[swinog] Re: Swisscom DNS issue: spectrum-conference.org wrongfully resolves to a bluewin address in swisscom mobile networks

2024-04-23 Diskussionsfäden Benoit Panizzon via swinog
Hi Samuel > That still does not answer why you as an ISP try to convince your > customers to not use Public DNS Servers, or „not seeing a reason“ in > them doing so. Let's see... why would those companies operate those public DNS Servers 'for free'? Nothing's free, right? Probably they get some

[swinog] Re: Swisscom DNS issue: spectrum-conference.org wrongfully resolves to a bluewin address in swisscom mobile networks

2024-04-23 Diskussionsfäden Benoit Panizzon via swinog
Hi Samuel > Matter of fact! That‘s what it looks like IMP is also (atleast attempting to > be) doing. (blocklist.imp.ch) I don't know this host. https://refused.breitband.ch/ here you go, not a secret. Legal background explained. > This is the exact same behaviour as Swisscom in this case.

[swinog] Re: Swisscom DNS issue: spectrum-conference.org wrongfully resolves to a bluewin address in swisscom mobile networks

2024-04-23 Diskussionsfäden Benoit Panizzon via swinog
Hi > So you are saying that relying on the provider dns and having to use > it instead of other public (non-modifying) DNS Servers will not feed > the internet provider with this „valuable personal data“? There are privacy laws in place. I would not consider this good practice. I don't think

[swinog] Re: Swisscom DNS issue: spectrum-conference.org wrongfully resolves to a bluewin address in swisscom mobile networks

2024-04-23 Diskussionsfäden Benoit Panizzon via swinog
> Part of the problem is that the user doesn’t get an error message at all, and > then mails us „hey, your website is down“. Also throwing in my 2 rappen: User notices: Provider DNS is misbehaving, blames Provider, and uses DNS of Google / Cloudflare feeding them valuable personal data. But

[swinog] Anyone else troubles with abusix.com swisscom 'false positives'?

2024-04-02 Diskussionsfäden Benoit Panizzon via swinog
Hi all Our ISP Email IP Adresses and Domains are, once more, being blacklisted @ Abusix because of, I guess, emails sent to Bluewin Spamtraps. As far as I have figured out, in contact with our customers allegedly sending spam in past cases, those are almost always false positives. There was

[swinog] Re: Contact to Ricardo Abuse Desk or Email Admin?

2024-01-30 Diskussionsfäden Benoit Panizzon via swinog
Hi Team Thank you all. I got the hint with the well-known URI :-) Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden __ Zurlindenstrasse 29 Tel +41 61 826 93 00 CH-4133 Pratteln

[swinog] Contact to Ricardo Abuse Desk or Email Admin?

2024-01-30 Diskussionsfäden Benoit Panizzon via swinog
Hi Team Does anyone have means to contact the Ricardo Abuse Desk or Email Admin? There is a possible issue with phishing regarding the CDN provider they use. Ricardo Customer and myself have attempted to bring the issue to their attention, but cases get repeatedly closed with statements like

[swinog] Microsoft massive spam outbreak

2024-01-22 Diskussionsfäden Benoit Panizzon via swinog
Hi Users of the SWINOG anti-spam blocklists. At the moment, various Microsoft IP addresses are in a similar state as this one: https://blacklist.imp.ch/entry.php?id=1.0.8.0.0.0.0.0.0.0.0.0.0.0.0.0.2.1.e.2.3.0.4.f.1.1.1.0.1.0.a.2 Unfortunately, Microsoft has confirmed to me, they use the same

[swinog] attn: ip-plus postmaster regarding issue on: mail.swisscom.com

2023-10-20 Diskussionsfäden Benoit Panizzon via swinog
Hi List Trying that way. Could the ip-plus postmaster contact me off-list please: Regarding emails to Swisscom employees reproducible disappearing after being successfully received on: mail.swisscom.com. [138.188.176.225] Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A

[swinog] Re: Email Outage @ NZZ?

2023-09-25 Diskussionsfäden Benoit Panizzon via swinog
Hi List *sigh*... May I ask for help again? 13.111.14.63 not in iptables, so it looks like Fail2Ban is not the culprit this time. Since 24.9.2023 23:00 no connections in our log nor hostname mta.email.nzz.ch connecting. Two Customer complaining that NZZ has sent a newsletter this morning which

[swinog] Email Outage @ NZZ?

2023-08-31 Diskussionsfäden Benoit Panizzon via swinog
Hi List Anyone from NZZ on this list? It looks like we have a couple of customers complaining not receiving emails from NZZ since almost 14 days and sender not getting any bounces. What I suspect when looking at the logs is an outage at SalesForce aka mta.email.nzz.ch[13.111.14.63] from which I

[swinog] DNSSEC issue with swizzonic DNS servers?

2022-12-28 Diskussionsfäden Benoit Panizzon via swinog
Hi List Fancy another DNS issue hunt? We have DNSSEC validation enabled on our BIND DNS Servers. We started seeing: no valid RRSIG resolving 'www.numberportability.ch/DS/IN': 2a01:8100:2901::1:183:202#53 no valid RRSIG resolving 'www.numberportability.ch/DS/IN': 2a01:8100:2901::1:183:201#53

[swinog] Re: Is AS203790 reading this list? (up-network.ch)

2022-10-27 Diskussionsfäden Benoit Panizzon
Hi Alex > Let me guess: You've got an abuse report to your abuse e-mail address > about some IP ranges and domains (including up-network.ch) which have > no relation to your AS at all? > > If yes: You're not the only one. Yes after the 3rd report, from yet another source we got after I sent the

[swinog] Re: MaxMind location determination (was: Contact: geoiplookup.net)

2022-10-20 Diskussionsfäden Benoit Panizzon
Last update Kudos to Andrew from MaxMind. He 'locked' all ImproWare Ranges to country: CH so no other sources should be able to change them as we observed repeatedly over the last months. Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden

[swinog] Re: switch started blocking whois queries?

2022-10-17 Diskussionsfäden Benoit Panizzon
Weird, switch only seems to support legacy ip. whois.nic.ch has address 130.59.31.241 whois.nic.ch has IPv6 address 2001:620:0:ff::b $ whois -h 130.59.31.241 imp.ch This information is subject to an Acceptable Use Policy. See https://www.nic.ch/terms/aup/ Domain name: imp.ch [...] $ whois -h

[swinog] Re: switch started blocking whois queries?

2022-10-17 Diskussionsfäden Benoit Panizzon
>whois alphanet.ch > > works from UPC/Sunrise, SWITCH and init7 for me. Tnx, opening case with Switch. Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden __ Zurlindenstrasse 29

[swinog] switch started blocking whois queries?

2022-10-17 Diskussionsfäden Benoit Panizzon
Hi Gang From three different IP Addresses I get: Requests of this client are not permitted. Please use https://www.nic.ch/whois/ for queries. Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden

[swinog] Re: DNS help: named 'end of file resolving' a hostname.

2022-10-17 Diskussionsfäden Benoit Panizzon
Hi Beat > May it be this issue? > https://gitlab.isc.org/isc-projects/bind9/-/issues/3474 Thank you and all who took the time investigating the issue. I'm not so sure it's bound to that issue. But nevertheless I now opened an issue myself. Let's see. Mit freundlichen Grüssen -Benoît

[swinog] MaxMind location determination (was: Contact: geoiplookup.net)

2022-10-17 Diskussionsfäden Benoit Panizzon
Hi One more update after managing to get in contact with a Human @ MaxMind. What I am piecing together from my exchanges with MaxMind. They get location information, from some service providers who use GPS data from their apps to connect an IP to a location. So they trust those locations to be

[swinog] Re: Contact: geoiplookup.net

2022-10-13 Diskussionsfäden Benoit Panizzon
Short update on that issue... > Does anyone know who operates geoiplookup.net and how to contact them? It looks like they source their Data from MaxMind but are solver implementing corrections and therefore lacking behind corrections published there. The issue we have is not with content, but

[swinog] Contact: geoiplookup.net

2022-10-11 Diskussionsfäden Benoit Panizzon via swinog
Hi Swinogers Does anyone know who operates geoiplookup.net and how to contact them? They repeatedly put parts of our IP ranges into Germany creating vast service disruptions for our affected customers by Swiss service providers that use their API for GeoBlocking. Mit freundlichen Grüssen

[swinog] contact to 'swisshost.ch'?

2022-05-19 Diskussionsfäden Benoit Panizzon
Hi Community! Does anyone know how to contact the Zürich based hosting company swisshost.ch? One of our customer has an email issue (causing spam reports being sent to our abuse desk) which could be due to an MX on a domain they own pointing to a host which has probably been repurposed as

Re: [swinog] CDN: Access Denied Reference #18.cad1f557.1634833505.1903b12e

2021-10-26 Diskussionsfäden Benoit Panizzon
> Are you sure Amazon is responsible? I mainly see Akamai as a CDN here. But > maybe it's different, depending on the source IP address... Aeh! s/Amazon/Akamai/ sorry! > For Akamai, this may be of interest: > https://www.akamai.com/us/en/clientrep-lookup/ I stumbled over this page, but

Re: [swinog] CDN: Access Denied Reference #18.cad1f557.1634833505.1903b12e

2021-10-26 Diskussionsfäden Benoit Panizzon
Hi Jeroen > Did you check if the customer's network is maybe infected with some botnet or > spambot that triggers honeypots? Usually we learn about such incidents through GovCert or other complaints. We received none. > Clearly, if the IP changes and the customer gets blocked again, it is >

[swinog] CDN: Access Denied Reference #18.cad1f557.1634833505.1903b12e

2021-10-26 Diskussionsfäden Benoit Panizzon
Dear Colleagues We have a customer whose IP keep getting blocked by various CDN operators. If we change his IP, this solved the issue for a couple of days, then he is blocked again. Actual IP: 87.102.212.133 At the moment, this IP is being blocked by the CDN used by: klm.com nespresso.com

Re: [swinog] Cloudflare DMCA Takedown requests - but content not present under mentioned IP

2021-07-06 Diskussionsfäden Benoit Panizzon
Am Tue, 6 Jul 2021 12:01:58 +0200 schrieb Markus Wild : > I find this a bit odd, that they'd send you take-down requests for their own > IP addresses No, that was me resolving the domain. :-) They of course mention the IP in our ranges, which I don't want to expose here as I can not find

[swinog] Cloudflare DMCA Takedown requests - but content not present under mentioned IP

2021-07-06 Diskussionsfäden Benoit Panizzon
Dear List I am a bit puzzled by repeated Cloudflare Takedown Requests regarding the domain: lord-film.cash we are getting. lord-film.cash has address 172.67.181.230 lord-film.cash has address 104.21.32.5 lord-film.cash has IPv6 address 2606:4700:3035::6815:2005 lord-film.cash has IPv6 address

[swinog] Coop.ch geoblocking?

2021-02-28 Diskussionsfäden Benoit Panizzon
Dear List Having issue in accessing www.coop.ch "Aus Sicherheitsgründen ist ein Login aus Ihrem Land nicht erlaubt". And a hint I shall not use a VPN or Proxy. No proxy or VPN in use, just IPv4 NAT, as confirmed by 'wieistmeineip'. (www.coop.ch is not IPv6 yet) So I supposed a messed up GeoIP

Re: [swinog] Spam from 'Rocketmails.ch'

2020-10-12 Diskussionsfäden Benoit Panizzon
> I will send another query to that other company, Sandro Achilles Photography > Corporation, Voltastrasse 66, 8044 Zurich and see what happens next. Bullseye! I will contact her (Ms. G. from Rocket Mountain AG) and provide her an absolute proof, that S.A. used to work in the management @

Re: [swinog] Spam from 'Rocketmails.ch'

2020-10-06 Diskussionsfäden Benoit Panizzon
Hi Marc Did you get a reply to your request? I had further contact with them, but they don't seem to grasp the issue. They tell me that their contract with the list owners only allow them to disclose the source of their data to the actual recipients. Yes, I understand and I keep telling them to

Re: [swinog] Spam from 'Rocketmails.ch'

2020-09-21 Diskussionsfäden Benoit Panizzon
Hi Gang Update about today's call with Rocket Mountains AG. Q: Involvement of rocketmails.ch: They used to work together in the past but have split since. They don't know why their emails contained the 'wrong' sender and reply-to header and are investigating the issue. (I'll also ask Tassero).

Re: [swinog] Spam from 'Rocketmails.ch'

2020-09-21 Diskussionsfäden Benoit Panizzon
Hi Also an Update from my Side. Tassero (the ESP) also told Rocket Moutain AG to contact me to solve the issue. I had a first phone call with the responsible @ Rocket Mauntain AG. She also told me that rocketmails.ch has nothing to do with them and that therefore they would never answer the

Re: [swinog] Announcement of 'china government' routes 125.208.4[567].0/24 forbidden?

2020-08-27 Diskussionsfäden Benoit Panizzon
Well, when I use the Sunrise LG: BGP routing table entry for 125.208.47.0/24, version 252176985 Paths: (4 available, best #1, table default) Not advertised to any peer ^-- see! 4134 24151 193.192.254.35 from 193.192.254.35 (212.161.178.83) Origin incomplete, metric 20,

[swinog] Announcement of 'china government' routes 125.208.4[567].0/24 forbidden?

2020-08-27 Diskussionsfäden Benoit Panizzon
Hi List A customer complained, he cannot reach the website of chinese embassy in Switzerland. CH.CHINA-EMBASSY.ORG The DNS Servers are hosted under 125.208.4[567].0/24 and none of our peers do announce those routes to us. The all, according to the looking glasses, seem to get those routes

Re: [swinog] DMARC Reports from Swiss Internetproviders

2020-08-04 Diskussionsfäden Benoit Panizzon
Hi Andres > Does anybody know, if Swiss Internetproviders do send DMARC Reports in theyr > Email Service? > https://de.wikipedia.org/wiki/DMARC Well, publish ruf / rua _DMARC txt entry for your domain and see what you get :-) We started sending reports about a month ago for our domains hosted

[swinog] Looking for contact to: Green Abuse Desk regarding blacklisting caused by backscatter from email sent with fake envelope sender.

2020-03-10 Diskussionsfäden Benoit Panizzon
Hi Hopefully somebody from the Green Abuse Desk is reading this and willing to contact me off-list regarding the blacklisting of green mail platform ip addresses because of a backscatter issue? I fear ab...@green.ch is handled by the enduser customer service as it looks they did not understand

[swinog] Any Green.ch DNS Admin on this list?

2020-02-13 Diskussionsfäden Benoit Panizzon
Hi List To migrate a couple of DNS Zones from green to another DNS operator. I need the zone files. I am giving up on the green customer service. So if a green tech with access to the zone files (as raw as possible, for example extracted by 'dig AXRF') is reading this, please contact me

[swinog] Advertizement from OFCOM (dot.swiss) to .swiss domain owners?

2020-01-31 Diskussionsfäden Benoit Panizzon
Dear List I am frowning upon an advertisement email I just got from OFCOM to the owner contact email address of a .swiss domain. Not only am I inclined to consider such emails as 'unlauter' but I am also very concerned that such emails are sent from an ESP in the US who has confirmed on several

[swinog] DNS issue @ metanet?

2020-01-17 Diskussionsfäden Benoit Panizzon
Hi Community Since yesterday we see more and more message of the kind: (host mail.zabli.ch[80.74.146.90] said: 450 4.7.1 Client host rejected: cannot find your hostname, [157.161.13.198] (host mx03.sui-inter.net[80.74.146.163] said: 554 IP name lookup failed. No PTR record found (host

Re: [swinog] SBB partially reachable via IPv6

2019-10-21 Diskussionsfäden Benoit Panizzon
Works for me: $ telnet sbb.ch https Trying 2a00:4bc0::::c296:f58e... Connected to sbb.ch. $ openssl s_client -connect sbb.ch:https CONNECTED(0003) depth=2 C = CH, O = SwissSign AG, CN = SwissSign Gold CA - G2 verify return:1 depth=1 C = CH, O = SwissSign AG, CN = SwissSign EV Gold CA

Re: [swinog] Geldspielgesetz: Zugangssperren Q

2019-06-28 Diskussionsfäden Benoit Panizzon
Guten Morgen Alex > Frage hierzu: Müssen wir die landingpage 1:1 übernehmen oder darf > jeder diese ein wenig „optimieren“? Ich denke hier an einen Link zu > einer Petitionsseite falls der Benutzer solche Staatszensuren nicht > mehr sehen möchte. Ich habe dies spezifisch nicht gefragt, aber

[swinog] Geldspielgesetz: Zugangssperren Q

2019-06-27 Diskussionsfäden Benoit Panizzon
Hallo zusammen Nachdem ich ausgiebigen Kontakt mit Suissedigital hatte, hier noch ein paar Infos zusammengefasst, welche Euch vermutlich auch interessieren könnte. F: Wann muss dies umgesetzt sein? A: Die Behörden sind noch nicht so weit. Es gibt keine Liste von zu sperrenden Domains, welche

Re: [swinog] Geldspielgesetz: Zugangssperren. Wirklich vom Volk so gewünscht?

2019-06-25 Diskussionsfäden Benoit Panizzon
Hallo Xaver Naja, ich meinte nicht Port 53 'sperren' sondern den Traffic auf die eigenen DNS mit entsprechenden 'Fake' Zonenfiles für die Spielbanken umleiten. Dies würden möglicherweise die Kunden nicht mal so deutlich merken und alles andere würde weiterlaufen, aber Google und Co und auch

Re: [swinog] Geldspielgesetz: Zugangssperren. Wirklich vom Volk so gewünscht?

2019-06-25 Diskussionsfäden Benoit Panizzon
Hallo Christian > Die Abstimmung war am 10. Juni 2018. Du findest sie hier: > https://www.admin.ch/gov/de/start/dokumentation/abstimmungen/20180610/Geldspielgesetz.html Danke, dort wird nirgendwo das Wort 'DNS' gefunden. Woher kommt der Beschluss dies IMHO ziemlich untauglich via DNS

[swinog] Geldspielgesetz: Zugangssperren. Wirklich vom Volk so gewünscht?

2019-06-25 Diskussionsfäden Benoit Panizzon
Hallo zusammen Ich darf mich mit der Aufforderung der Eidgenössische Spielbankenkommission und Suissedigial auseinandersetzen die gewünschten DNS Sperren bei uns per 1. Juli einzurichten. Es geht mir hierbei hauptsächlich um die technische Umsetzung, so dass der Wunsch der ESBK wirklich

[swinog] What are the legal requirements of swiss email providers to identify users?

2019-06-17 Diskussionsfäden Benoit Panizzon
Hi List Lately we received mass advertizement emails sent via protonmail.com an email provider offering freemail and commercial email accounts. One of the first statements on their website is: Quote: "ProtonMail is incorporated in Switzerland and all our servers are located in Switzerland. This

[swinog] Swisscom operating Business Customer Mailservices from 'Mobile' IP Ranges?

2019-03-15 Diskussionsfäden Benoit Panizzon
Hello List We have some issues with emails sent from the kpt.ch online plattform over Swisscom Mobile IP Range: inetnum:138.188.0.0 - 138.188.255.255 netname:Swisscom-Mobile country:CH There is no SPF entry and the sending ip addresses are not listed by dnswl.org nor the

[swinog] Weird Bluewin Server Problem (occasional 550 5.1.1)

2019-01-24 Diskussionsfäden Benoit Panizzon
Dear List Has anyone else experienced this problem? According to our customer, it occurred a couple of times in the last days: Sender and Destinations are the same in all examples: Our customer is sending an email to bluewin: Jan 23 13:32:42 obelix postfix-submit.obelix/smtp[28721 C5015C0CE5:

[swinog] How do website operators get the mobile phone number of visitors?

2018-12-06 Diskussionsfäden Benoit Panizzon
Hi List I have read: https://nakedsecurity.sophos.com/2012/01/25/smartphone-website-telephone-number/ And I have sniffed the traffic between my swisscom mobile Samsung Mobile and my Website, but can't find any of the additional headers disclosing my phone number. Is there a trick to make a

[swinog] Do ISP still offer outgoing smtp relaying services to business customers with own smtp server?

2018-11-16 Diskussionsfäden Benoit Panizzon
Dear List We sometimes get requests from business customers, with own mailserver, which directly receives email via smtp, for an outgoing smtp-relay. I then argue with: * Their server is absolutely capable of sending emails directly * They have better control of the sending process. * They can

[swinog] Any tech from IncaMail Swiss Post on this list?

2018-08-21 Diskussionsfäden Benoit Panizzon
Hi List I wonder if a tech from IncaMail Swiss Post (sender: swissp...@im.post.ch) source: gw1.incamail.com [194.41.147.13] is on this list and could contact me off-list to check on something? I contacted their abuse desk and support, regarding excessive bounce generation, probably due to some

Re: [swinog] strange DNS issues with swinog blacklists

2018-08-14 Diskussionsfäden Benoit Panizzon
> whois show cyon operating the swinog.ch DNS Servers and there the glue > records look right. Uhm, die cyon delete the glue records right now? I contacted the hostmaster ser...@cyon.ch about the issue. Mit freundlichen Grüssen -Benoît Panizzon- -- I m p r o W a r e A G-Leiter

[swinog] strange DNS issues with swinog blacklists

2018-08-14 Diskussionsfäden Benoit Panizzon
Hi Team We have reports of troubles accessing the swinog blacklists. Did SWINOG change Nameservers lately? http://www.zonecut.net/dns/?domain=dnsrbl.swinog.ch still points to switch and saitis and have weird glue record issues. whois show cyon operating the swinog.ch DNS Servers and there the

Re: [swinog] Huge Packetloss towards switch mirrors?

2018-08-09 Diskussionsfäden Benoit Panizzon
Am Thu, 9 Aug 2018 10:59:47 +0200 schrieb Claudio Kuenzler : > Update: Switch just changed something in their routing. > No packet loss anymore from both source networks. PING ch.archive.ubuntu.com(frisal.switch.ch (2001:620:0:1002::20)) 56 data bytes ^C --- ch.archive.ubuntu.com ping statistics

[swinog] Huge Packetloss towards switch mirrors?

2018-08-09 Diskussionsfäden Benoit Panizzon
Hi Community Anyone else experiencing high latency and packetloss towards ch.archive.ubuntu.com / mirror.switch.ch IPv4 via SwissIX. IPv6 via HE. --- frisal.switch.ch ping statistics --- 99 packets transmitted, 34 received, 65% packet loss, time 99279ms rtt min/avg/max/mdev =

[swinog] GDPR / DSGVO and 'whois' domain data

2018-07-02 Diskussionsfäden Benoit Panizzon
Dear Swinogers. I run a couple of .com and .ch domains, which are registered via Gandi.net About one week ago, Gandi activated 'privacy protect' on my .com domains, hiding all my contact data in the whois output, without me asking them to do so. They sent an email though, that they would do so

Re: [swinog] Help with DNSSEC issue... (bncr.fi.cr)

2018-04-09 Diskussionsfäden Benoit Panizzon
Hi Oli > The most likely reason: > Bind 9.11 enables EDNS cookies by default, but the authoritative > servers for this domain do not handle EDNS correctly: > > https://ednscomp.isc.org/ednscomp/b01039e111 > > quick fix: > server NSNAME { send-cookie no; }; That was the cause and the fix.

[swinog] Help with DNSSEC issue... (bncr.fi.cr)

2018-04-09 Diskussionsfäden Benoit Panizzon
Hi List Usually I have no problems identifying DNSSEC issues, but I don't get this one. Our two main caching DNS Servers run bind 9.11.2-P1, after flushing the cache and even restarting still see an issue with this domain: 09-Apr-2018 09:28:25.934 no valid RRSIG resolving

[swinog] What email headers need to be understood by a PGP/MIME enabled email client?

2018-02-15 Diskussionsfäden Benoit Panizzon
Hello fellow Swinogers To exchange emails containing potentially sensitive customer information with swisscom, we agreed to use PGP encrytped emails. Now when swisscom is sending an encrypted attachment to us, we get those MIME Headers: --=_Part_5064522_1012233884.1518535424993

Re: [swinog] Bluewin Error: Der MX-Eintrag fuer die Domaene aerni.com kann nicht verifiziert werden

2018-01-12 Diskussionsfäden Benoit Panizzon
Hi Marcel > As for the issue at hand: the DNS servers of your customer are (were) > not properly reachable from our IP ranges or more specifically we are > (were) unable to get the IPs for ns1.aerni.com or ns2.aerni.com. > During our investigation this resolution has mostly recovered and we > are

Re: [swinog] Bluewin Error: Der MX-Eintrag fuer die Domaene aerni.com kann nicht verifiziert werden

2018-01-12 Diskussionsfäden Benoit Panizzon
Dear List Ok, thank you for the replies as they all point out an apparent PTR Problem, let me reply to the list. According to my knowledge of the DNS rfcs (I did not look it up right now). A Host resource may point to an A record another host resource is already pointing to. A Host resource

[swinog] Bluewin Error: Der MX-Eintrag fuer die Domaene aerni.com kann nicht verifiziert werden

2018-01-12 Diskussionsfäden Benoit Panizzon
Hello List Does anyone know, how bluewin does 'verify' an MX? The MX of our customer is prefectly reachable for sender verification but his emails sent 'to' bluewin recipients are getting blocked with: MAIL FROM: <[scrubbed]@aerni.com> Unable to verify MX-Record for domain aerni.com aerni.com

Re: [swinog] What blacklists does @bluewin.ch use

2017-10-31 Diskussionsfäden Benoit Panizzon
Hi Franco and Swinogers Posting on SWINOG does seem to accelerate problem solving sometimes :-) Swisscom has contacted our customer, explained and solved the issue. Apparently the installed a new anti-spam measure short time ago (I don't know if cloudmark is involved). They count the number of

[swinog] What blacklists does @bluewin.ch use

2017-10-31 Diskussionsfäden Benoit Panizzon
Hello List A Mailserver from a business customer of ours is blacklisted @ bluewin. The Error Message from Bluewin MXes directing to the removal site: https://www.swisscom.ch/en/res/hilfe/ip-blacklist.html Our customer has requested removal via this form, no success. Our customer has contacted

[swinog] GSM AT command to set 'Validity Period'?

2017-10-16 Diskussionsfäden Benoit Panizzon
Dear Swinogers We use smsd to send our nagios alarms via a GSM usb stick. I'm looking for some advice after I was not able to find a working solution. The mobile operator we use has a somewhat short queue to accept SMS and when a recipient is not getting the SMS (mobile off during vacation or

Re: [swinog] Advice after hoax

2017-05-19 Diskussionsfäden Benoit Panizzon
Hi Dan Operating anti-spam blacklists, adding my email address to all kind of newsletters, online contests etc. apparently is a common revenge from spamers who get listed. Unfortunately too many ESP operators still don't understand that 'real' double opt-in would solve the issue. According to

[swinog] Bind9 9.9.5 memory exhaustion attack?

2017-02-04 Diskussionsfäden Benoit Panizzon
Hello All Anyone else running bind9 and seeing a lot of request with permuted case in the requested resource, which I fear causes bind9 to cache each reply individually leading to memory exhaustion? -Benoît- ___ swinog mailing list

Re: [swinog] UPC Mailservers problems with greylisting

2017-01-12 Diskussionsfäden Benoit Panizzon
Hi Update on the Problem. I got two replies, one yesterday stating, that the problem is about our side, that the UPC servers rotate between 3 IP addresses and this causes problems with greylisting. => Fact: Already last week I told them I see those 3 IP Addresses from within the same /24 and

Re: [swinog] UPC Mailservers problems with greylisting

2017-01-05 Diskussionsfäden Benoit Panizzon
Quick update on that case. UPC Switzerland is fully aware of the problem. The Mail-Platform in the Netherlands is operated by UPC Austria (probably chello.at). And they still deny that there is a problem on their side and blame the ISPs that do greylisting. UPC Switzerland is trying to escalate

Re: [swinog] UPC Mailservers problems with greylisting

2017-01-05 Diskussionsfäden Benoit Panizzon
Hi Per > Is there any point in greylisting genuine mailservers? We only > greylist dodgy-looking setups. True, no point in greylisting a propper SMTP engine that does queueing and would resend the email later in case of a 4XX error. But how do you find out which ip's to greylist and which not

Re: [swinog] UPC Mailservers problems with greylisting

2017-01-05 Diskussionsfäden Benoit Panizzon
Hi > I do not greylist servers with correct spf record. With UPC i think > the main problem is the missing NDR. We also do not greylist if the SPF record matches. We do not greylist IP's listed in the DNSWL.org or SWINOG Whitelist either. But none of this was true for the new 'NL' ranges used

Re: [swinog] UPC Mailservers problems with greylisting

2017-01-03 Diskussionsfäden Benoit Panizzon
Same Problem here, since at least 24. December. Opened a case today @ UPC. I keep you updated. -- -Benoît Panizzon- -- I m p r o W a r e A G-Leiter Commerce Kunden __ Zurlindenstrasse 29 Tel +41 61 826 93 00 CH-4133

Re: [swinog] Swiss ISPs and IPv6 --- 2016 edition

2016-09-20 Diskussionsfäden Benoit Panizzon
> Management of companies need to be convinced. Technical folks > typically know that they want it, but are not allowed to play with > it... Oh, I have heard a lot of tech excuses: * Why should I bother with IPv6? IPv4 works fine! * There could be potential security issues with IPv6, so better

Re: [swinog] 'known' DNS Problems with Migros Banking App?

2016-08-09 Diskussionsfäden Benoit Panizzon
Hi Daniel In the meantime, the Migros APP Support center called me again. They got in contact with the customer for further investigation in the problem and think they found the Problem. The customer has an older ZyXEL WLAN Router with NAT. The APP apparently uses some kind of ipsec

[swinog] 'known' DNS Problems with Migros Banking App?

2016-08-09 Diskussionsfäden Benoit Panizzon
Hello One customer contacted us, because the Migros Banking App does not work from within our network and asked me to contact the Migros NOC to find out what we should change to make it work. From the Migros NOC I got the feedback, that this is an issue they observed with customers whose ISP

[swinog] Zukunft von Abuse Desks (was: Reject von hotmail.com)

2016-03-18 Diskussionsfäden Benoit Panizzon
Hallo David > Google hat uebrigens auf "mailop" (eine Mailing-Liste fuer Mail > Hoster) gesagt, dass es bei ihnen auch passieren kann, dass ganze > netblocks blockiert werden: > https://www.mail-archive.com/mailop@mailop.org/msg01042.html Danke für den Hinweis. Ich versuche seit Monaten das

Re: [swinog] UPC rejecting mails as spam?

2015-12-10 Diskussionsfäden Benoit Panizzon
Hi Per > Does anyone @UPC happen to know what this means: > > host mx.hispeed.ch [213.46.255.2]: 552 5.2.0 rl4b1r00p3kCCMl01l4bgK > automated process detected unsolicited content > > The email is being sent from a UPC connection, via Hostpoint > (mail.hostpoint.ch) to a user @swissonline.ch. >

Re: [swinog] Bluewin MX Protocol Errors

2015-11-02 Diskussionsfäden Benoit Panizzon
Hält sich in Grenzen: # grep postfix-submit /var/log/mail.log | grep relay=mxbw.lb.bluewin.ch | grep -i bounce | wc -l 64 # grep postfix-submit /var/log/mail.log | grep relay=mxbw.lb.bluewin.ch | grep -i -v bounce | wc -l 2919 -Benoît Panizzon- -- I m p r o W a r e A G-Leiter

Re: [swinog] UPC-Cablecom and ip6.arpa

2015-06-18 Diskussionsfäden Benoit Panizzon
when they get a notification and will re-submit it with the approval key or password. Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 Pratteln

[swinog] Blacklisting of orange.fr mailserver ranges

2015-06-02 Diskussionsfäden Benoit Panizzon
:193.252.23.174 - 193.252.23.183 inetnum:193.252.23.186 - 193.252.23.255 Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 Pratteln

Re: [swinog] .ch registrars : goodbye nic.ch, but where to go then ?

2015-05-11 Diskussionsfäden Benoit Panizzon
the registrars? Solved by openid or a similar technique? Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02 Schweiz

Re: [swinog] RFC1918 IP's im Internet-Trace outbound - eine Unsitte - oder liege ich falsch ?

2015-03-06 Diskussionsfäden Benoit Panizzon
höchsten in Richtung zum eigenen Kunden, weil es im lokalen Netz geroutet wird, und auch nur wenn der Kunde hinter seinem NAT nicht dasselbe Netz nutzt und der NAT Router des Kunden RFC1918 nicht droppt. Gruss Benoit Panizzon -- I m p r o W a r e A G

Re: [swinog] Suche nach neuem Registrar

2015-01-23 Diskussionsfäden Benoit Panizzon
* Price That would give a nice overview and facilitate choosing the right one. Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 Pratteln

Re: [swinog] Suche nach neuem Registrar

2015-01-23 Diskussionsfäden Benoit Panizzon
https://docs.google.com/spreadsheets/d/1UWK6ijLCiLXSIuTT4sS_h0zCqPMCjjhry0b yQprysts/edit?usp=sharing Nice! exactly what I had in mind :-) Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29

[swinog] Danke Switch für die Offenlegung des Registrars

2015-01-12 Diskussionsfäden Benoit Panizzon
findet man auch nicht auf der Webseite, ob dessen DNS-Server überhaupt via IPv6 erreichbar sind, ob diese IPv6 Glue Records und DNSSEC unterstützen, und ob man die DS Records selber aktualisieren kann oder nur via Kundendienst etc. Wird dies auch noch kommen? Mit freundlichen Grüssen Benoit

Re: [swinog] upc cablecom - mail.upccablecom-emailbilling.ch

2014-06-12 Diskussionsfäden Benoit Panizzon
Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02 Schweiz Web http://www.imp.ch

[swinog] Google DNS outage?

2014-05-26 Diskussionsfäden Benoit Panizzon
Hey there Anyone still able to resolve Google? Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02

[swinog] .com registrar that offers DS records and IPv6 Glue

2014-05-23 Diskussionsfäden Benoit Panizzon
Hello I'm on a task that turn out to be harder that I expected. From switch.ch registered .ch domains I'm used to be able to specify the IPv6 addresses of my DNS servers and to upload the DS keys needed for the DNSSEC chain. Now I would like to do the same for a .com domain. But as of today

[swinog] Broken SPF Check implementation in Microsoft Exchange Forefront?

2013-12-02 Diskussionsfäden Benoit Panizzon
implementation. Or did the exchange admin just misconfigure his server? Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41

[swinog] Google IPv6, wrong Geolocation?

2013-10-07 Diskussionsfäden Benoit Panizzon
: CH Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02 Schweiz Web http

Re: [swinog] How to automate abuse complaints for ip based violations

2013-08-23 Diskussionsfäden Benoit Panizzon
via DNS: $ host -t txt 0.0.161.157.abuse-contacts.abusix.org 0.0.161.157.abuse-contacts.abusix.org descriptive text ab...@imp.ch Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29

Re: [swinog] DDOS DNS Attack by Netgear Products caused by CNAME instead of A record?

2013-05-24 Diskussionsfäden Benoit Panizzon
Hi Jeroen You want to deploy RRL. Please see http://www.redbarn.org/dns/ratelimits Excellent, thank you. Didn't know that bind feature. Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29

[swinog] Email forwarding and backscatter, any idea how to solve?

2013-04-26 Diskussionsfäden Benoit Panizzon
freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02 Schweiz Web http://www.imp.ch

[swinog] TSP: Agreement template for 'clip no screening' / 'special arrangement'

2013-03-18 Diskussionsfäden Benoit Panizzon
use as a template for our agreement? Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02 Schweiz

[swinog] MS DNS creating invalid records rejected by Bind check-names?

2012-08-30 Diskussionsfäden Benoit Panizzon
A record with underscore is re-created by the ADS and the problem is back. Is this some kind of MS DNS bug, or have the DNS RFCs been updated recently to also allow underscores in other RR and some non bleading edge versions of bind still use the check from previous rfc? Benoit Panizzon -- I m p

[swinog] 'Foreign' IP Addresses assigned to swiss customers?

2012-07-06 Diskussionsfäden Benoit Panizzon
? Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02 Schweiz Web http://www.imp.ch

[swinog] Pro / Contra Backup MX?

2012-05-24 Diskussionsfäden Benoit Panizzon
can you avoid the disatvantage to generate a shitload of bounces when operating ab backup MX? - Is it true, that most ISP offer this kind of service? Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G

[swinog] Pro / Contra Smarthosting

2012-05-24 Diskussionsfäden Benoit Panizzon
email infrastructure as smarthost? Mit freundlichen Grüssen Benoit Panizzon -- I m p r o W a r e A G- __ Zurlindenstrasse 29 Tel +41 61 826 93 07 CH-4133 PrattelnFax +41 61 826 93 02 Schweiz

Re: [swinog] What GeoIP Locator service do srf.ch, bluewin.ch and iTunes use?

2012-01-26 Diskussionsfäden Benoit Panizzon
Hello The Problem was solved. They use an offline version of the wipmania.com GeoIP Database. They added our range to their offline database and we have also submitted the range to wipmania.com as it was flagged 'unknown'. -Benoit- ___ swinog

[swinog] What GeoIP Locator service do srf.ch, bluewin.ch and iTunes use?

2012-01-25 Diskussionsfäden Benoit Panizzon
://www.ipaddresslabs.com and http://www.maxmind.com Do locate the ip addresses correctly to switzerland. So I suppose SRF uses some other service. Does somebody know what GeoIP Locator services srf.ch uses? The SRF IT Helpdesk was not able to tell me. Kind regards Benoit Panizzon -- I m p r o W

  1   2   >