OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: postscreen_dnsbl_sites

From: /dev/rob0 (rob0gmx.co.uk)
Date: Mon May 06 2013 - 19:37:41 CDT


On Sat, May 04, 2013 at 06:48:36AM -0500, I wrote:
> On Fri, May 03, 2013 at 06:27:15PM -0600, Robert Lopez wrote:
> > I had
> > postscreen_dnsbl_sites = <the-key-to-hide>zen.dq.spamhaus.org
>
> This is right.

Let me try again also! I presume your lookup is actually against
key.zen.dq.spamhaus.org. That's what I said was right. Hereafter,
"key" will be substituted for the actual key.

> > and
> > postscreen_dnsbl_reply_map = texthash:/etc/postfix/dnsbl_reply
> > in main.cf
> >
> > and I had
> > <the-authorization-key-was-here>.zen.dq.spamhaus.net zen.dq.spamhaus.org

And here you are talking about spamhaus.net. Which is your lookup
against, key.zen.dq.spamhaus.org or key.zen.dq.spamhaus.net? Do note
that "net" is not "org".

> "net" != "org". This would never match.

Assuming that you DID mean key.zen.dq.spamhaus.org, your
postscreen_dnsbl_reply_map lookup of key.zen.dq.spamhaus.net would
never match, because as we have seen, "net" is not "org". :)

If "net" was right, your munging was wrong.

> You probably want to rewrite that to "zen.spamhaus.org" without
> the "dq" domain component. That's what non-subscribers use.
>
> > How can I prove to myself the spamhaus list actually being used
> > now as opposed to being not used because of configuration?
>
> http://www.crynwr.com/spam/ provides a testing service. Or, maybe
> you're using a home Internet connection which is listed on PBL. If
> your port 25 is not blocked by the ISP, you could test from home.
--
  http://rob0.nodns4.us/ -- system administration and consulting
  Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: