Re: RPZ for reverse lookups ?

2019-08-27 Thread J Doe
Hi Noel and Fred, Thank you for your replies. I probably should have provided a bit of context about my situation. I manage a small e-mail server for a client. While setting up support for the SpamHaus DNSBL, I read that SpamHaus prefers that people use a non-public (ie: not 8.8.8.8 / large

Re: rpz fail

2019-08-27 Thread Lee
On 8/27/19, Tony Finch wrote: > Lee wrote: >> >> Can someone please explain why using this as my rpz zone does NOT >> block everything for *.2o7.net? >> >> 2o7.net CNAME . >> *.2o7.net CNAME . >> bcbsks.com.102.112.2o7.net CNAME . > > I suspect this is RPZ obeying the weird semantics of DNS wildc

Re: rpz fail

2019-08-27 Thread Tony Finch
Lee wrote: > > Can someone please explain why using this as my rpz zone does NOT > block everything for *.2o7.net? > > 2o7.net CNAME . > *.2o7.net CNAME . > bcbsks.com.102.112.2o7.net CNAME . I suspect this is RPZ obeying the weird semantics of DNS wildcard matching. The * only matches if the ans