Re: blacklisting replies, was: Proper CNAME interpretation

2011-09-15 Thread Ronald F. Guilmette
In message <39634800-7e01-4878-b1a1-cf384c8a6...@mac.com>, Chuck Swiger wrote: >On Sep 14, 2011, at 5:09 PM, Ronald F. Guilmette wrote: >> In message , you wrote: >>> Sigh: your mail server is blacklisting email from mac.com. >> >> Yes. Sorry about that. Too much spam from there and no indic

Re: Compelling Reason for Deploying DNSSEC

2011-09-15 Thread michoski
On 9/15/11 12:19 PM, "Paul Romano" wrote: > Does the lack of response indicate a lack of compelling reason or just lack of > interest in this topic?  Not at all, folks are just busy I bet... > Is there a way to tie an ROI into a DNSSEC deployment?  It's basically a risk analysis game. You shou

Re: blacklisting replies, was: Proper CNAME interpretation

2011-09-15 Thread Chuck Swiger
On Sep 14, 2011, at 5:09 PM, Ronald F. Guilmette wrote: > In message , you wrote: >> Sigh: your mail server is blacklisting email from mac.com. > > Yes. Sorry about that. Too much spam from there and no indication > that anybody there gives a damn that that they gush spam. (If you > find anybod

Re: SERVFAIL

2011-09-15 Thread Alan Clegg
On 9/15/2011 4:14 AM, kshitij mali wrote: > ; <<>> DiG 9.2.4 <<>> completefreight.net.au [...] If your version of BIND matches your version of dig, all bets are off. Please upgrade and see if you continue to have problems. AlanC signature.asc Description: OpenPGP digital signature __

Re: SERVFAIL

2011-09-15 Thread Stuart Gall
Due to the fact that IPV4 addresses have run out, many addresses that were reserved have been un-reserved and used on the internet. Is it possible that you have a bogon filter file that is blocking this IP ? On 15 Sep, 2011, at 2:14 PM, kshitij mali wrote: > Hello ALL, > > > I repeated see do

Re: Compelling Reason for Deploying DNSSEC

2011-09-15 Thread Paul Romano
Does the lack of response indicate a lack of compelling reason or just lack of interest in this topic?    Is there a way to tie an ROI into a DNSSEC deployment?  Are any agencies planning on deying access to unsigned domains? Are there any numbers indicating a trend in DNS related attacks?      

Re: slow non-cached quries

2011-09-15 Thread Warren Kumari
On Sep 15, 2011, at 12:04 PM, Michael McNally wrote: > On 9/9/11 1:34 PM, TMK wrote: > > > > On Sep 9, 2011 10:28 PM, "TMK" > > wrote: > > > > > > On 09.09.11 19:31, TMK wrote: We have find the reason why our > > network analyzer report that bind is responding to a.roo

Re: SERVFAIL

2011-09-15 Thread michoski
On 9/15/11 4:14 AM, "kshitij mali" wrote: > I repeated see domain lookup issue for the certain domain give an error > :SERVFAIL . my server is configured for simple caching nameserver for the  > email delivery > > please find the error example below > = > > > dig com

Re: slow non-cached quries

2011-09-15 Thread Michael McNally
On 9/9/11 1:34 PM, TMK wrote: > > On Sep 9, 2011 10:28 PM, "TMK" > wrote: > > > > On 09.09.11 19:31, TMK wrote: We have find the reason why our > network analyzer report that bind is responding to a.root-server.net > in 30 sec. You may have noticed this already, but in

SERVFAIL

2011-09-15 Thread kshitij mali
Hello ALL, I repeated see domain lookup issue for the certain domain give an error :SERVFAIL . my server is configured for simple caching nameserver for the email delivery please find the error example below = dig completefreight.net.au ; <<>> DiG 9.2.4 <<>> compl