server supports the commands.
Related concepts
“Scenario: Sending and receiving e-mail locally” on page 3
This scenario demonstrates how e-mail is processed between local users.
The client software uses commands called verbs to communicate with the POP server. The i5/OS POP
server supports the following verbs.
Related concepts
“Scenario: Sending and receiving e-mail locally” on page 3
This scenario demonstrates how e-mail is processed between local users.
“Post Office Protocol on i5/OS” on page 3
The Post Office Protocol (POP) server is the i5/OS implementation of the Post Office Protocol Version
3 mail interface.
Troubleshooting e-mail
This information is designed to help you solve problems related to e-mail that you might experience.
Related tasks
“Preventing large e-mail messages from splitting” on page 29
You might need to prevent your large e-mail messages from splitting, and being delivered in smaller,
confusing pieces.
To identify likely sources of Simple Mail Transfer Protocol (SMTP) problems, follow these steps:
1. Verify that TCP/IP is configured for e-mail.
a. Ensure that any required PTFs are installed.
b. Check e-mail servers to ensure that the necessary servers are started and running.
2. Verify the local domain name.
a. In iSeries Navigator, expand your system → Network.
b. Right-click TCP/IP Configuration and select Properties.
c. Click the Host Domain Information tab and verify the local domain name.
3. Set the SMTP retry values lower.
a. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
b. Double-click SMTP.
c. Click the Outbound Mail Retries tab.
4. Verify that the user ID and address of the receiver are in the system distribution directory.
a. In iSeries Navigator, expand your system → Users and Groups → All Users.
b. Right-click the Profile of the user ID and select Properties.
c. Click Personal, and go to the Mail tab to verify the address.
E-mail 39
5. Verify whether a host table entry is necessary for the e-mail to reach the destination address.
a. In the character-based interface, type CHGTCPHTE (the Change TCP/IP Host Table Entry command)
and enter the e-mail server’s Internet address.
b. If no host table entry appears, then enter the host name for that Internet address.
6. Ensure you have not exceeded your storage threshold
a. In iSeries Navigator, expand your system → Configuration and Service → Hardware → Disk Units →
Disk Pools.
b. Right-click the source disk pool that you want to view and select Properties.
c. Select the Capacity tab.
d. If your system usage is greater than your threshold, mail might stop working. For more
information, refer to Independent disk pools in the Backup and recovery topic.
7. Verify that e-mail splitting is disabled.
a. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
b. Double-click POP. The POP Properties dialog appears.
c. Click the Configuration tab.
d. For the Message Split Size field, verify No maximum is selected.
8. Run the Trace TCP/IP Applications command. In the character-based interface, type TRCTCPAPP.
9. Check component journals to locate the problem.
Related concepts
“Controlling e-mail access” on page 6
You should control who accesses your system through e-mail to protect your data from malicious
attacks.
Independent disk pool examples
“Controlling Post Office Protocol access” on page 7
To ensure the security of your system, you should control Post Office Protocol (POP) access.
“Solving problems with the QtmmSendMail API” on page 42
You can use this troubleshooting process to resolve problems that you are having with the Send
MIME Mail (QtmmSendMail) API.
Related tasks
“Checking e-mail servers” on page 28
Before using your e-mail servers, you need to verify the status of e-mail servers and make sure that
they are all running.
“Configuring TCP/IP for e-mail” on page 10
You need to set up TCP/IP before you can configure e-mail on your i5/OS operating system.
“Checking mail server framework jobs” on page 43
You should check mail server framework jobs in the QSYSWRK system to determine a possible cause
of the error in the QtmmSendMail API.
“Checking component journals”
You can check journals that record errors to determine how to solve a particular e-mail problem.
“Tracking undelivered e-mail” on page 41
You can use a generic user ID to track problems with undeliverable e-mail. This method can be useful
for both e-mail delivery and configuration problems.
Related information
Journal records are stored in journal receivers. These receivers are user managed. When the journal
becomes full, issue the Change Journal (CHGJRN) command to change to a new journal receiver. The
new SMTP Journaling function uses the QZMF journal.
To turn on journaling and view the journal contents, follow these steps:
1. In iSeries Navigator, expand your system → Network → Servers → TCP/IP.
2. Double-click SMTP. The SMTP properties dialog opens.
3. Click the General tab.
4. Select the Enable journal entries check box.
5. Open an emulation session.
6. To convert the SMTP journal entries to a viewable form, in the character-based interface, type: DSPJRN
JRN(QZMF) OUTPUT(*OUTFILE) OUTFILE(jrnlib/zmfstuff) OUTMBR(MAR2) ENTDTALEN(512), where jrnlib
is the name of the library, and zmfstuff is the name of the physical file.
7. To view the SMTP journal entries, type DSPPFM FILE(jrnlib/zmfstuff) MBR(MAR2)on the command
line.
8. Press F20 (Shift + F8) to see the journal-specific information.
Related concepts
“Determining problems with e-mail” on page 39
You can use simple steps to determine what is causing a problem with e-mail.
Related reference
“Mail server journal entries” on page 33
This information might help you understand the codes and messages used in journal entries.
E-mail 41
Note: The user ID you enter must be an actual ID so that it can effectively monitor nondelivery notices.
The sender receives a copy of the nondelivery notice with a list of the recipients who did not
receive the e-mail.
Related concepts
“Determining problems with e-mail” on page 39
You can use simple steps to determine what is causing a problem with e-mail.
You might encounter errors that are returned with the QtmmSendMail API. This table provides
descriptions of error messages that are returned byQtmmSendMail API.
Table 1. Error messages for QtmmSendMail API
CPFA0A9 The object was not found.
CPFA0CE The path name parameter that was specified resulted in an error.
CPF3C12 The length of data is not valid.
CPF3C17 An error occurred with input data parameter.
CPF3C21 The format name (name) is not valid.
CPF3C39 The value for the reserved field is not valid.
CPF3C75 An error occurred with entry lengths and offsets parameter.
CPF3C88 The number of variable length records &1 is not valid.
CPF3E0A The resource limits were exceeded.
Related concepts
“Determining problems with e-mail” on page 39
You can use simple steps to determine what is causing a problem with e-mail.
Related reference
“QtmmSendMail API” on page 21
You can use the Send MIME Mail (QtmmSendMail) API to send e-mail from an i5/OS program.
If you code to return the error, then the program returns it to the program. However, if you set this value
to 0, as shown in the following examples, then the error appears on your workstation display.
C example
Qus_EC_t Snd_Error_Code;
Snd_Error_Code.Bytes_Provided=0;
RPG example
DAPIError DS
D APIBytes 1 4B 0
D CPFId 9 15
C Eval APIBytes = 0
| Note: See section 2.1 in RFC2822 (http://rfc.net/rfc2822.html) for more information about the
| end-of-header statement.
Manuals
Read about the framework that drives the i5/OS mail server.
IBM Redbooks
v AS/400 Internet Security: Protecting Your AS/400 from HARM in the Internet (about 2160 KB)
This Redbook provides security information, including steps for cleaning up your i5/OS operating
system if your system is the victim of a overwhelming attack.
Web sites
v Support for IBM System i
E-mail 43
Download current PDFs for your i5/OS operating system by using your workstation as a gateway to
the Internet PTF page, or view i5/OS solutions from the Technical Information and Databases category.
v RFC Index
The e-mail protocols are defined in RFCs (Request for Comments). RFCs are the vehicles that are used
to define evolving Internet standards. For additional information about the SMTP protocol, refer to
RFC 2821. For the POP protocol, refer to RFC 1725.
Other information
v Lotus Documentation
| You need Adobe Reader installed on your system to view or print these PDFs. You can download a free
| copy from the Adobe Web site (www.adobe.com/products/acrobat/readstep.html) .
IBM may not offer the products, services, or features discussed in this document in other countries.
Consult your local IBM representative for information on the products and services currently available in
your area. Any reference to an IBM product, program, or service is not intended to state or imply that
only that IBM product, program, or service may be used. Any functionally equivalent product, program,
or service that does not infringe any IBM intellectual property right may be used instead. However, it is
the user’s responsibility to evaluate and verify the operation of any non-IBM product, program, or
service.
IBM may have patents or pending patent applications covering subject matter described in this
document. The furnishing of this document does not grant you any license to these patents. You can send
license inquiries, in writing, to:
IBM Director of Licensing
IBM Corporation
North Castle Drive
Armonk, NY 10504-1785
U.S.A.
For license inquiries regarding double-byte (DBCS) information, contact the IBM Intellectual Property
Department in your country or send inquiries, in writing, to:
IBM World Trade Asia Corporation
Licensing
2-31 Roppongi 3-chome, Minato-ku
Tokyo 106-0032, Japan
The following paragraph does not apply to the United Kingdom or any other country where such
provisions are inconsistent with local law: INTERNATIONAL BUSINESS MACHINES CORPORATION
PROVIDES THIS PUBLICATION “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS
OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
NON-INFRINGEMENT, MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Some
states do not allow disclaimer of express or implied warranties in certain transactions, therefore, this
statement may not apply to you.
This information could include technical inaccuracies or typographical errors. Changes are periodically
made to the information herein; these changes will be incorporated in new editions of the publication.
IBM may make improvements and/or changes in the product(s) and/or the program(s) described in this
publication at any time without notice.
Any references in this information to non-IBM Web sites are provided for convenience only and do not in
any manner serve as an endorsement of those Web sites. The materials at those Web sites are not part of
the materials for this IBM product and use of those Web sites is at your own risk.
IBM may use or distribute any of the information you supply in any way it believes appropriate without
incurring any obligation to you.
Licensees of this program who wish to have information about it for the purpose of enabling: (i) the
exchange of information between independently created programs and other programs (including this
one) and (ii) the mutual use of the information which has been exchanged, should contact:
IBM Corporation
Such information may be available, subject to appropriate terms and conditions, including in some cases,
payment of a fee.
| The licensed program described in this information and all licensed material available for it are provided
| by IBM under terms of the IBM Customer Agreement, IBM International Program License Agreement,
| IBM License Agreement for Machine Code, or any equivalent agreement between us.
Any performance data contained herein was determined in a controlled environment. Therefore, the
results obtained in other operating environments may vary significantly. Some measurements may have
been made on development-level systems and there is no guarantee that these measurements will be the
same on generally available systems. Furthermore, some measurements may have been estimated through
extrapolation. Actual results may vary. Users of this document should verify the applicable data for their
specific environment.
Information concerning non-IBM products was obtained from the suppliers of those products, their
published announcements or other publicly available sources. IBM has not tested those products and
cannot confirm the accuracy of performance, compatibility or any other claims related to non-IBM
products. Questions on the capabilities of non-IBM products should be addressed to the suppliers of
those products.
All statements regarding IBM’s future direction or intent are subject to change or withdrawal without
notice, and represent goals and objectives only.
This information contains examples of data and reports used in daily business operations. To illustrate
them as completely as possible, the examples include the names of individuals, companies, brands, and
products. All of these names are fictitious and any similarity to the names and addresses used by an
actual business enterprise is entirely coincidental.
COPYRIGHT LICENSE:
This information contains sample application programs in source language, which illustrate programming
techniques on various operating platforms. You may copy, modify, and distribute these sample programs
in any form without payment to IBM, for the purposes of developing, using, marketing or distributing
application programs conforming to the application programming interface for the operating platform for
which the sample programs are written. These examples have not been thoroughly tested under all
conditions. IBM, therefore, cannot guarantee or imply reliability, serviceability, or function of these
programs.
Each copy or any portion of these sample programs or any derivative work, must include a copyright
notice as follows:
© (your company name) (year). Portions of this code are derived from IBM Corp. Sample Programs. ©
Copyright IBM Corp. _enter the year or years_. All rights reserved.
If you are viewing this information softcopy, the photographs and color illustrations may not appear.
| AIX
| AS/400
| Domino
| eServer
| i5/OS
| IBM
| IBM (logo)
| Infoprint
| iSeries
| Lotus
| Lotus Notes
| Notes
| OfficeVision
| OS/400
| Redbooks
| System i
| The Output of e-business
Microsoft, Windows, Windows NT, and the Windows logo are trademarks of Microsoft Corporation in the
United States, other countries, or both.
Java and all Java-based trademarks are trademarks of Sun Microsystems, Inc. in the United States, other
countries, or both.
Other company, product, and service names may be trademarks or service marks of others.
Personal Use: You may reproduce these publications for your personal, noncommercial use provided that
all proprietary notices are preserved. You may not distribute, display or make derivative works of these
publications, or any portion thereof, without the express consent of IBM.
Commercial Use: You may reproduce, distribute and display these publications solely within your
enterprise provided that all proprietary notices are preserved. You may not make derivative works of
these publications, or reproduce, distribute or display these publications or any portion thereof outside
your enterprise, without the express consent of IBM.
Except as expressly granted in this permission, no other permissions, licenses or rights are granted, either
express or implied, to the publications or any information, data, software or other intellectual property
contained therein.
IBM reserves the right to withdraw the permissions granted herein whenever, in its discretion, the use of
the publications is detrimental to its interest or, as determined by IBM, the above instructions are not
being properly followed.
You may not download, export or re-export this information except in full compliance with all applicable
laws and regulations, including all United States export laws and regulations.
Appendix. Notices 47
IBM MAKES NO GUARANTEE ABOUT THE CONTENT OF THESE PUBLICATIONS. THE
PUBLICATIONS ARE PROVIDED ″AS-IS″ AND WITHOUT WARRANTY OF ANY KIND, EITHER
EXPRESSED OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF
MERCHANTABILITY, NON-INFRINGEMENT, AND FITNESS FOR A PARTICULAR PURPOSE.
Printed in USA