On 2007-05-01 22:58:12 -0400, David F. Skoll wrote:
Hector Santos wrote:
If both the primary and secondary MX servers are administered by the
same organization or by closely-cooperating organizations, this works
well. However, there are ISPs that offer "secondary MX service" to
their customers, and they are unlikely (or sometimes unable) to make
special arrangments to synchronize user lists.
Yep. We can't "outlaw" this practice in the RFC, of course, but I think
that this service isn't very useful any more. If you are doing any
serious anti-spam filtering you really want the same filter rules on all
your MXs. You especially don't want an "accept everything" policy on the
lowest-priority MX because spammers do expect and exploit that.
(Hmm, is that another recommendation that should go into the RFC if it
isn't already there? "If there are multiple MX for a domain, they
SHOULD implement the same policy for accepting or rejecting mail. In
particular, a lower priority MX should not accept mail that a higher
priority MX rejects")
Perhaps an RFC for querying whether or not an e-mail address is
valid using DNS? :-)
host -t txt some.email.AT.example.com.email-verification-zone.example.com
After all, there are already well-established and widely-used mechanisms
for synchronizing DNS data. (I skip tedious details like restrictions
on local-part of e-mail addresses, etc.)
Funny you should mention that. I thought about mentioning that
possibility but left it out because it isn't standardized, so it's on
the same level as rsyncing config files, etc.: Easy to implement within
one organisation, but each organization is likely to do it slightly
differently. An RFC would help, of course, but I'm not sure you can get
all the needed information in there. For example, I would cram
address-specific configurations (e.g., is greylisting enabled) into the
TXT record, but of course that is MTA-specific.
hp
--
_ | Peter J. Holzer | I know I'd be respectful of a pirate
|_|_) | Sysadmin WSR | with an emu on his shoulder.
| | | hjp(_at_)hjp(_dot_)at |
__/ | http://www.hjp.at/ | -- Sam in "Freefall"
signature.asc
Description: Digital signature