Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: exim: users

Re: [dnsbl-users] in which rbl is an entry listed?

 

 

exim users RSS feed   Index | Next | Previous | View Threaded


wbh at conducive

Oct 31, 2006, 10:49 AM

Post #1 of 2 (206 views)
Permalink
Re: [dnsbl-users] in which rbl is an entry listed?

Marten Lehmann wrote:
> Hello,
>
> from time to time I'm noticing, that there are entries in the sorbs rbl,
> which shouldn't belong in there. For it is for example not accceptable
> to block mails from yahoo accounts, although they may be misused for
> spamming every now and then. Currently I see this entry listed:
>
> 217.12.10.214
>
> Netblock: 217.12.10.0/24 (217.12.10.0-217.12.10.255)
> Record Created: Wed Jul 5 19:10:22 2006 GMT
> Record Updated: Wed Jul 5 19:10:22 2006 GMT
> Additional Information: from web25105.mail.ukl.yahoo.com
> (web25105.mail.ukl.yahoo.com [217.12.10.53]) by [server] with SMTP id
> 80FD8534077 for [email]; Wed, 5 Jul 2006 17:26:06 +0000 (GMT)
> Currently active and flagged to be published in DNS
> If you wish to request a delisting please do so through the Support System.
>
> But how do I find out to which rbl it is assigned (i.e.
> zombie.dnsbl.sorbs.net or recent.spam.dnsbl.sorbs.net)? This is very
> important for us (and surely others), as I need to remove this single
> rbl from our list while the remaining sorbs-rbls seem to be fine.
>
> Regards
> Marten

First:

The exim variable: $dnslist_domain returns the txt-field of the (first) specific
list in which it found a hit. You can log that.

Second:

These things happen, and often, as RBL's play few favorites.

It is wise when using RBL's for blocking that you have some form of 'scoring' or
'weighting' such that it is either:

- never an absolute block. Merely a score usable by an MUA or to 'quarantine'

and/or

- is a per-delivery-domain (customer) decision to make it a hard-block for the
domain they are responsible for.

and, more pragmatically, you need a quick-reaction and fairly selective
whitelisting capability, 'coz the first two work better in theory than in practice..

;-)

HTH,

Bill




--
## List details at http://www.exim.org/mailman/listinfo/exim-users
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://www.exim.org/eximwiki/


wbh at conducive

Oct 31, 2006, 1:11 PM

Post #2 of 2 (212 views)
Permalink
Re: [dnsbl-users] in which rbl is an entry listed? [In reply to]

Marten Lehmann wrote:
> Hello,
>
>>> well, that sounds reasoned. But I'm not using the
>>> spam.dnsbl.sorbs.net list, but only dnsbl.sorbs.net, which does per
>>> definition not include spam.dnsbl.sorbs.net. Why does it contain that
>>> entry anyway?
>>
>> Dnsbl is an aggregate zone that returns the results from a list of
>> subzones. Take another look at the 'Using SORBS' page:
>> http://www.de.sorbs.net/using.shtml
>
> it clearly states:
>
> dnsbl.sorbs.net - Aggregate zone (contains all the following DNS zones
> __except__ spam.dnsbl.sorbs.net)
>
> So why does the aggregated zone contain entries of the spam-subzone,
> although this zone should be excluded?
>
> Regards
> Marten

Cannot any given entity be in violation of more than one parameter?

Bill


--
## List details at http://www.exim.org/mailman/listinfo/exim-users
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://www.exim.org/eximwiki/

exim users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.