dw> Assume I incremented the SOA so many times it wrapped around and is dw> back to the original number (because you can't prove it didn't, dw> therefore your code can't make assumptions about the SOA even if you dw> happen to have it available).
There are all sorts of ways to abuse and break DNS. But mail has enough moving parts outside your control that if you can avoid adding to the chaos, that seems like a prudent move. And you should understand what rules you're breaking and what the possible failures are. ebersman> In general, it's far more reliable for the app that is ebersman> generating the query to have any logic or load balancing or ebersman> whatever built into the app and not assume that the DNS won't ebersman> ever surprise you. dw> Agreed. But in practice, it works well enough on the small scale. If you control everything (servers, stubs, middleware, firewalls) in the chain between original querier and the auth server and the auth server, sure. In servicing email, that's a hard assumption to make. _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
