Re: FEATURE(`require_rdns') : 451 reaction to FORGED [WHY?]
- From: Andrzej Adam Filip <anfi@xxxxxxx>
- Date: Sat, 24 Mar 2007 09:07:24 +0100
Neil W Rickert <rickert+nn@xxxxxxxxxx> writes:
Andrzej Adam Filip <anfi@xxxxxxx> writes:
Why the feature sends back *temporary* reject when forward and reverse
lookups do not match? [FORGED]
IMHO In such situation sendmail should send permanent reject.
Am I wrong? [Have I missed something important?]
On a dual hosted system, it sometimes happens that the forward
lookup only returns one IP, and it might not be the IP that was
being checked in the reverse lookup.
This can happen when the A records for the two IP addresses have
different TTLs. In turn, that can happen when one of those A-records
came from the correct DNS server for the domain, and the other came
as a glue record from the root dns servers.
I don't know whether they have corrected this, but the host template
used for setting up DNS only had space for one IP, so it was near
impossible to get both IPs of a dual hosted system into those
glue records.
(I know this from personal experience).
I think current versions of bind software are less susceptible to
this problem, but it probably still happens with other DNS software.
DJB always argued against the bind implementation changes that make
it less susceptible.
Oh, I see [Some "other soft implementation details" can be important]
Judging by your explanation giving 5?? reply on FORGED may be asking for
troubles in some pretty common situations.
--
[pl>en: Andrew] Andrzej Adam Filip : anfi@xxxxxxxxxxxx : anfi@xxxxxxxx
Before You Ask: http://anfi.homeunix.net/sendmail/B4UAsk-Sendmail.html
http://anfi.homeunix.net/sendmail/ [orkut,linkedin,xing]
.
- References:
- FEATURE(`require_rdns') : 451 reaction to FORGED [WHY?]
- From: Andrzej Adam Filip
- Re: FEATURE(`require_rdns') : 451 reaction to FORGED [WHY?]
- From: Neil W Rickert
- FEATURE(`require_rdns') : 451 reaction to FORGED [WHY?]
- Prev by Date: Re: FEATURE(`require_rdns') : 451 reaction to FORGED [WHY?]
- Next by Date: Move queue
- Previous by thread: Re: FEATURE(`require_rdns') : 451 reaction to FORGED [WHY?]
- Next by thread: TLS by Domain
- Index(es):
Relevant Pages
|