Verisign suggestion

David B Harris david at eelf.ddts.net
Thu Sep 18 15:42:26 UTC 2003


On Thu, 18 Sep 2003 08:24:40 -0400 (EDT)
Todd Vierling <tv at duh.org> wrote:
> : > ...and for heavens sake, stop accepting any kind of request at all on port
> : > 25!! Just shut it down altogether. There is no reason for you to accept
> : > any connection of any kind on port 25!
> 
> : If they don't accept anything on port 25, either by sending all packets
> : to /dev/null or by responding with SYN+RST ("Connection refused"), MTAs
> : everywhere will consider this a "temporary error."
> 
> Then the wildcard should have included a MX that points to nowhere, rather
> than implementing a fake MTA that allows the MAIL FROM and RCPT TO addresses
> to be transmitted.  The record "IN MX 0 ." is commonly used for this
> purpose.

Yeah, thanks for pointing this out. T'was an accidental omission in my
mail.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20030918/5a43738d/attachment.sig>


More information about the NANOG mailing list