Am 24.11.2015 um 20:16 schrieb David Jones:
From: Reindl Harald <h.rei...@thelounge.net>
and that is why i call it harmful to completly rely on the Received
header instead doing the DNS lookup based on the IP which would have a
lot of advantages:

* less error prone
* even when the MTA had a timeout a chance that this
   DNS rqeuest get answered properly, the MTA treats
   a timeout *completty* different and would *not*
   reject a mail if the answer is not an NXDOMAIN even
   if it is configured for reject clients without a PTR
* SpamAssassin has *no clue* what the "unknown" means
  it could have been a timeout or a NXDOMAIN

disadvantages - zero - there is no overhead for a chached DNS query

I agree with you if the SA server is configured with a local caching
DNS server that is not forwarding and the /etc/resolv.conf is
pointing to 127.0.0.1.

We have seen a number of people ask for help on this mailing
list because their DNS was not setup like this which means SA
would generate a lot more queries to the ISP or Internet DNS
servers compounding the problem with free usage limits on
some RBLs

not true at all - the ISP server would cache anyways while at the same time you mix different things - what has the PTR query to do with any RBL?

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to