Re: Handling of abusive DNSBL/WL clients
Matthias Leisi <[email protected]>
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <CALgnk9rFb23WFK5bTM8zxvMAjOArva2+nQa09zogwhFiPneBOw@mail.gmail.com> |
On Thu, Dec 22, 2011 at 5:06 PM, Chris Lewis <[email protected]> wrote: > The DNSBL shutdown process would _also_ be perfectly appropriate for > blocking abusive DNS queries, _without_ listing the world, _and_ by its very > nature shedding the abusive queries. Note that the case referred to by the OP is not about shutting down a DNSxL, but about signaling to client applications (and resolvers/forwarders) that their use is considered not acceptable by the operator of the service. Unfortunately, a straightforward REFUSED rcode results in a three-fold increase in queries due to retries in most cases. A dedicated return value which would cause at least certain applications to at least temporarily suspend queries is helpful. -- Matthias