On Wed, 2007-09-05 at 10:50 +0200, mouss wrote:
> ram wrote:
> > I am using SA 3.2.3 and very few spam get thru
> > But I can still see some spam with urls because the the urls are not yet
> > listed in uribls 
> >
> > I tried to do some analysis on my quarantine, I found atleast some
> > spammer domains have the same NS records. 
> >
> > Now in my spamassassin can I do a DNS check (on all domains in body-urls
> > or mail-from, reply-to etc)  to find their NS records and score them on
> > bad NS servers. 
> > What is the risk of FP's because innocent DNS providers may see
> > themselves getting list 
> >   
> 
> 
> better show an example so that we can see.
> if the NS belongs to a spam organization, then it's ok. otherwise, just 
> because a spammer configures his dns to point to my domain doesn't mean 
> you can block me!
> 



But if his DNS points to your server and you dont host DNS for him, his
domain will not get resolved. I could easily check for such domains
then. 




Reply via email to