Re: [Asrg] rDNS

Douglas Otis <dotis@mail-abuse.org> Wed, 27 May 2009 19:03 UTC

Return-Path: <dotis@mail-abuse.org>
X-Original-To: asrg@core3.amsl.com
Delivered-To: asrg@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0960F28C335 for <asrg@core3.amsl.com>; Wed, 27 May 2009 12:03:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.328
X-Spam-Level:
X-Spam-Status: No, score=-6.328 tagged_above=-999 required=5 tests=[AWL=0.271, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aEXR0pj+ea4p for <asrg@core3.amsl.com>; Wed, 27 May 2009 12:03:30 -0700 (PDT)
Received: from harry.mail-abuse.org (harry.mail-abuse.org [168.61.5.27]) by core3.amsl.com (Postfix) with ESMTP id F31CD28C155 for <asrg@irtf.org>; Wed, 27 May 2009 12:00:57 -0700 (PDT)
Received: from [IPv6:::1] (gateway1.sjc.mail-abuse.org [168.61.5.81]) by harry.mail-abuse.org (Postfix) with ESMTP id 6A721A9443A for <asrg@irtf.org>; Wed, 27 May 2009 19:02:23 +0000 (UTC)
Message-Id: <728E5AC5-061F-4C93-AFAD-B889195FF0CD@mail-abuse.org>
From: Douglas Otis <dotis@mail-abuse.org>
To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
In-Reply-To: <200905271821.OAA20063@Sparkle.Rodents-Montreal.ORG>
Content-Type: text/plain; charset="US-ASCII"; format="flowed"; delsp="yes"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v935.3)
Date: Wed, 27 May 2009 12:02:22 -0700
References: <003d01c9dd01$bf3531d0$800c6f0a@china.huawei.com> <4A1A45BA.5030704@swin.edu.au> <3be421270905250718y5d62f6d5odb6f2bebecf418d0@mail.gmail.com> <4A1D7C8A.5060407@tana.it> <200905271821.OAA20063@Sparkle.Rodents-Montreal.ORG>
X-Mailer: Apple Mail (2.935.3)
Subject: Re: [Asrg] rDNS
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 May 2009 19:03:32 -0000

On May 27, 2009, at 10:59 AM, der Mouse wrote:

> Certainly, if they care about rDNS and whois.  (I would hope anyone  
> interested in following best practices would care about each.  I've  
> seen things like "nobody cares about rDNS these days" said; in my  
> admittedly limited experience, clue level correlates remarkably well  
> with not sharing such points of view.)

There are different geographic regions and organizations that refuse  
to publish reverse DNS.  Reverse DNS is normally controlled by the  
holder of the IP address, where the forward DNS is normally controlled  
by the entity offering a service. When a PTR record in the reverse DNS  
appears to match with the service offered, the domain using the IP  
address is known by the IP address holder.  However, it does not mean  
the entity offering the service is controlled by that domain.  SSL  
certs attempt to convey that information in a much safer fashion.  In  
addition, it is often the case where the number of PTR records that  
can be published represent only a small faction of the domains  
legitimately using the IP address.   In the case of email, reverse DNS  
entries are often used to divine some deeper, often undefined, meaning  
based upon the content of a PTR records found at the in-addr.arpa  
zone.  As an anti-abuse effort,  some providers in North America do  
not accept connections without a reverse DNS entry being found.  As a  
result, these providers may be unable to communicate with some  
organizations or geographic regions.  Who is wrong, because in the  
case of email, reverse DNS is clearly being misused.

-Doug