Hi.

Am Sonntag, 11. November 2007 schrieb niclas:
> >> oh, and they said, their smtp-systems are a cluster, so DNS-lookup
> >> *cannot* work all the time anyway. still sounds like they're right.

This is either a dump setup or a dumb answer.
All hosts should always have any unique identifier, no matter if they are also 
in a cluster.

A setup where an admin cannot distinct between hosts to log in and fix 
problems is really not what you should have.

And if they have something unique, they should be able to put this unique host 
name in HELO greeting.
Maybe the correct reverse-lookup cannot always be given because in 
cluster-setups, there may be shared IP-addresses but that's not faced here.


> > They are not. They have DNS delegation for the whole class, so they
> > can implement whatever view they like, the way they like.
> ok, maybe they're wrong about their DNS setup.
> still they don't have to fix it to make mail delivery work. the SMTP
> *MUST NOT* bounce mail if the HELO-DNS-comparison fails. (it was you who
> quoted RFC 2821...)

You are really proud of defending a company with a broken setup, aren't you? 

Maybe checking HELO is not allowed according to RFC 2821. But sending a wrong 
name is not allowed either. 
So anyone should be free to decide from whom he wants mail and from whom he 
doesn't. If Sam decides that his mail host should not be bugged by poor 
setups, it's his choice.

For me, I use BOFHCHECKHELO for all hosts that are in any used RBL (and it 
fights MANY spam mails without cpu-intensive spam checkers). I turned it off 
for all others because there are so many wrong setups out there and I have 
paying customers that want mail from many of those senders. That may be the 
difference. :)

cu, Bernd

-- 
Make something idiot proof and someone will make a better idiot.

Attachment: signature.asc
Description: This is a digitally signed message part.

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >> http://get.splunk.com/
_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to