-
-
Notifications
You must be signed in to change notification settings - Fork 155
Description
Impacted versions
- Distribution: Debian
- Codename: Bullseye
- Arch: 64 Bits
- Database: PostgreSQL
Steps to reproduce
When a public resolver is configured in the DNS chain (e.g. Google's 8.8.8.8 or CloudFlare's 1.1.1.1) Spamhaus and other services will not accept DNS requests from postscreen's RBL checks (the services block requests from these resolvers to avoid abuse).
For the time being, these services will not fully block access yet, but this might come in the future.
The obvious fix is to run a local forwarding resolver that will not forward DNS requests for the spamhaus.org (or other) zones, but that is not part of the scope of the installer (nor should it be as it is a pretty involved change to a server's local setup).
IMO a check for the current resolver and a warning/error might suffice, disabling spamhaus.org in postfix' main.cf in that case would be nice-to-have.