Search Again:

Re: Windows and QuickDNS

From: Aaron Lynch
Date: Wednesday, June 6, 2001
Time: 3:30:35 pm

On 6/6/01 2:31 PM, The Defendant "Men & Mice Support"
<cbuxton@menandmice.com> Confessed:

> At 1:02 PM -0400 6/6/01, Dave Cooper wrote:
>> Hi,
>>=20
>> After recently tightening security on our mail server, all of my Windows
>> boxes (Win95,98,2000) are unable to send mail to the mail server. The e=
rror
>> message indicates that the reverse DNS look is returning a different nam=
e,
>> etc. My Macs are ok. Does QuickDNS 2.21 work with Windows? If so can =
you
>> offer any hint as to what isn't set up in my configuration?
>=20
> Your mail server is misconfigured. It should accept any and all mail
> from local machines.
>=20
> That oversight appears to be combining with a lack of PTR records for
> your Windows machines. Who controls your PTR records, you or your
> ISP? If you're on a private subnet, with a NAT server, then the
> answer is you, by definition.


I would take this a step farther. If you are bouncing mail based on a PTR
record not matching up, your mail server is misconfigured, and is
explicitly violating the RFC. (there was a thread about this on the
Communigate list)

RFC1123:
-----------

=A0=A0=A0=A0=A0=A05.2.5 HELO Command: RFC-821 Section 3.5

=A0=A0=A0=A0=A0=A0=A0=A0=A0The sender-SMTP MUST ensure that the <domain> parameter in a
=A0=A0=A0=A0=A0=A0=A0=A0=A0HELO command is a valid principal host domain name for the
=A0=A0=A0=A0=A0=A0=A0=A0=A0client host. As a result, the receiver-SMTP will not have to
=A0=A0=A0=A0=A0=A0=A0=A0=A0perform MX resolution on this name in order to validate the
=A0=A0=A0=A0=A0=A0=A0=A0=A0HELO parameter.

=A0=A0=A0=A0=A0=A0=A0=A0=A0The HELO receiver MAY verify that the HELO parameter really
=A0=A0=A0=A0=A0=A0=A0=A0=A0corresponds to the IP address of the sender. However, the
=A0=A0=A0=A0=A0=A0=A0=A0=A0receiver MUST NOT refuse to accept a message, even if the
=A0=A0=A0=A0=A0=A0=A0=A0=A0sender's HELO command fails verification.


-- Aaron Lynch
System Administrator
NineWire Digital Solutions || http://ninewire.com

If I ever get real rich, I hope I'm not real mean to poor people, like now.
-Jack Handy




Messages In This Thread:



Return to Digital Point Solutions' Home Page