|
|
 |  |
Re: Lame DelegationFrom: Men & Mice Support Date: Tuesday, May 25, 1999
Time: 10:48:00 pm>While checking my QDNS server yesterday I heard a lot of disk activitiy all
>the sudden and so I checked the log and found it full of a Lame Delegation
>for mailserver.com with two IP addresses which alternated back and forth.
>The log was completely full of this same entry except for the two IP
>numbers for this address. Any idea as to what happened and why so many
>entrys/hits all of the sudden?
Spam. A spammer was apparently trying to send scads of mail through your
server, which was trying to verify the sender's name with your name server.
The name server was running into a lame delegation and was thus unable to
give the mail server a good answer. That's my guess.
The lame delegation is simple: The root servers delegate mailserver.com to
ns1.altaway.net, which in turn tries to delegate it to
ns1.granitecanyon.com. Which means that the root servers have incorrect
(lame) information.
As for the granitecanyon.com servers, they have done their best to shut it
down: "Normal name service for this zone has been discontinued. It was
being used in violation of the anti-spam policy of the Public DNS. See
http://SOA.GraniteCanyon.COM/" - this came from a TXT record for
mailserver.com.
And here's the SOA record:
mailserver.com. 12096000 SOA nuked.for.spamming.
nobody.mailserver.com.
0 ; serial
2419201 ; refresh (28 days, 1 second)
1209600 ; retry (14 days)
14515202 ; expire (168 days, 2 seconds)
12096000 ; minimum (140 days)
____________________________________________________________________
Chris Buxton Men & Mice
cbuxton@menandmice.com http://www.menandmice.com
|

Return to Digital Point Solutions' Home Page |