nanog mailing list archives

Re: Questinair about email policy records to indicate proper source of email (RE: FW: The worst abuse e-mail ever, sverige.net)


From: "Ricardo \"Rick\" Gonzalez" <rico.gonzalez () gmail com>
Date: Wed, 22 Sep 2004 16:08:17 -0400


Now here are the questions, I'd like to receive feedback on:
-------------------------------------------------------------------

1. Are you ISP? What size?

I am ISP.  Well rather, I'm AN ISP.  Okay, so I just operate one, but
you get the gist.

2. If you're ISP are you willing to quickly deploy these records if such
   standard becomes available? If so how quickly can you deploy it -

"If you're ISP"?  Who's asking the questions, Ali G?
 
3. Are you willing to configure/upgrade your email server to check of
   these policy records and reject SMTP connection based on these records?

No, because I already utilize multiple DNS-based blacklists which do
precisely that (blocking dynamically assigned dialup/cable/DSL address
pools), as part of SpamAssassin and other spam filtering mechanisms.

4. Many users and even RIRs have expressed doubts about relying on IN-ADDR
   and said it has technical problems and/or that IN-ADDR zones are badly
   maintained by ISPs and that we should not rely on it. Do you agree?

No need to look at in-addr.  See above.

6. The suggestion that has been made to allow DNS policy record for
   SMTP Mail server as used in EHLO to override policy record for IP as
   a way to get around non-cooperative or slow ISPs that don't let their
   customers control what record is in the INADDR zone. What do you
   think about this?

Don't take it personally, but I think that's a bad idea.

7. For the policy record would you prefer to just say that no email
   is to come from the ip or would you prefer to be able to specify
   more complex record:

"For the policy record"?  Are you an officer of the court?  Columbo? 
What "record" are you keeping, and for which organization(s)?  Did Ray
P. step down and make you the CEO of ARIN?

8. Would you like to have an option as part of policy record that
   can be used so that other email servers when they see SMTP connection

That doesn't parse.  "SMTP connections"?  Or "a SMTP connection"?  

   from certain ip would report back to you if ip is used for outgoing
   email connections?

Yes.  I'd hope IP is being used for e-mail connections.  It sure beats
the alternatives, such as DECNet, AppleTalk, and IPX.

9. Would you like to have an option as part of policy record
   that lets specify who the administrator is to contact in case

Depends.  Lets who specify?

12. Do you consider that these email policy records for ips would be
    alternative for ISP port 25 blocking or a complimentary technology
    that can be used together with it?

No.  Again, you're reinventing the wheel unnecessarily.  See existing dnsbl's.


Current thread: