Reminder for sites using DNS blacklists with Domino 6
Do not use the osirusoft DNSBLs.
Regulars in this forum may well remember this post I made here a little over a year ago.
The osirusoft DNSBLs had been taken down by their maintainer and, in order to encourage sites to quit using them had been set to return a positive result when queried for any IP address whatsoever.
The practical consequence of this was that sites using these DNSBLs started to reject all email. Most noticed and stopped. It appears however that some sites continue to this day to use these defunct DNSBL zones, creating redundant DNS look-ups at their end and inconveniencing the owner of the osirusoft.com domain.
That said domain owner has therefore once again set up the DNS for DNSBLs in the osirusoft.com domain to return a hit on any IPv4 address. If your site is rejecting all email, this may be an important clue.
See Google Groups for further discourse on this phenomenon (which I would not have believed had I not, very recently, seen with my own eyes examples of email bounced due to osirusoft DNSBL hits).
I’ve always been curious as to what happens with any DNSBL zone we use if they went offline or are unavailable. Would the same happen for instance if spamhaus.org was unavailable?
I’m aware there are multiple mirror sites globally for spamhaus.org but what if there’s a DNS issue or if the servers are overloaded, etc.
In other words, how do we ensure mail is not rejected when using the DNSBL sites?
Subject: RE: FYI: Osirusoft DNSBLs still off the air
if domino can’t find a dnsbl server (for whatever reason) then you will incur a 2 second (maximum) timeout and then it will move on to the next dnsbl server in the list.
a positive reply must be recieved back from a dnsbl server BEFORE domino will reject the message.
Subject: RE: FYI: Osirusoft DNSBLs still off the air
Like Raymond says - just a DNS timeout and move on so no damage if the name servers for a DNSBL are unavailable.
What is different in the case of Osirusoft (and one or two others that were killed off by sustained DDoS against their operators) is that the former maintainer has listed all of IPv4 in the defunct zone to encourage people to stop using it. It is amazing how many people continue to use completely dead DNSBLs and this just consumes resources (at both ends) to no good effect. In my opinion, the tactic of listing the whole Internet in a dead DNSBL is therefore perfectly sound.
Also (slightly changing the subject) Spamhaus does also return a hit for any IPv4 address when queried using one or two common misspellings of the zone - for largely the same reasons, to discourage the waste of resources. It appears that many users cannot tell the difference between