OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [OT] HELO/rDNS Checking Policy (was: Re: Acceptance of domain literals)

From: Alex van den Bogaerdt (alexergens.op.het.net)
Date: Sat Jan 03 2004 - 10:59:37 CST


On Sat, Jan 03, 2004 at 11:34:55AM -0500, Jim Seymour wrote:

> > > He didn't explicitly refuse to accept your response. His MTA config
> > > refused to accept email from a server whose HELO violates RFC 1123.
> > > Admittedly, that RFC says one MAY verify, but MUST not reject on a
> > > failure, so Mr. Woods is, technically speaking, violating the RFCs
> > > worse than you are.

> I stand by my original comments. If your HELO does not match your
> rDNS, you are in violation of RFC 1123.

I never said this wasn't true. What I did say is that RFC 1123 talks
about rejecting in certain circumstances.

RFC 1123 does not forbid you to reject a message. RFC 1123 only forbids
to reject a message for no other reason than the correctly formed HELO
parameter not matching the connecting IP address.

This is what RFC1123 discusses:
   hostname -> resolved_IP
   resolved_IP -> hostname
   resolved_IP != connected_IP

resolved_IP != connected_IP ? MUST NOT reject
Cannot resolve hostname into IP ? RFC1123 does not forbid to reject
Cannot resolve IP into hostname ? Dito

cheers,
Alex
--
begin sig
http://www.googlism.com/index.htm?ism=alex+van+den+bogaerdt&type=1
This message was produced without any <iframe tags