> -----Original Message----- > From: Dirk Bonengel [mailto:[EMAIL PROTECTED] > Sent: Thursday, August 11, 2005 5:01 PM > To: Dallas L. Engelken > Cc: users@spamassassin.apache.org > Subject: Re: Phishing IP listed in URIBL and SURBL, but not > triggering URI rules > > Dallas (and all the rest), > > what you're saying is: > - We're talking of forward lookups, not of reverse lookup. >
Ah, we are talking about two completely different things. Reverse Lookups via DNS to pull a PTR from a IP is one thing, Reverse Dotted-decimal notation to lookup a forward DNS lookup on a blacklist is another thing. > What I'm seeing, however, is that the zone files contain IPs > in reverse notation.So SA does a forward lookup on a reversed IP. 'reversed dotted-decimal IP' would be more understandble. It doesn't do a forward lookup on a reversed IP in terms of DNS. > I think that's about it. Wolfgang complained about not being > able to resolve 219.144.194.158.multi.surbl.org, and that's true. > The zone files contain an entry for > 158.194.144.219.multi.surbl.org, which - to me at least - is > wrong as SA is douing forward lookups on it. > > Dirk > Looks like we agree with surbl.. # host -tTXT 158.194.144.219.multi.uribl.com 158.194.144.219.multi.uribl.com descriptive text "Listed on [black] - See http://lookup.uribl.com/?domain=158.194.144.219" d