Re: [Asrg] DNSBL and IPv6

"Emanuele Balla (aka Skull)" <skull@bofhland.org> Thu, 25 October 2012 15:38 UTC

Return-Path: <skull@bofhland.org>
X-Original-To: asrg@ietfa.amsl.com
Delivered-To: asrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E22B21F88AE for <asrg@ietfa.amsl.com>; Thu, 25 Oct 2012 08:38:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.442
X-Spam-Level:
X-Spam-Status: No, score=-2.442 tagged_above=-999 required=5 tests=[AWL=-0.158, BAYES_00=-2.599, SARE_MILLIONSOF=0.315]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Azbl5--hRpIH for <asrg@ietfa.amsl.com>; Thu, 25 Oct 2012 08:38:30 -0700 (PDT)
Received: from mithrandir.bofhland.org (mithrandir.bofhland.org [IPv6:2a02:9a8:94::b]) by ietfa.amsl.com (Postfix) with ESMTP id 1A16221F8901 for <asrg@irtf.org>; Thu, 25 Oct 2012 08:38:30 -0700 (PDT)
Received: from zarathustra.local (zarathustra.spin.it [147.123.15.60]) by mithrandir.bofhland.org (Postfix) with ESMTPSA id 711026C0A1 for <asrg@irtf.org>; Thu, 25 Oct 2012 17:38:28 +0200 (CEST)
Message-ID: <50895CF2.7050807@bofhland.org>
Date: Thu, 25 Oct 2012 17:38:26 +0200
From: "Emanuele Balla (aka Skull)" <skull@bofhland.org>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:16.0) Gecko/20121010 Thunderbird/16.0.1
MIME-Version: 1.0
To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
References: <20121025141158.11869.qmail@joyce.lan> <50894BA1.7020100@invaluement.com> <50895125.4050606@bofhland.org> <50895868.50100@invaluement.com>
In-Reply-To: <50895868.50100@invaluement.com>
X-Enigmail-Version: 1.4.5
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Subject: Re: [Asrg] DNSBL and IPv6
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Oct 2012 15:38:36 -0000

On 10/25/12 5:19 PM, Rob McEwen wrote:
> On 10/25/2012 10:48 AM, Emanuele Balla (aka Skull) wrote:
>> So you're basically suggesting that MXs should not allow any IPv6 SMTP
>> connection unless it's coming from a trusted entity, and only MSAs
>> should speak IPv6.
> 
> No. I'm talking about AUTHENTICATED e-mail that is, by design, NOT
> considered the "sending IP" for that message. Maybe the "originate
> IP"... but not the "sending IP". I'm not sure what you mean by "only
> MSAs", this wouldn't prevent the use of IPv6 for OTHER uses. My answers
> below should clear this up...
> 
>> In other words, you're basically suggesting something like "do not
>> publish any AAAA record for your MXs and just rely on IPv4, unless you
>> found a solution to the IPv6 spam problem".
> 
> I think you must be greatly misunderstanding me. When millions of end
> user customers for a large set up their outlook programs (or
> thunderbird, or whatever)... their connection to their ISP's mail server
> does NOT use MX records!!!!

I think we're speaking of the same thing here... :-)

MSA == Mail Submission Agent, the SMTP server your MUA (Outlook,
Thunderbird, pine) will connect to in order to send email.

MX in my notation was intended as "the MTA on the receiving end" or, in
other words, a mailserver that expects to be contacted by others MTAs
only, not by MUAs.


So, to rephrase the whole thing as I understood it:

- allow end customers to use IPv6 to *send* email through their ISP's
(not necessarily the connection one) IPv6-enabled authenticated mailserver

- do not allow the receiving mailserver (aka "the one published as MX
record for the domain") to receive email from strangers through IPv6


Did I get it right?

-- 
Paranoia is a disease unto itself. And may I add: the person standing
next to you may not be who they appear to be, so take precaution.
-----------------------------------------------------------------------------
http://bofhskull.wordpress.com/