Search Again:

Re: reverse DNS questions

From: Michael Wise
Date: Thursday, September 4, 2003
Time: 7:55:00 pm

At 4:29 -0500 9/5/03, Len Conrad wrote:

>> or do I need to contact SBC to get them to modify their reverse DNS?
>
>If rr is blocking by IP subnet rather than by PTR hostname domains,
>you can't escape.
>
>> As part of this continuing effort, Road Runner has implemented
>>blocks to its inbound SMTP servers from residential IP address
>>ranges, regardless of whether they are static or dynamic. The
>>reason for this is because of the widespread number of residential
>>subscribers who we have found are infected with trojans such as
>>Jeem, or have open proxy or SMTP applications which allow third
>>parties to hijack them.
>
>I happen to agree with their reasoning and actions completely,

Their reasoning...partially; their actions...no.

They claim that they want to block smtp transactions from so-called
"residential" DSL lines. (whether thy have static IP blocks or not),
but what their lazy admins are really doing is labelling as
"residential" and then blocking _ALL_ SBC DSL IP blocks if they do
not have an rdns suggesting they are being used by a business.

Several bad assumptions here:

1) That somebody paying an extra 10-20% to have their account
classifies as a "business" one is any more secure than one who has a
"residential" one.

2) That SBC "business" DSL customers automatically have an rdns
suggesting so (they don't)

3) That "residential" customers can't get an rdns without *.dsl.* or
*.adsl.* and *pacbell.net.* in it (they can just as easily as
so-called "business" users.


What rr.com should really be doing is blocking users with dymanic
blocks...and taking out sledge hammer and tarring tens of thousands
of static and SWIP'd blocks simply because they're too lazy to do
some homework.


Of course, their servers; their rules and all that NANAE/Spam-L
jargon....but I find it a little insulting that a huge spam source
and a reigning open proxy king like rr.com should all of the sudden
be johnny-come-lately spam fighter and tell those of us who have,
unlike rr.com, managed our servers securely for years how we are all
of the sudden spam pits.

Their methods are lazy at best...irresponsible and incompetent at worst.



>since my experience with DSL/cable/dial access networks is identical
>to theirs. I've come up with very long list of PTR hostname
>domains, my "subscriber access network" list, for my IMGate
>customer, and it's proving very effective.
>
>The amt of legit IPs and mail from subscriber nets minuscule
>compared to the spam.


"DSL/cable/dial access"? Wow, you're lumping a whole lot there. I
would agree if the statement were "DYNAMIC IP DSL/cable.dial
access"...but lumping all DSL is a big stretch.


--Miike



--Mike





Messages In This Thread:



Return to Digital Point Solutions' Home Page