Page 1 of 1

doubt with check_dynamic_reverse_dns

Posted: Thu May 13, 2010 6:38 am
by m0rpheu5
Hello guys, i´m very satisfy with Magic Spam, but some clients is calling me to know why many clients of him was getting your message return, so i verify in my logs, many of this messages is by black list, ip reputation etc, but i´m getting many like check_dynamic_reverse_dns, so i have doubts about this, this option only verify the IP and DNS reverse? Because i´m looking for that, and i test many IP to check the DNS Reverse, i ping the DNS Reverse and point to the right IP, so i don´t know why this message got blocked. Follow some below:

May 13 08:06:27 br02 postfix/smtpd[24478]: NOQUEUE: reject: RCPT from unknown[200.234.214.7]: 550 5.7.1 <mauricio@pellegrino.adv.br>: Recipient address rejected: Dynamic Style reverse DNS IP=[200.234.214.7].Rejected by MagicSpam 1.0.4-6.1 (http://www.magicspam.com/).Visit http://www.linuxmagic.com/best_practice ... e_dns.html for more information; from=<10952418620495018@intelectojuridico.mktenvios.net> to=<mauricio@pellegrino.adv.br> proto=ESMTP helo=<hm950.locaweb.com.br>


May 13 10:46:57 br02 postfix/smtpd[2236]: NOQUEUE: reject: RCPT from unknown[200.234.214.2]: 550 5.7.1 <pedro@porteengenharia.com.br>: Recipient address rejected: Dynamic Style reverse DNS IP=[200.234.214.2].Rejected by MagicSpam 1.0.4-6.1 (http://www.magicspam.com/).Visit http://www.linuxmagic.com/best_practice ... e_dns.html for more information; from=<1091026173720341794@papau112.disparadordeemails.com> to=<pedro@porteengenharia.com.br> proto=ESMTP helo=<hm638.locaweb.com.br>

May 13 10:47:32 br02 postfix/smtpd[2327]: NOQUEUE: reject: RCPT from unknown[200.234.214.10]: 550 5.7.1 <rec.humanos@sanjulian.com.br>: Recipient address rejected: Dynamic Style reverse DNS IP=[200.234.214.10].Rejected by MagicSpam 1.0.4-6.1 (http://www.magicspam.com/).Visit http://www.linuxmagic.com/best_practice ... e_dns.html for more information; from=<instmaurinoveiga10.mkt9.com@maurinoviega1.mktsender.net> to=<rec.humanos@sanjulian.com.br> proto=ESMTP helo=<hm950-3.locaweb.com.br>

May 13 13:01:06 br02 postfix/smtpd[6574]: NOQUEUE: reject: RCPT from unknown[201.76.49.193]: 550 5.7.1 <rafael@gruporeta.com.br>: Recipient address rejected: Dynamic Style reverse DNS IP=[201.76.49.193].Rejected by MagicSpam 1.0.4-6.1 (http://www.magicspam.com/).Visit http://www.linuxmagic.com/best_practice ... e_dns.html for more information; from=<ricardo@milanez-arquitetos.com.br> to=<rafael@gruporeta.com.br> proto=ESMTP helo=<hm1315-37.locaweb.com.br>


Locaweb.com.br is the bigger provider here in Brazil, i teste ALL this message, but let´s use the last message, i done a nslookup for 201.76.49.193 and point to hm1315-37.locaweb.com.br, and i can ping without problems to hm1315-37.locaweb.com.br, so the DNS Reverse is right configured, or am i wrong?

Thanks

Re: doubt with check_dynamic_reverse_dns

Posted: Thu May 13, 2010 9:06 am
by magicspam
The check_dynamic_reverse_dns rule is in place to check if the reverse DNS lookup for an IP address matches a known pattern for a dynamic-style address. In this case, the reverse DNS for the IP 201.76.49.193 is hm1315-37.locaweb.com.br, which is a dynamic-style hostname pattern we have seen a lot of spam from. The reverse DNS for any properly configured mail server should resolve to the domain of the party responsible for that mail server, rather than their upstream provider.

The ideal solution would be for them to change the reverse DNS entry to conform to the generally accepted best practices. If they are not running mail servers, they may have their mail clients configured incorrectly and are attempting to send directly to you, rather than relaying through their mail provider's server.

The fastest resolution to this (though not the best) would be for you to add an entry to your hosts file to "trick" your server into thinking that the reverse DNS for the IP is in the proper format. For example:

201.76.49.193 mail.gruporeta.com.br