>I was able to contact AOL
amazing
>and they did confirm that the missing PTR is my biggest problem.
astonishing. There are huge numbers non-spamming mail servers out
without the reverse set up. I can't believe AOL has a policy that
requires reverse delegation and matching PTR records, just can't.
# dig pixelpushers.com a
; <<>> DiG 8.2 <<>> pixelpushers.com a
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 1
;; QUERY SECTION:
;; pixelpushers.com, type = A, class = IN
;; ANSWER SECTION:
pixelpushers.com. 21h22m20s IN A 216.216.166.169
;; AUTHORITY SECTION:
pixelpushers.com. 21h22m20s IN NS dns1.siliconstorm.com.
pixelpushers.com. 21h22m20s IN NS dns2.silisonstorm.com.
;; ADDITIONAL SECTION:
dns1.siliconstorm.com. 1d18h31m42s IN A 216.216.166.5
where's the A record for dns2????
# dig -x 216.216.166.169
; <<>> DiG 8.2 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUERY SECTION:
;; 169.166.216.216.in-addr.arpa, type = ANY, class = IN
;; ANSWER SECTION:
169.166.216.216.in-addr.arpa. 1D IN PTR ATHM-216-216-xxx-169.home.net.
;; AUTHORITY SECTION:
166.216.216.in-addr.arpa. 1D IN NS ns1.home.net.
166.216.216.in-addr.arpa. 1D IN NS ns2.home.net.
>I'm no DNS guru and I'm not sure how to supercede @home's
>reverse lookup information.
As Scott said, you can't, you don't have authoriy over the reverse
zone. You can't fix anything until home.net's DNS delegate reverse
authority to your DNS. good luck
>I'm using DeEnesse 2.13 with Bind 4.9.7 on a Windows NT Server 4.0 SP6
BIND 4.9.7 has the same vulnerability as BIND 8.2.2. You should get
4.9.8 (Larry Kahn's site) at least or upgrade to 8.2.3.
Attn EVERYBODY running BIND: if your are not running BIND 4.9.8 or
BIND 8.2.3 but something earlier, your DNS is vulnerable. There are
scanners that are now taking down every DNS they can find, you should
assume they will get yours. There is even a rootkit/virus called
LiOn for Linux based on this vulnerabilty.
>I have attached my reverse.DNS file
Since your DNS is not authoritative for the reverse zone, it doesn't
matter what you put in your reverse zone since Internet will not look at it.
Len
http://MenAndMice.com/DNS-training : In Austin, TX; SFO, CA; Paris,
FR
http://BIND8NT.MEIway.com : ISC BIND 8.2.3 "NT3" for NT4 & W2K
http://IMGate.MEIway.com : Build free, hi-perf, anti-abuse mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/