Re: SPF records and DKIM signatures on ubuntu/postfix/mailman
Martin D Kealey <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 15 Oct 2011, Volker Kuhlmann wrote: > The reason for blocking requests from non-customers has more to do with > "why do something for the competition" than any security. There are exploits in the wild that can poison a DNS cache, based on guessing (read "brute-forcing") request ID numbers. A good way to guard against your ISPs resolver cache getting poisoned is simply not to use it: run your own resolver instead. But most people won't do that. Restricting requests to "just customers" will cut by three orders of magnitude the number of 'bots that can attack you. (Or at least, it will if you're a "small" ISP, being one whose customers comprise less than 0.1% of worldwide internet users, which includes every ISP in NZ including Xtra.) Another way to reduce the chances of an attack succeeding is to use different outgoing IP addresses for incoming and outgoing queries. Running many small DNS caches behind a load balancer (rather than just a few large ones) also helps. -Martin _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug