Re: SPF records and DKIM signatures on ubuntu/postfix/mailman

Mark Foster <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <[email protected]>
On 15/10/11 11:39, Volker Kuhlmann wrote:
> On Sat 15 Oct 2011 08:41:20 NZDT +1300, Mark Foster wrote:
>
>> +1. Was glad to move away from them to be honest. I had cable when I was
>> in Wellington for a while.
> It's all relative to the available alternatives, which are unfortunately
> lacking on the better side. Plenty on the worse side esp when it comes
> to latency (really matters for ssh, couldn't care less about games) and
> the cows will come home before I use xtra.

I still have some resources hosted with a friend in Wellington who's on
Cable. I'm relatively happy that we don't need to engage their tech
support often, and that it 'just works' most of the time. 

>> from people who aren't paying customers. (How many people hardcoded
>> Xtra's DNS servers into their workstations, then changed ISP's and
>> continued to use Xtra's machines for lookups?)
> Well the reverse would hold too, but who in their right mind would
> *choose* to use xtra DNS? I had heaps of problems with pages not loading
> and resulting in a 404, but an immediate reload would load them fine.
> Problems went away when switching from xtra DNS to another one. (pfsense
> with DNS forwarder.)
Plenty of people threw Alien and Terminator (or one or the other) into
their systems in order to present some sort of redundancy, or simply
because they knew what their IP's were off the top of their head.
I saw this many times when working for both Xtra and for other ISPs in
support roles in the early 2000s.

>> I mentioned this because these policies can make it hard to externally
>> test DNS.  For example I know Orcon's DNS platform rejects queries from
>> outside:
> Having a shell available somewhere else is very useful for investigating
> lots of things, but for querying other DNS servers it's not needed. Sure
> xtra, orcon, clear and a few smaller ones block requests from
> non-customers for domains they don't host, but there are plenty left in
> NZ who don't. For checking from overseas you can use the big public DNS
> servers from opendns (just spot their ad server and replace that with
> NXDOMAIN), cisco or google.

Yeah there's a few options, but in particular I found that a complaint
from an Orcon customer that (xyz website doesn't resolve) was very hard
to troubleshoot without being able to do my own DNS queries against
their servers.
One of the reasons that blocking external resolver lookups causes
problems for support techs.


> The reason for blocking requests from non-customers has more to do with
> "why do something for the competition" than any security. At least xtra
> was doing it much earlier than the dns security issues you mention.
>

Actually I don't believe so; for a long time Alien and Terminator were
the 'only' DNS servers operated by Xtra; both hosting and
resolver-purposed. This meant the machines had to remain wide-open to
cater for queries against the hosted domains.
It was relatively recently that they changed the auto-assigned-DNS
servers for customers on Dialup and DSL to try to share the load, as the
machines were struggling (and it was a very obvious SPOF when the
machines fell over) - and it also causes problems when hosted domains
are transferred and stale DNS entries remain...

Mark.

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.