Skip to content

Check for public resolver to avoid possible spamhaus blocking #467

@PatTheMav

Description

@PatTheMav

Impacted versions

  • Distribution: Debian
  • Codename: Bullseye
  • Arch: 64 Bits
  • Database: PostgreSQL

Steps to reproduce

When a public resolver is configured in the DNS chain (e.g. Google's 8.8.8.8 or CloudFlare's 1.1.1.1) Spamhaus and other services will not accept DNS requests from postscreen's RBL checks (the services block requests from these resolvers to avoid abuse).

For the time being, these services will not fully block access yet, but this might come in the future.

The obvious fix is to run a local forwarding resolver that will not forward DNS requests for the spamhaus.org (or other) zones, but that is not part of the scope of the installer (nor should it be as it is a pretty involved change to a server's local setup).

IMO a check for the current resolver and a warning/error might suffice, disabling spamhaus.org in postfix' main.cf in that case would be nice-to-have.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions