OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [OT] dnsbl.sorbs.net too much restrictive ?

From: Emmanuel Lesouef (elesouef+listslorinand.org)
Date: Thu Feb 22 2007 - 04:37:31 CST


Le Thu, 22 Feb 2007 11:12:25 +0100,
Robert Felber <r.felberek-muc.de> a écrit :

>
> No! It's not. But it's a long standing fact.

Didn't new about it. Ok.

>
> > What are you all do to solve this issue ?
>
> Most do not use sorbs.

Thought about that.

>
> Is sorbs the only list? If so:
>

For the moment we have the following lines :

smtpd_sender_restrictions = reject_invalid_hostname,
                                reject_non_fqdn_hostname,
                                reject_non_fqdn_sender,
                                reject_non_fqdn_recipient,
                                reject_unknown_sender_domain,
                                reject_unknown_recipient_domain,
                                permit_mynetworks,
                                check_client_access
hash:/etc/postfix/rbl_override,
                                reject_unauth_destination,
                                reject_rbl_client zen.spamhaus.org,
                                reject_rbl_client list.dsbl.org,
                                reject_rbl_client
rbl-plus.mail-abuse.org,
                                reject_rbl_client cbl.abuseat.org,
                                reject_rbl_client dnsbl.sorbs.net,
                                permit

Do you see something missing ?

>
> Another alternative is policyd-weight[2] where you can use score
> based RBL results plus other score weighted DNS checks which are not
> appropriate for 0|1 outright blocking. Note this software is beta
> (and will remain beta for a long time :-/ ).
>

Ok, I'll check it when I'll be back at work next week. Thanks for the
tip.

--
Emmanuel Lesouef