Since I use (and love) my SA/amavisd-new/postfix setup, I thought maybe
I would share this with you in the hopes that it might help.

In 2002, in frustration with DNS based RBL lists and their arbitrary and
sometimes capricious listings (I dared an RBL owner to list our ip's
stating that I never wanted to send any email to anyone stupid enough to
use his list.. He listed me despite web site stated reasons for listing
didn't include 'insulting the owner').  I think our one of our DNS
servers is listed as a dialup/dhcp ip in another list.

I created a DNS zone called 'blocked.secnap.net' for two reasons:
First, I wanted to see if someone would be silly enough to use an
arbitrary DNZ zone as an RBL without checking it out, and Second, to
make a point: don't use an RBL unless you understand their listing
policies, and if can be trusted.

I never announced it as an RBL, and every reputable RBL web site knew
this and listed it as a 'bogus' zone, or warned not to use it. (since a
wildcard zone would return positive on every ipv4 ip address in the
world, for the lusers reading this, that is every internet address in
the world that is not using the experimental ipv6 addressing: this means
YOU)

Four years later, we still see ip address lookups to that zone, and get
calls from people telling us we are blocking their email.

Even Mail-Abuse-1.025 on cpan, a perl module scans for listing in
blocked.secnap.net (again, even though we NEVER published ANY
information publicly suggesting its use as an RBL)

Since the only way our DNS based zone could be used to block email would
be a misconfiguration at the recipient mail server, and we don't have
access to that configuration file, we try to explain that we don't run a
blacklist, don't run that mail site and can't help them.

I would imagine that at some point in time, the administrator of that
mail server would notice two things:
#1, he would not be receiving any spam or viruses at all
#2, he would not be receiving ANY email at all.

Please check your postfix/SA/amavisd-new rules and make sure you don't
use blocked.secnap.net to filter email.
It is not a DNS based RBL, and if you use it, it will block 100% of all
email send by any ipv4 based ip address in the world.

Please do not call me or send email to SECNAP asking to be taken off our
'blacklist'.  We don't run a public blacklist, and you are not on it (if
it existed, which it doesn't).

Please check all RBL's you use (including those not disabled in SA).
Check their listing policies and delisting policies.

Reduce their score if you don't agree with their listing policies in
local.cf, or disable them.

Use only RBL's you trust, since there seems to be no standards body or
anyone checking these RBL's

For SECNAP's internal servers, we do use bl.spamcop.net,
bogusmx.rfc-ignorant.org and dsn.rfc-ignorant.org in postfix, and SOME
of the DNS based RBL's in SA.

Please doublecheck before using anything that will block legitimate
email.

-- 
Michael Scheidell, CTO
561-999-5000, ext 1131
SECNAP Network Security Corporation
Keep up to date with latest information on IT security: Real time
security alerts: http://www.secnap.com/news
 


-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid0709&bid&3057&dat1642
_______________________________________________
AMaViS-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/amavis-user
AMaViS-FAQ:http://www.amavis.org/amavis-faq.php3
AMaViS-HowTos:http://www.amavis.org/howto/

Reply via email to