Re: DNSBL and IPv6
"John Levine" <[email protected]>
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
>The only relevant difference between v4 and v6 DNS based blacklisting is >that the ability to easily hop around *within* your /64 makes it >possible (easy) to blow the cache of a traditional caching DNS resolver >if you do naive "look up a record based on the IPv6 address". That's always been our assumption, but there is at this point precious little evidence that MTAs that query DNSBL through caches (as opposed to those who have a local rsync mirror) have a cache hit rate much greater than zero. If in fact they don't, the same design, perhaps with a little TTL tuning to give clients a hint about which ones are worth caching, could work no worse than they do now for similar mail volumes. That's why I want to do the cache simulations, to figure out what's going on now. It shouldn't be terribly hard, and we have people offering data. Want to help? R's, John