SMTP Sender Domain Exists validation

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

SMTP Sender Domain Exists validation

Postby labull » Sep 24 03 10:38 am

In EMAIL I have checked -

Validate that the sender domain exists.

I recieved an email that has this in its header -

Received: From simmts6-srv.bellnexxia.net (unverified [206.47.199.164]) by SMTP Server [xxx.xxx.xxx.xxx]

This is not a valid domain.

Shouldn't this email be blocked?

Thanks!

Larry
labull
WinGate Guru
 
Posts: 710
Joined: Sep 06 03 1:03 am
Location: Washington, DC - USA

Re: SMTP Sender Domain Exists validation

Postby tim » Sep 24 03 10:52 am

labull wrote:In EMAIL I have checked -

Validate that the sender domain exists.

I recieved an email that has this in its header -

Received: From simmts6-srv.bellnexxia.net (unverified [206.47.199.164]) by SMTP Server [xxx.xxx.xxx.xxx]

This is not a valid domain.
Shouldn't this email be blocked?
Thanks!
Larry


This may be caused my Verisigns take over of all non-assigned domains. I'm not sure of the exact technical details at this time, but I know it has been causeing havoc with similar systems world wide. VeriSign has been ordered / requested to stop this, but when and if it happens is another matter.

Tim
tim
Senior Member
 
Posts: 109
Joined: Sep 03 03 2:53 pm

Postby adrien » Sep 25 03 2:13 am

Also if the lookup fails for any reason we feel it is better to be safe than sorry. Some DNS servers return error responses for some domains...
adrien
Qbik Staff
 
Posts: 5441
Joined: Sep 03 03 2:54 pm
Location: Auckland

Postby labull » Sep 25 03 2:18 am

Turns out that the look-up is for the domain in Mail From: rather than HELO/EHLO.

The spammers are always going to say they're from some legal domain e.g. yahoo.com.

Why not verify the HELO/EHLO domain?
labull
WinGate Guru
 
Posts: 710
Joined: Sep 06 03 1:03 am
Location: Washington, DC - USA

Postby adrien » Sep 25 03 2:42 am

The RFCs advise against any sort of validation against the domain given in the HELO or EHLO command. Basically because that can be anything, not even a resolvable name.
adrien
Qbik Staff
 
Posts: 5441
Joined: Sep 03 03 2:54 pm
Location: Auckland

Postby labull » Sep 25 03 2:49 am

Almost all of the SPAM that gets through here is of this flavor and there's a lot of it.

What can we do block this stuff?
labull
WinGate Guru
 
Posts: 710
Joined: Sep 06 03 1:03 am
Location: Washington, DC - USA

Postby labull » Sep 25 03 1:17 pm

How about an option to turn on ORDB and DNS checking for all domains listed in the header?

Appropriate caveats about performance degradation would accompany the option.

For me, I’d gladly take the performance hit if it will help eliminate one of the largest parts of my SPAM problem.

Thanks!

Larry
labull
WinGate Guru
 
Posts: 710
Joined: Sep 06 03 1:03 am
Location: Washington, DC - USA


Return to WinGate

Who is online

Users browsing this forum: Bing [Bot] and 56 guests