Re: Outgoing DANE not working

2020-04-14 Thread Viktor Dukhovni
On Tue, Apr 14, 2020 at 12:06:41PM -0400, Rich Felker wrote: > > Well, ISP resolvers and anycast resolvers from Google, Cloudflare, > > Verisign and Quad are generally not too far away. > > If you're on dialup or saturated DSL or cellular link, they're easily > 300-1000 ms away. Each round trip

Re: Possible header_check solution?

2020-04-14 Thread Dominic Raferd
On Tue, 14 Apr 2020 at 18:45, Rick King wrote: > > Postfix version 3.1.1 > > Hello List! > > We have a customer that occasionally receives messages like this... > > Return-Path: > From: "Free iPad " > To: > Subject:Free iPad > > From the looks of it, messages like these are from legit domains

Possible header_check solution?

2020-04-14 Thread Rick King
Postfix version 3.1.1 Hello List! We have a customer that occasionally receives messages like this... Return-Path: From: "Free iPad " To: Subject:Free iPad >From the looks of it, messages like these are from legit domains with a >carefully crafted "displayName". So the "displayName" is

Re: Outgoing DANE not working

2020-04-14 Thread Rich Felker
On Tue, Apr 14, 2020 at 02:16:20AM -0400, Viktor Dukhovni wrote: > On Mon, Apr 13, 2020 at 11:53:03PM -0400, Rich Felker wrote: > > > > Your local nameserver has already done the TCP failover and paid the > > > cost of obtaining the full RRset, your stub resolver is just failing to > > > give it

Re: Outgoing DANE not working

2020-04-14 Thread Viktor Dukhovni
On Mon, Apr 13, 2020 at 11:53:03PM -0400, Rich Felker wrote: > > Your local nameserver has already done the TCP failover and paid the > > cost of obtaining the full RRset, your stub resolver is just failing to > > give it the opportunity to return the full data to you. The performance > > cost