[SpamCop.net - protecting the internet through technology]

[SC-Help] rDNS checks and third party SMTP agents

Iain ipmarketing at spamcop.net
Wed Feb 2 08:29:58 EST 2005


I still working on my same Government project and have a new issue to seek 
help about :-)

One proposal is that opted-in mail be despatched via a coordinated 
cross-Governement eMail service. This is raising numerous issues including:

1. If mail is not sent in the name of the 'real' Government agency then this 
is both a poor user experience and could be confused for phishing mail 
either by the recipient or a mail scanner (I've seen mail where the scanner 
compared the domain quoted in links included in the body of the message with 
the domain of the sender and if they didn't match would insert a large 
'possible fraud attempt' tag in red into the message at every link!

2. If the cross-Government service then simply sends mail in the name 
(domain) of the real agency, then (I presume) unless the SMTP server is 
listed in the real agency's DNS the mail send would fail any rDNS check, 
i.e. the server would appear to be sending mail under a domain for which the 
server were not listed. Is this correct?

3. To ensure rDNS checks worked, would it be necessary for the sending SMTP 
server to have a valid MX record or would the servers IP just need to apear 
in the domain records? The significance of a 'valid MX' is that this would 
be a cross-Government *sending* service and we wouldn't want inbound mail 
going to it should the regular SMTP servers not be available at any tme for 
some unexpected reason

I'm sure Mike is going to read this and think "third party sending 
agency...sounds like a dirty list", but it's not :-) Just well intentioned 
ideas for shared infrastructure which continues to give us issues. The is a 
lot of political desire - 'political' with a big 'P', not company 
politics! - for shared infrastructure with little understanding of the 
technical and imlpementation issues this often raises. The belief is it 
makes things simpler, easier and cheaper, although IMHO it's usually the 
opposite!

Thanks for any help on this. If you can see other holes a shared service 
like this might lead us into please feel free to say (like another user of 
the shared service abusing mail/spam policies and causing the entire service 
to become blocklisted??)

Thx.../Iain 




More information about the SpamCop-Help mailing list