Re: educating rDNS violators

JGrimshaw_at_ASAP.com
Date: 08/23/04

  • Next message: Chris Olave: "Re: educating rDNS violators"
    Date: Mon, 23 Aug 2004 14:24:50 -0500
    
    

    I was under the impression that reverse DNS for the Internet was
    essentially broken, due to several large ISPs not necessarily implementing
    reverse DNS for their many subnetted customers.

    With that in mind, with many customers using large ISPs for their public
    DNS service, a updating the bounce back message might not resolve
    anything, as the emailing site may not be in the authority to make the
    changes you have requested, and the large ISP may not have the
    wherewithall to implement such policies.

    While I agree that the reverse lookup is trivial to set up and likely
    should be setup, but it breeds complexity when outsourced to another
    vendor for management.

    SMiller@unimin.com
    08/18/2004 04:49 PM

    To
    security-basics@securityfocus.com
    cc

    Subject
    educating rDNS violators

    Our mail administration group recently implemented blocking of all
    incoming
    messages from domains that cannot be resolved via reverseDNS, for purposes
    of spam prevention. Of course, there are quite a number of legitimate
    business contacts who do not have rDNS properly configured. Assuming that
    the rDNS criterion remains, the question becomes one of who will notify
    and/or educate the sender(s) about this issue. The only time-efficient
    way
    that I can think of to do this would be to have instructions and
    references
    in the body of the bounce message itself. Anyone tried that? Results?
    Other suggestions? Thanks in advance.

    Scott

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class
    sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills
    of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.securityfocus.com/sponsor/InfoSecInstitute_security-basics_040817

    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------


  • Next message: Chris Olave: "Re: educating rDNS violators"

    Relevant Pages

    • Re: IP address allocation
      ... They may also do reverse DNS for sanity sake. ... Is it common practice for ISPs to allocate a block of ... xxx.8-xxx.15 is assigned to the customer. ...
      (Security-Basics)
    • Re: Running own servers
      ... > Without your ISPs assistance, you wouldn't be able to run reverse DNS ... need rDNS. ...
      (freebsd-questions)
    • Re: AAAAARRGGGHHHH!!!!!!!
      ... Reverse DNS on mail.ABC.com - your ISP will do this for no charge. ... > My company hosts email for a number of different domains. ... > of the domains (ISPs) having problems include AOL, ...
      (microsoft.public.exchange.admin)
    • RE: educating RDNS violators
      ... Besides the argument of "My isp does not allow RDNS", more significantly, ... Reverse DNS is *NOT* are requirement for SMTP transmissions as per rfc822. ... So until the IETF proposes a draft which revises the rfc or is superseded by ... an "implied" violation of rfc822. ...
      (Security-Basics)
    • Re: genuine bulk email
      ... several virtual hosts ie we have more than one domain name so the reverse DNS is not clear to me. ... Is the from address inspected for comparison with the RDNS ie if I claim to be sending from xxx.com should my RDNS point back to xxx.com? ... the sales people manually enter all the details. ...
      (freebsd-questions)