Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu Oct 18, 2007 12:07 pm 
Offline
Senior Newbie

Joined: Tue Nov 30, 2004 10:01 pm
Posts: 17
Starting on Oct 9th, I started getting some weirdness in my named logs. My named server is authoritative for my domain (call it domain1.com) and returns two MX records:

Code:
# dig -t mx domain1.com
...
;; ANSWER SECTION:
domain1.com.    259200  IN      MX      20 mail.domain2.com.
domain1.com.    259200  IN      MX      10 mail.domain1.com.
...


My name server responds to requests for domain1, but domain2's name servers are elsewhere. However, for some reason, starting on Oct 9th, I started getting these in my logs:

named[1403]: client xx.xx.xx.xx#2125: query (cache) 'mail.domain2.com/A/IN' denied

At first I thought it was a misconfigured client but it is occurring more and more often with many different client IPs. Why are these clients attempting to resolve my backup MX from my primary domain's name server?

Cheers,
Raman


Top
   
 Post subject:
PostPosted: Mon Oct 22, 2007 10:50 am 
Offline
Senior Member

Joined: Fri Feb 13, 2004 11:30 am
Posts: 140
Location: England, UK
I assume your primary MX *is* working? I can't think why a backup MX server would be resolved unless it was actually using it. Do you have any connections logged to your backup MX?


Top
   
 Post subject:
PostPosted: Mon Oct 22, 2007 6:45 pm 
Offline
Senior Member

Joined: Sun Nov 30, 2003 2:28 pm
Posts: 245
You're probably a victim of two different conspiracies:

1. Lots of spammers try to use the backup MX on the assumption that there will be lest spam filtering on it.

2. I'd guess that lots of spam bots assume that the (backup) MX can be A resolved at the same NS as sourced the MX record, not noticing that it's actually a different domain. Spammers are stupid, except when they're fiendishly clever.

_________________
The irony is that Bill Gates claims to be making a stable operating system and Linus Torvalds claims to be trying to take over the world.
-- seen on the net


Top
   
 Post subject:
PostPosted: Tue Oct 23, 2007 2:27 am 
Offline
Senior Newbie

Joined: Tue Nov 30, 2004 10:01 pm
Posts: 17
SteveG wrote:
You're probably a victim of two different conspiracies:

1. Lots of spammers try to use the backup MX on the assumption that there will be lest spam filtering on it.

2. I'd guess that lots of spam bots assume that the (backup) MX can be A resolved at the same NS as sourced the MX record, not noticing that it's actually a different domain. Spammers are stupid, except when they're fiendishly clever.


Thanks Steve -- yes, I'm quite aware of #1. I didn't think of #2, but it makes complete sense. And since I have only recently started seeing these, most likely a new spambot that makes this assumption is loose out in the wild.

Cheers,
Raman


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group