North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: SORBS Insanity

  • From: jlewis
  • Date: Thu Apr 15 09:34:53 2004

On Thu, 15 Apr 2004, Joe Maimon wrote:

> Speaking about whitelisting....comp.mail.sendmail google
> link...Reproduced below..
>
> http://groups.google.com/groups?q=sendmail+whitelist+dns&hl=en&lr=&ie=UTF-8&oe=UTF-8&c2coff=1&selm=ac4e9990.0311250514.65c4e614%40posting.google.com&rnum=9

ok...you've now drifted way off-topic for NANOG IMO.  This belongs in
spam-tools or spam-l.

> I was wondering if any of you use *dns* lists for whitelisting purposes.

Yes...for several years.

> I have found a couple of whitelists online (bondedsenders) and their
> m4 was far from satisfactory.

Why?  I came up with essentially the same rules (modified dnsbl.m4 to
support DNSWLs) as them back in 2001 and have been using it ever since at
multiple sites with privately maintained DNSWLs.  For that usage, it works
fine.  If you want to use it with someone else's DNSWL and they have
different 127.x.y.z return codes for different whitelisting reasons, sure,
it's too primitive, and you'll likely need to modify enhdnsbl.m4 to make
your own enhdnswl.m4, or do something similar.  Why the sendmail folks
have chosen to support DNSBLs but not DNSWLs, is still a mystery to
me...but this has little to do with network operations.

----------------------------------------------------------------------
 Jon Lewis *[email protected]*|  I route
 Senior Network Engineer     |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________