nanog mailing list archives
Re: Blocking MX query
From: Suresh Ramasubramanian <ops.lists () gmail com>
Date: Wed, 5 Sep 2012 07:44:54 +0530
This is a bit of a slippery slope. There is broad agreement that SPs need to block port 25 outbound (and inbound) on dynamic IP space. And he did say he's in a country where he's obliged by law to filter out porn (and I guess anything else his country's government doesn't like). Where do blocking MX record lookups fit in between the porn blocking and the port 25 filtering? Rather closer to port 25 filtering I'd say, but your call. This is not a user privacy issue at all. Static IP broadband is entirely available if you should decide you want to run a mailserver at your home. And for people using outlook (or postfix) on their desktop to relay through a smarthost, MX lookups don't matter one way or the other. --srs On Wed, Sep 5, 2012 at 7:30 AM, Mark Andrews <marka () isc org> wrote:
Well he was looking for software to block the queries. There is a whole mentality that homes don't need X which on closer examination just doesn't bear up to scrutany. This includes blocking SMTP or don't you think home users are entitled to have privacy when it comes to whom they email? STARTTLS from anywhere to anywhere is possible today and is not vulnerable to interception except in the MX's themselves. You can secure the MX records (and their absense) and secure the CERTs used by STARTTLS.
-- Suresh Ramasubramanian (ops.lists () gmail com)
Current thread:
- Re: Blocking MX query, (continued)
- Re: Blocking MX query Bacon Zombie (Sep 04)
- Re: Blocking MX query Ibrahim (Sep 04)
- Re: Blocking MX query Suresh Ramasubramanian (Sep 04)
- Re: Blocking MX query Ibrahim (Sep 04)
- Re: Blocking MX query Tony Finch (Sep 04)
- Re: Blocking MX query William Herrin (Sep 04)
- Re: Blocking MX query Rich Kulawiec (Sep 04)
- Re: Blocking MX query Jimmy Hess (Sep 04)
- Re: Blocking MX query Mark Andrews (Sep 04)
- Re: Blocking MX query Suresh Ramasubramanian (Sep 04)
- Re: Blocking MX query Mark Andrews (Sep 04)
- Re: Blocking MX query Suresh Ramasubramanian (Sep 04)
- Re: Blocking MX query Jimmy Hess (Sep 04)
- Re: Blocking MX query Mark Andrews (Sep 04)
- Re: Blocking MX query Rich Kulawiec (Sep 04)
- Re: Blocking MX query Bacon Zombie (Sep 04)
- Re: Blocking MX query Ray Wong (Sep 04)
- Re: Blocking MX query Suresh Ramasubramanian (Sep 04)
- Re: Blocking MX query Jay Ashworth (Sep 04)
- Re: Blocking MX query Suresh Ramasubramanian (Sep 04)
- Re: Blocking MX query Masataka Ohta (Sep 04)
- Re: Blocking MX query Suresh Ramasubramanian (Sep 04)
- Re: Blocking MX query valdis . kletnieks (Sep 04)