SORBS Insanity

jlewis at lewis.org jlewis at lewis.org
Thu Apr 15 13:30:56 UTC 2004


On Thu, 15 Apr 2004, Joe Maimon wrote:

> Speaking about whitelisting....comp.mail.sendmail google
> link...Reproduced below..
>
> http://groups.google.com/groups?q=sendmail+whitelist+dns&hl=en&lr=&ie=UTF-8&oe=UTF-8&c2coff=1&selm=ac4e9990.0311250514.65c4e614%40posting.google.com&rnum=9

ok...you've now drifted way off-topic for NANOG IMO.  This belongs in
spam-tools or spam-l.

> I was wondering if any of you use *dns* lists for whitelisting purposes.

Yes...for several years.

> I have found a couple of whitelists online (bondedsenders) and their
> m4 was far from satisfactory.

Why?  I came up with essentially the same rules (modified dnsbl.m4 to
support DNSWLs) as them back in 2001 and have been using it ever since at
multiple sites with privately maintained DNSWLs.  For that usage, it works
fine.  If you want to use it with someone else's DNSWL and they have
different 127.x.y.z return codes for different whitelisting reasons, sure,
it's too primitive, and you'll likely need to modify enhdnsbl.m4 to make
your own enhdnswl.m4, or do something similar.  Why the sendmail folks
have chosen to support DNSBLs but not DNSWLs, is still a mystery to
me...but this has little to do with network operations.

----------------------------------------------------------------------
 Jon Lewis *jlewis at lewis.org*|  I route
 Senior Network Engineer     |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________



More information about the NANOG mailing list