Re: educating rDNS violators

From: Derek Schaible (dschaible_at_cssiinc.com)
Date: 08/25/04

  • Next message: Derek Schaible: "Re: educating rDNS violators"
    To: security-basics@securityfocus.com
    Date: Wed, 25 Aug 2004 14:20:25 -0400
    
    
    

    On Wed, 2004-08-25 at 13:55, someone wrote:
    >
    > This becomes even further complicated if a company is hosting with
    > somebody who provides "virtual domain" mail hosting. The server could
    > be mail.somefamily.net, but have a reverse DNS entry that points to
    > mail.myprovider.net. How is that invalid? Just because the records
    > don't match doesn't make me a spammer!

    > > Mail servers should have correct DNS info. Forward and reverse. It is
    > > the sysadmin's responsibility to ensure that their systems are
    > > configured properly. Period.

    I wanted to respond to this point to the list before I get flooded with
    similar replies.

    True, such a situation does not make you a spammer but using a virtual
    domain will in no way impact the reverse DNS of the smtp server from
    which the email is delivered. Reverse DNS is not matching the address of
    the smtp server to the domain name in the email address. This would
    break many things like reply-to, etc.

    All it is doing is verifying that the server is who it claims to be.
    Virtual mail domains are not impacted. I run many virtual email domains
    as well for every website we host. These accounts can happily send mail
    through our company's SMTP server, arrive in tact and survive an rDNS
    lookup.

    As I've stated earlier, filtering out mail from servers with a bad rDNS
    will dramatically reduce your spam and that's a fact to live by. There
    is always a means in which you can configure a valid email system that
    will pass this test. Some require more imagination than others, but it
    can always be done and should always be done if you want to guarantee
    that your mail will be delivered and not rejected.

    -- 
    Derek Schaible <dschaible@cssiinc.com>
    CSSI, Inc.
    
    



  • Next message: Derek Schaible: "Re: educating rDNS violators"

    Relevant Pages

    • Re: Basic Questions about Reverse DNS
      ... Your Email SMTP server can report any name ... Every example I've seen of Reverse DNS shows only one hostname per IP ... You should only have a single reverse DNS entry for each IP address. ...
      (microsoft.public.windows.server.dns)
    • Re: Reverse DNS
      ... to have the same IP address associated with many A records, only one PTR ... What your ISP is doing is allowing ... there is a choice of only setting up reverse DNS on the IP ... name to match the HELO name of the SMTP server no matter ...
      (microsoft.public.windows.server.dns)
    • Re: Basic Questions about Reverse DNS
      ... reverse DNS, I don't see how it can effectively prevent spam. ... Your Email SMTP server can report any name ... You should only have a single reverse DNS entry for each IP address. ...
      (microsoft.public.windows.server.dns)
    • Re: Basic Questions about Reverse DNS
      ... reverse DNS, I don't see how it can effectively prevent spam. ... Your Email SMTP server can report any name ... Every example I've seen of Reverse DNS shows only one hostname per IP ... You should only have a single reverse DNS entry for each IP address. ...
      (microsoft.public.windows.server.dns)
    • RDNS Required?
      ... Ok I've found where I can tell the SMTP server to do a Reverse DNS lookup. ... Also, is there a way to accept a message with a failed RDNS lookup, but send ...
      (microsoft.public.exchange.admin)