On Tue, Sep 29, 2015 at 10:59:15AM -0400,
 Paul Wouters <[email protected]> wrote 
 a message of 32 lines which said:

> What made things worse is that said Registrar took over the domains
> and is running those zones on their DNS servers, including an MX
> record that points to an actual mailserver.

For the record, the DNSDB data about that:

Normal MX :

bailiwick   puiterwijk.org.
count   10521
first seen   2013-04-26 14:04:22 -0000
last seen   2015-09-29 21:32:40 -0000
puiterwijk.org.   MX   10 mail.puiterwijk.org.

Hijacked MX :

bailiwick   puiterwijk.org.
count   27
first seen   2015-09-27 13:32:20 -0000
last seen   2015-09-29 13:32:05 -0000
puiterwijk.org.   MX   5 mail.b-io.co.

Normal NS :

bailiwick   puiterwijk.org.
count   48437
first seen   2013-03-23 23:58:26 -0000
last seen   2015-09-29 20:31:16 -0000
puiterwijk.org.   NS   ns0.nohats.ca.
puiterwijk.org.   NS   ns1.nohats.ca.
puiterwijk.org.   NS   ns2.foobar.fi.

Hikacked NS :

bailiwick   org.
count   129
first seen   2015-09-27 13:32:20 -0000
last seen   2015-09-29 14:36:51 -0000
puiterwijk.org.   NS   ns1.pendingrenewaldeletion.com.
puiterwijk.org.   NS   ns2.pendingrenewaldeletion.com.
 

Reply via email to