Re: IPv6 recap
Alessandro Vesely <[email protected]>
| Newsgroups | gmane.mail.imap.courier.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, the IPv6 MX being secondary, no compliant sender should choose it unless it has IPv6 connections only. Best Ale On Tue 26/Mar/2024 15:36:08 +0100 Adam Augustine wrote: > Hello Ale, > > I am mildly surprised that you haven't seen any IPv6 traffic yet. When I did my > testing most traffic to or from the big email providers seemed to use IPv6 for > the most part. Microsoft cloud-based email exchanges (see what I did there?) > particularly stick out in my mind as being predominantly IPv6, but I seem to > recall a fair number of Gmail connections being IPv6 as well. But all this was > a few years ago. > > I may have misrepresented the one user's reaction to my testing. He only > eventually noticed the IPv6 addresses when he happened to look at the > "Received:" headers while looking for the "Delivered-To" header. And this was > more than a year after I had started and forgotten to end my test. There is > nothing in the email addresses themselves that indicate whether it was > delivered via v4 or v6. > > Ah, good times, > Adam > > On 3/24/24 06:00, Alessandro Vesely wrote: >> Hi Adam, >> >> thanks for sharing your thoughts and experience. >> >> I ended up setting two new IPv6 addresses. One for outgoing mail, in ip6out >> and SPF record. The other for incoming, set in esmtpd's PORT variable and >> published as a secondary MX which only has an AAAA address. >> >> Thus far neither happened to be used. I prefer it so, because people is >> picky about unknown email addresses, and I don't send so much mail as to make >> my address(es) known. Increasing the number of addresses worsens low volume >> senders reputation. >> >> That differs from IPv6 usage for the web, where I regularly get IPv6 >> connection, sometimes reaching percentages as high as 4%. >> >> >> Best >> Ale >> >> >> On Sat 23/Mar/2024 00:49:52 +0100 Adam Augustine wrote: >>> Hello Ale, >>> >>> I have some practical experience with IPv6 environments. >>> >>> "Is it advisable to use different numbers (in the same /64) for outgoing >>> (ip6out) and incoming MX, esmtpd, esmtpd-msa, esmtpd-ssl, pop3d, pop3d-ssl, >>> imapd and imapd-ssl?" >>> >>> Short answer, do whatever makes things easy for you. >>> >>> Longer answer: >>> Despite what people say about "Everything is different in IPv6!" my >>> experience has been that 90% if not more of everything is exactly the same, >>> just with longer addresses. The remaining 10% or so that does change has >>> mostly to do with how IPv6 addresses get assigned in dynamic environments >>> (cases where you would use DHCP in the IPv4 world). You don't have to use >>> those functions if you don't want to. IPv6 was meant to be a drop-in >>> replacement for IPv4, and it actually works that way, assuming the >>> applications are coded correctly. >>> >>> I may or may not have tested IPv6 with Courier a few times on a production >>> system with a light but non-trivial load. It just worked. I may possibly >>> have accidentally left my test running for more than a year or so before >>> someone noticed and said something about the funny addresses. >>> >>> If you are already hosting all those services (SMTP, POP, IMAP, and their >>> encrypted counterparts) on a single IPv4 address and that is working for you >>> today, then follow the same operational pattern with IPv6. Think of it like >>> adding another network interface with a second IPv4 address. Would you do >>> anything different from what you are doing today in that scenario? Probably >>> not. So don't change anything and do IPv6 the same way. >>> >>> At least, at first. There /is/ a psychological barrier that you are going to >>> need to get over to get used to IPv6, and that barrier is just >>> unfamiliarity. Once you get comfortable and are used to looking at those >>> addresses as normal and fully accept that things work exactly the same as >>> they did with IPv4, start imagining what you could do if you had all the >>> IPv4 addresses you could ever possibly want and could waste them in >>> embarrassing ways. IPv6 gives you that, you just have a longer address. >>> >>> If it would makes your life easier to have a separate IPv4 address for each >>> service, then you can do that with IPv6. >>> >>> If it would make sense for you to have a separate IP address for /each and >>> every incoming and outgoing connection and never _ever_ re-use that address >>> again/, you can do that with IPv6. And only after 3,928 years would you need >>> another /64 subnet. And that is assuming a 100 gigabit ethernet network and >>> a single 64 byte packet representing each connection. So that's a lower bound. >>> >>> It is hard to break out of the "I must conserve" mindset of IPv4, so >>> exercises like that help open the mind to the possibilities. >>> >>> One bit of production roll-out advice I would give. You won't get traffic on >>> IPv6 until you publish the "AAAA" equivalent of the DNS "A" record for your >>> MX record. So don't create the "AAAA" record until you are ready to take >>> traffic on your IPv6 address. And when you do, set the TTL to something >>> short (60 seconds maybe). That way, if you do make a mistake in the >>> configuration somewhere, you can remove the "AAAA" and figure things out at >>> your leisure. Minimal impact. It is helpful in situations like if you forgot >>> to open the inbound port 25 on IPv6 in addition to the already open port 25 >>> on IPv4 on the firewall. Just an example. >>> >>> Anyway, I hope that is at least somewhat useful. And thanks for all the work >>> you do to keep my email flowing. You don't know it, but some of your posts >>> have really helped me over the years. >>> >>> Adam Augustine >>> >>> >>> On 3/20/24 09:18, Alessandro Vesely wrote: >>>> Hi all, >>>> >>>> I've always compiled Courier using the --without-ipv6 option. Now I've got >>>> some IPv6 addresses, so I'd try and enable IPv6 for mail. In order to keep >>>> behavioral changes to a minimum, I've already set IPv4 preference in >>>> /etc/gai.conf, and will leave courierd's ESMTP_PREFER_IPV6_MX commented out. >>>> >>>> What else? >>>> >>>> Is it advisable to use different numbers (in the same /64) for outgoing >>>> (ip6out) and incoming MX, esmtpd, esmtpd-msa, esmtpd-ssl, pop3d, pop3d-ssl, >>>> imapd and imapd-ssl? >>>> >>>> TIA for any hint >>>> >>>> Best >>>> Ale >> >> >> >> _______________________________________________ >> courier-users mailing list >> [email protected] >> Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users > > > > _______________________________________________ > courier-users mailing list > [email protected] > Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users _______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users