dw> Assume I incremented the SOA so many times it wrapped around and is
dw> back to the original number (because you can't prove it didn't,
dw> therefore your code can't make assumptions about the SOA even if you
dw> happen to have it available).

There are all sorts of ways to abuse and break DNS. But mail has enough
moving parts outside your control that if you can avoid adding to the
chaos, that seems like a prudent move. And you should understand what
rules you're breaking and what the possible failures are.

ebersman> In general, it's far more reliable for the app that is
ebersman> generating the query to have any logic or load balancing or
ebersman> whatever built into the app and not assume that the DNS won't
ebersman> ever surprise you.

dw> Agreed. But in practice, it works well enough on the small scale.

If you control everything (servers, stubs, middleware, firewalls) in the
chain between original querier and the auth server and the auth server,
sure. In servicing email, that's a hard assumption to make.

_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to