Re: Welcome to the new(ish) ASRG list
Rob McEwen <[email protected]>
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 3/17/2013 12:48 AM, Roger B.A. Klorese wrote: > On 3/16/13 8:17 PM, Rob McEwen wrote: >> On 3/16/2013 7:53 PM, Chris wrote: >> (1) get strongly behind *requiring* FCrDNS for IPs sending >> NON-authenticated mail (i.e. "last external" MTA) >> > I fail to see any way in which this adds legitimacy, as long as the > rDNS is legitimate. And in the case of my non-profit discussion and > announcement server, from which we deliver on behalf of 80+ > organizations, the cost of 80+ IP addresses, and the need to support > 80+ virtual interfaces (and throttle simultaneous sending behavior on > them) would probably put us under. Chris, I think you're reading into this more requirements than what I suggested. First, FCrDNS ensures that the rDNS is transparent or honest (keeping in mind that an "honest" spammer could still send spam through such IPs!). Also, who said anything about any kind of requirement that the FCrDNS must match the domain in the "from" address? instead, if is more important that it properly represents YOU as the valid sending agent for these 80+ organizations. Then, all you need is one IP, and one host name. Ultimately, YOU are singularly responsible for what comes from YOUR ip address! Therefore, it makes sense for the rDNS to represent your domain name, not your client's domains. PS - I should have added to my original short of list of suggestions... one more thing... that there be an industry standard for what constitutes the formatting of an ISP's dynamically assigned IP. There already is sort of a general common pattern for this for IPv4 where lots of hypens and dots to the left of the domain name in the rDNS indicate a dynamic IP... this is such a common pattern in IPv4 that some anti-spam plugins actually add points to the spam score based on this. Yet, still, many break this rule in IPv4. But perhaps it isn't too late for IPv6 to come up with some kind of standard rDNS formatting for dynamic-assigned IPs vs mail-sending IPs. (I would guess that this is already taking shape just from following IPv4's lead, even if not officially so.) Certainly, if... 15 years ago... all of us had a discussion about IPv4 rDNS formatting... and had there been a movement towards blocking ALL IPs that had lost of hypens and dashes to the left of the domain name in the rDNS... then blocking botnet spam would have been MUCH easier all these years... and MUCH fewer mail admins would have allowed their rDNS to be so poorly formatted. So... why not do that with IPv6 EARLY IN THE PROCESSES? (ADD THIS TO MY EARLIER LIST OF SUGGESTIONS) -- Rob McEwen http://dnsbl.invaluement.com/ [email protected] +1 (478) 475-9032