Re: SPF records and DKIM signatures on ubuntu/postfix/mailman
Volker Kuhlmann <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On Sat 15 Oct 2011 08:41:20 NZDT +1300, Mark Foster wrote: > +1. Was glad to move away from them to be honest. I had cable when I was > in Wellington for a while. It's all relative to the available alternatives, which are unfortunately lacking on the better side. Plenty on the worse side esp when it comes to latency (really matters for ssh, couldn't care less about games) and the cows will come home before I use xtra. > Think of it like SMTP. > There's essentially two types of DNS servers I see. You were thinking of serving recursive DNS requests from external to the ISP, I was thinking internal to the ISP so the security aspect didn't make sense. > from people who aren't paying customers. (How many people hardcoded > Xtra's DNS servers into their workstations, then changed ISP's and > continued to use Xtra's machines for lookups?) Well the reverse would hold too, but who in their right mind would *choose* to use xtra DNS? I had heaps of problems with pages not loading and resulting in a 404, but an immediate reload would load them fine. Problems went away when switching from xtra DNS to another one. (pfsense with DNS forwarder.) > I mentioned this because these policies can make it hard to externally > test DNS. For example I know Orcon's DNS platform rejects queries from > outside: Having a shell available somewhere else is very useful for investigating lots of things, but for querying other DNS servers it's not needed. Sure xtra, orcon, clear and a few smaller ones block requests from non-customers for domains they don't host, but there are plenty left in NZ who don't. For checking from overseas you can use the big public DNS servers from opendns (just spot their ad server and replace that with NXDOMAIN), cisco or google. The reason for blocking requests from non-customers has more to do with "why do something for the competition" than any security. At least xtra was doing it much earlier than the dns security issues you mention. Volker -- Volker Kuhlmann is list0570 with the domain in header. http://volker.dnsalias.net/ Please do not CC list postings to me. _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug