O Apply the Same Filtering Rules to Secondary MX Servers

Unless you want to face a queue management nightmare, secondary mail exchangers should always apply the same filtering and validation policies as the primary servers. If feasible in your environment, user validation on external servers can be safely performed via LDAP or other databases hooks; check your MTA documentation for all possible options.

Designing and implementing a secure way of allowing an external server (a secondary or tertiary MX server may be residing in a foreign LAN) to access your authentication system is also important: LDAP, Active Directory, Novell...

