Re: dnssec-analyzer.verisignlabs.com aaaa lookup fail

2024-05-01 Thread Mark Andrews


> On 1 May 2024, at 22:25, Walter H. via bind-users  
> wrote:
> 
> On 01.05.2024 01:33, Mark Andrews wrote:
>> 
>>> On 1 May 2024, at 03:32, Lee  wrote:
>>> 
>>> On Mon, Apr 29, 2024 at 11:40 PM Walter H. wrote:
 On 29.04.2024 22:19, Lee wrote:
> On Sun, Apr 28, 2024 at 2:18 AM Walter H. via bind-users
>  wrote:
> 
> something that I replied to and got this in response:
> 
> Error Icon
>  Message blocked
> Your message to Walter.H@[..snip..] has been blocked. See technical
> details below for more information.
> 
> The response from the remote server was:
> 554 5.7.1 : Client host rejected: Use IPv4
> 
> 
 For explanation: this is MY mail server, which blocks IPv6 connections from
 
 Outlook.com
 Gmail.com
 ...
 
 as these are the biggest SPAM senders
>>> Which is fine .. your server, your rules.
>>> But maybe what isn't so fine is me replying only to the list and still
>>> getting a 'rejected: Use IPv4' msg.  I don't know how the mailing list
>>> works; I'm a bit surprised that I can reply only to the list, get the
>>> Client host rejected msg and somehow you can still get the msg??
> 
> there are 2 pair of shoes, mails from the list are not from Outlook.com or 
> Gmail.com
> 
> but if you put my mail address to "To: ", then its from Gmail.com ;-)
> 
>> This is
>> what happens when you put something into the rejection rules which has zero
>> relationship whether something is spam or ham.
> depends ...
>> I just find it interesting that someone using mx01.ipv6help.de as a MX would 
>> be
>> so interested in punishing IPv6 use.
> 
> you are mixing up 2 independent things ...
> 
> IPv6 clients aren't blocked at all, just Outlook.com, Gmail.com, ...
> 
> that is the difference; just for Outlook.com the following fact is true but 
> bullshit
> 
> # host -t MX outlook.com
> outlook.com mail is handled by 5 outlook-com.olc.protection.outlook.com.
> # host outlook-com.olc.protection.outlook.com
> outlook-com.olc.protection.outlook.com has address 52.101.8.47
> outlook-com.olc.protection.outlook.com has address 52.101.9.15
> outlook-com.olc.protection.outlook.com has address 52.101.40.30
> outlook-com.olc.protection.outlook.com has address 52.101.194.14
> #
> 
> as you see no IPv6 at all;
> 
> why then the need of accepting their SPAM on IPv6 transport?

Well lets look at the sender that started this thread.

% dig mx gmail.com +short
40 alt4.gmail-smtp-in.l.google.com.
5 gmail-smtp-in.l.google.com.
30 alt3.gmail-smtp-in.l.google.com.
10 alt1.gmail-smtp-in.l.google.com.
20 alt2.gmail-smtp-in.l.google.com.
% dig  gmail-smtp-in.l.google.com +short
2404:6800:4003:c01::1b
%

% dig txt gmail.com +short
"globalsign-smime-dv=CDYX+XFHUw2wml6/Gb8+59BsH31KzUr6c1l2BPvqKX8="
"v=spf1 redirect=_spf.google.com"
% dig txt _spf.google.com +short
"v=spf1 include:_netblocks.google.com include:_netblocks2.google.com 
include:_netblocks3.google.com ~all"
 dig txt _netblocks2.google.com +short
"v=spf1 ip6:2001:4860:4000::/36 ip6:2404:6800:4000::/36 ip6:2607:f8b0:4000::/36 
ip6:2800:3f0:4000::/36 ip6:2a00:1450:4000::/36 ip6:2c0f:fb50:4000::/36 ~all"
% 

Which we verify then sign to say that we have verified the incoming email.  But 
for you email from @gmail.com over IPv6 is “proof” that it is spam and you send 
back a rejection which says to send it again over IPv4 when none of the senders 
has any control over the transport being used and no one is going to add 
special rules to force email to you to go over IPv4 when you advertise MX 
servers with  addresses.

Mark
> -- 
> Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from 
> this list
> 
> ISC funds the development of this software with paid support subscriptions. 
> Contact us at https://www.isc.org/contact/ for more information.
> 
> 
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users


-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742  INTERNET: ma...@isc.org

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from 
this list

ISC funds the development of this software with paid support subscriptions. 
Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


Re: dnssec-analyzer.verisignlabs.com aaaa lookup fail

2024-05-01 Thread Walter H. via bind-users

On 01.05.2024 01:33, Mark Andrews wrote:



On 1 May 2024, at 03:32, Lee  wrote:

On Mon, Apr 29, 2024 at 11:40 PM Walter H. wrote:

On 29.04.2024 22:19, Lee wrote:

On Sun, Apr 28, 2024 at 2:18 AM Walter H. via bind-users
 wrote:

something that I replied to and got this in response:

Error Icon
  Message blocked
Your message to Walter.H@[..snip..] has been blocked. See technical
details below for more information.

The response from the remote server was:
554 5.7.1 : Client host rejected: Use IPv4



For explanation: this is MY mail server, which blocks IPv6 connections from

Outlook.com
Gmail.com
...

as these are the biggest SPAM senders

Which is fine .. your server, your rules.
But maybe what isn't so fine is me replying only to the list and still
getting a 'rejected: Use IPv4' msg.  I don't know how the mailing list
works; I'm a bit surprised that I can reply only to the list, get the
Client host rejected msg and somehow you can still get the msg??


there are 2 pair of shoes, mails from the list are not from Outlook.com 
or Gmail.com


but if you put my mail address to "To: ", then its from Gmail.com ;-)


This is
what happens when you put something into the rejection rules which has zero
relationship whether something is spam or ham.

depends ...

I just find it interesting that someone using mx01.ipv6help.de as a MX would be
so interested in punishing IPv6 use.


you are mixing up 2 independent things ...

IPv6 clients aren't blocked at all, just Outlook.com, Gmail.com, ...

that is the difference; just for Outlook.com the following fact is true 
but bullshit


# host -t MX outlook.com
outlook.com mail is handled by 5 outlook-com.olc.protection.outlook.com.
# host outlook-com.olc.protection.outlook.com
outlook-com.olc.protection.outlook.com has address 52.101.8.47
outlook-com.olc.protection.outlook.com has address 52.101.9.15
outlook-com.olc.protection.outlook.com has address 52.101.40.30
outlook-com.olc.protection.outlook.com has address 52.101.194.14
#

as you see no IPv6 at all;

why then the need of accepting their SPAM on IPv6 transport?





smime.p7s
Description: S/MIME Cryptographic Signature
-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from 
this list

ISC funds the development of this software with paid support subscriptions. 
Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users