nanog mailing list archives

Re: Kill Verisign Routes :: A Dynamic BGP solution


From: Damian Gerow <damian () sentex net>
Date: Thu, 18 Sep 2003 18:58:13 -0400


Thus spake Stephen J. Wilcox (steve () telecomplete co uk) [18/09/03 18:54]:
So totallymadeupdomain.com now resolves but is unreachable. That will prevent 
you from bouncing emails to non-existent domains immediately..

FWIW, the latest versions of postfix have code in them to block connects
from explicitly listed hosts:

    New check_{helo,sender,recipient}_{ns,mx}_access maptype:mapname
    restriction that applies the specified access table to the NS or
    MX hosts of the host/domain given in HELO, EHLO, MAIL FROM or RCPT
    TO commands.
            
    This can be used to block mail from so-called spammer havens, or
    from sender addresses that resolve to Verisign's wild-card mail
    responder, currently at IP address 64.94.110.11.

  - Damian


Current thread: