Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Bill Cole via mailop
On 2023-03-27 at 06:46:04 UTC-0400 (Mon, 27 Mar 2023 13:46:04 +0300) Lena--- via mailop is rumored to have said: [...] For NS I currently use the registrar. Its web-interface allowed me to create the TXT record for a selector. The parent _domainkey - NXDOMAIN. So this isn't what you're

Re: [mailop] NS DKIM

2023-03-27 Thread Lena--- via mailop
> That (sub)domain is not DNSSEC signed, thus it will work with > (many) recursive resolvers for some time. DNSSEC mandates > NoDATA for empty non terminals, thus there can be problem > once it become signed (and SW and/or admin will not be > upgraded). Okay, I created a TXT record for the parent

Re: [mailop] NS DKIM

2023-03-27 Thread Slavko via mailop
Dňa 27. marca 2023 17:06:55 UTC používateľ Alessandro Vesely via mailop napísal: >On Mon 27/Mar/2023 18:25:24 +0200 Brad Beyenhof via mailop wrote: >> On 3/27/23, 9:18 AM, "mailop on behalf of Heiko Schlittermann via mailop" >> mailto:mailop-boun...@mailop.org> on behalf of >>

Re: [mailop] NS DKIM

2023-03-27 Thread Alessandro Vesely via mailop
On Mon 27/Mar/2023 18:25:24 +0200 Brad Beyenhof via mailop wrote: On 3/27/23, 9:18 AM, "mailop on behalf of Heiko Schlittermann via mailop" mailto:mailop-boun...@mailop.org> on behalf of mailop@mailop.org > wrote: Lena--- via mailop mailto:mailop@mailop.org>> (Mo 27

Re: [mailop] NS DKIM

2023-03-27 Thread Slavko via mailop
Dňa 27. marca 2023 16:13:35 UTC používateľ Heiko Schlittermann via mailop napísal: >Lena--- via mailop (Mo 27 Mär 2023 17:40:29 CEST): >> dig _domainkey.lena.kiev.ua txt >> ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 57410 > >Reading https://www.rfc-editor.org/rfc/rfc8020#section-3.1

Re: [mailop] NS DKIM

2023-03-27 Thread Brad Beyenhof via mailop
On 3/27/23, 9:18 AM, "mailop on behalf of Heiko Schlittermann via mailop" mailto:mailop-boun...@mailop.org> on behalf of mailop@mailop.org > wrote: > Lena--- via mailop mailto:mailop@mailop.org>> (Mo 27 Mär > 2023 17:40:29 CEST): > > > If the DNS name

Re: [mailop] NS DKIM

2023-03-27 Thread Heiko Schlittermann via mailop
Lena--- via mailop (Mo 27 Mär 2023 17:40:29 CEST): > > If the DNS name xxx._domainkey.example.com exists, then > > _domainkey.example.com exists too. > > dig 3._domainkey.lena.kiev.ua txt > 3._domainkey.lena.kiev.ua. 66633 IN TXT "v=DKIM1; p=MIGfMA0GCSqGSIb... > > dig

[mailop] NS DKIM

2023-03-27 Thread Lena--- via mailop
> If the DNS name xxx._domainkey.example.com exists, then > _domainkey.example.com exists too. dig 3._domainkey.lena.kiev.ua txt 3._domainkey.lena.kiev.ua. 66633 IN TXT "v=DKIM1; p=MIGfMA0GCSqGSIb... dig _domainkey.lena.kiev.ua txt ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id:

Re: [mailop] Unbound configuration for DNSBL ?

2023-03-27 Thread Cyril - ImprovMX via mailop
Thank you for the follow ups. @Michael why the suggestion to use something else? I think it would just move the issue elsewhere without fixing it. @Renaud that's exactly what we are currently doing; we are working on a partnership with Spamhaus to set up a paid account with them in order to have

Re: [mailop] Unbound configuration for DNSBL ?

2023-03-27 Thread Renaud Allard via mailop
On 3/27/23 11:17, Cyril - ImprovMX via mailop wrote: Hi everyone! We have a few SpamAssassin servers running that test against services such as SpamHaus, URIBL, etc. We often have our queries blocked because we go beyond the free usage. As such, we started a trial with SpamHaus, and the

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Slavko via mailop
Dňa 27. marca 2023 13:20:06 UTC používateľ Heiko Schlittermann via mailop napísal: >If the DNS name xxx._domainkey.example.com exists, then >_domainkey.example.com exists too. It doesn't have any data (no TXT, A, >AAA, … record). But asking for _domainkey.example.com must not return >NXDOMAIN

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Heiko Schlittermann via mailop
Slavko via mailop (Mo 27 Mär 2023 14:37:54 CEST): > That problem is more visible with DNSSEC and > DNS "nothing under" (sorry i don't remember exact > name nor RFC). The result is, that when _domainkey > returns NXDOMAIN, anything under it is considered > as NXDOMAIN too... If the DNS name

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Slavko via mailop
Dňa 27. marca 2023 11:10:58 UTC používateľ Heiko Schlittermann via mailop napísal: >Do you have an example where ._domainkey. exists, but >_domainkey. returns NXDOMAIN? Yes, my previous DNS provider had that broken their DNS server(s). I had to create dummy TXT record for _.domainkey to get my

Re: [mailop] Unbound configuration for DNSBL ?

2023-03-27 Thread Slavko via mailop
Dňa 27. marca 2023 9:17:27 UTC používateľ Cyril - ImprovMX via mailop napísal: >Right now, here's our Unbound.conf file: >https://pastebin.com/PZWUn4My If i understand that correctly, you are forwarding all requests to OpenDNS. I am not sure if any tweaking will do any/big difference, as

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Heiko Schlittermann via mailop
Lena--- via mailop (Mo 27 Mär 2023 12:46:04 CEST): > > > > They have SPF, but no DKIM (NXDOMAIN for the _domainkey.bsi.de) > > > > Or did I miss something? > > > > > > The DKIM keys would be at ._domainkey.bsi.de > > > > Yes, but as long as the parent of *any* selector does not exist, there > >

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread hg user via mailop
Yes I do but when the phishing is in italian I know (and use) one updated sources of patterns but sometimes it is late... Just as an example, a little bit of one body rule I wrote: clicca qui per (verificare|confermare|favore|riconvalidare|aggiornare) (la tua e-mail|il tuo account) in english

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Lena--- via mailop
> > > They have SPF, but no DKIM (NXDOMAIN for the _domainkey.bsi.de) > > > Or did I miss something? > > > > The DKIM keys would be at ._domainkey.bsi.de > > Yes, but as long as the parent of *any* selector does not exist, there > is a very good chance, that not any selector exists. > > If the

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Jaroslaw Rafa via mailop
Dnia 26.03.2023 o godz. 17:24:32 Grant Taylor via mailop pisze: > > Or are you referring to IPs that two different names resolve to? Yes, I do. I have only one server. Of course, I can try to work around this, for example I can put my friend's server (that I know does not have any mail service

[mailop] Unbound configuration for DNSBL ?

2023-03-27 Thread Cyril - ImprovMX via mailop
Hi everyone! We have a few SpamAssassin servers running that test against services such as SpamHaus, URIBL, etc. We often have our queries blocked because we go beyond the free usage. As such, we started a trial with SpamHaus, and the result is that we query around 8M times per day. Our current

Re: [mailop] mailgun anybody? (variable sender address) time

2023-03-27 Thread Heiko Schlittermann via mailop
Gellner, Oliver via mailop (So 26 Mär 2023 10:46:22 CEST): > >;; Got answer: > >;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 16687 > > > > > > They have SPF, but no DKIM (NXDOMAIN for the _domainkey.bsi.de) > > Or did