Besides the DDOS issue, there's a privacy issue, which is messy with DNSBLs already. Nothing SA does should send network traffic to a place controlled by the mail sender. Checking a DNSBL for which there's some reason to believe they aren't underhanded is one thing, but fetching stuff from a spammer's site, or enabling a backdoor delivery confirmation is IMHO not ok.
pgp0SHj4YbRb7.pgp
Description: PGP signature