On 12-Aug-00, Fred Wright wrote:

>> I think I pointed this out before, but my ISP does not own the POP that
>> is here. The DNS lookups work but the DNS servers that are returned do
>> not belong to Earthlink. Everything works when I leave DNS on automatic,
>> with the exception of sending mail. The SMTP server checks somehow, and
>> does not consider me to be "dialed up" to earthlink, much as if I tried
>> to use it from the LAN at work. I have seen several other services that
>> use the same POP as earthlink, and they all prefix the logon somehow.
>> For example, my earthlink logon is "ELN/digitalq". Now I'm assuming here
>> that if the machine that is used there can tell I belong to earthlink,
>> then it could somehow be told to spit back DNS servers that are owned by
>> earthlink, but I don't know.
>> 
>> Should I complain?  I am, after all paying them for the service.
>> 
>> I think that if they change the DNS IPs, it would be pretty obvious
>> though.
>> So I just call them up and find out the new ones, right?
> 
> It's not necessarily true that you need DNS servers associated with your
> ISP.  What you want is reliable servers "close" to your POP that give the
> correct answers.  Whether they should belong to your ISP or the party
> that's supplying the POP depends on the architecture.

I see.

> The SMTP server itself is completely unaware of your DNS settings, but I
> can think of a few ways the DNS choice might come into play:
> 
> 1) You're using a fully qualified domain name for the SMTP server, but
> the different DNS servers are returning different IP addresses for it,
> and hence you're actually using different servers. IP<->hostname mappings
> aren't *supposed* to vary with the server, but various misconfigurations
> are possible.

The SMTP server is found, that is not the problem.  The server returns
"relaying denied" if I have anything other that the supplied DNS servers
in my database.  Including the ones that get "looked up" at logon.

> 2) You're not using an FQDN, and the server name is being looked up in
> different domains as a function of the DNS server chosen (perhaps due to
> the "auto-add domain" feature), thus again yielding different IPs.

Same as #1, I think.  Attempts to logon to the SMTP server are greeted with
"relaying denied" 
 
> 3) You're getting the same server each way, but your hostname is being
> set up differently as a function of the DNS server, and the SMTP server
> is being fussy about this.

Aha, this sounds like what they must be using to deny access from outside
the domain.

Yep!  Just checked.  Turned "Get DNS" back on, connected and put the
numeric IP of the SMTP server in YAM and the domain set to
"earthlink.net".  Mail was sent without incident.

So this tells me that thier reason given for this behaviour (eliminating
the relay of mail through thier servers for bulk mail purposes) may be a
noble cause, but it is all to easily circumvented.  It would only seem to
cause grief for thier customers, and neophyte spammers.  :P

> You can check your lookups for 1 and 2 by using:
>     Miami:MiamiTCPDump -nvs 200 -i <interface> udp port 53
> 
> You can check your hostname with "Echo $HOSTNAME".  You can check your
> domains in the "Domains" database.

As always, you are a wealth of information sir.  I thank you for your
explanations.  (even if I did have to read them over two or three times. 
I can be really dense about such things.) :)

-- 
C-ya!     //      VP of NAK, <http://surf.to/NAK/>
Chris   \X/       [EMAIL PROTECTED]     member of Team *AMIGA*

----------Digital Quill Graphics-----------   |  Amiga 2000/T-Rex
-------Specializing in Heat Applied--------    | Graphic Workstation
---------Digital Image Transfer to--------- |  68060@50Mhz/96Meg/
----T-shirts, Mugs, Mousepads and More!---- | 2.1 Gig. Motorollin! 

 Your mouse has moved. Windows NT must be
 restarted for the change to take effect.
             Reboot now?
.                [ OK ]                  .

-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to