Re: Proper Way to Configure a Domain which never sends emails

2019-08-20 Thread Karl Lovink via bind-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 The reject will only work when DKIM AND SPF are failing. So you have to setup SPF too. -all does the magic. cheers, Karl On 20/08/2019 20:12, John Levine wrote: > In article > you write: >> El 20/08/2019 a las 9:28, Marco Davids via bind-users

Re: EDITED: Proper Way to Configure a Domain which never sends emails

2019-08-19 Thread Karl Lovink via bind-users
Hi, We (Arnold Holzel and I) gave a talk about SPF (with macros), DKIM, DMARC and MTA-STS during Black Hat USA two weeks ago. The slides contains example DNS records you can use. Also a kink to a Splunk app for get insight whether Your domain are abused. Link:

Re: Regarding named related issue observed with bind 9.11.5-P4 version

2019-04-10 Thread Karl Lovink via bind-users
Alan, Are you running bind on a Linux box with apparmor. Check your apparmor configuration: /etc/apparmor.d/usr.sbin.named. Cheers, Karl > On 10 Apr 2019, at 16:31, Alan Clegg wrote: > >> On 4/10/19 10:19 AM, Alan Clegg wrote: >>> On 4/3/19 5:26 AM, Chandra Rao wrote: >>> While launching

Re: Problem with zone delegation with private gTLD

2019-04-08 Thread Karl Lovink via bind-users
I cannot use a registered domain name because I’am building a phishing demo environment and I do not want to use an internet connection. Met vriendelijke groet, Karl On 8 Apr 2019, at 13:06, Matus UHLAR - fantomas wrote: >> Karl Lovink via bind-users wrote: >>> I am t

Problem with zone delegation with private gTLD

2019-04-08 Thread Karl Lovink via bind-users
Hello, I am trying to set up a private gTLD with BIND9 and underneath that gTLD a subdomain. The subdomain runs on another BIND9 server. The problem I'am facing is that the BIND9 server of the gTLD gives a NXDOMAIN for the ns record of the subdomain. If have no clue what is wrong. Can somebody