Am 24.11.2015 um 13:38 schrieb Matus UHLAR - fantomas:
On Tue, 24 Nov 2015 11:22:20 +0100
Matthias Apitz wrote:
I have contacted the support of my ISP and phoned them today: the
hotline guy said, that the technican not even understood the problem
and why there should be together with the IP a rDNS, and why I can't
do the lookup by my own, .... :-(

Am 24.11.2015 um 13:00 schrieb RW:
You can by running the BOTNET plugin

On 24.11.15 13:24, Reindl Harald wrote:
on the other hand why can't SA not do the lookup for the IP of
"Received: from [140.211.11.3]" given that it does a lot of dns
lookups anyway?

just because of that - to limit the number of outgoing DNS requests and
focus on that haven't been done before.  That's why SA uses existing
headers
like Received: and Received-SPF:

in reality it would be not a "outgoing DNS request" because it's cached

it's obvious that the info is missing in the header, otherwise for a remote IP with no PTR on that place would appear "unknown" so you can even fire that DNS request only when it is needed

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to