DNS block lists are easy to include into most mail servers. They are a very effective and efficient server side tool to help keeping spam out of your systems. As the name implies they use domain name servers to transmit the information whether mails from a distinct mail server should be accepted or rejected.
Sometimes they are too effective. It can happen that a mail server is listed on a block list wrongfully. This can lead to a situation where your mail server will reject mails that you wanted to receive. The biggest problem with block lists is that you have to trust somebody else to take the right decision which mails to accept and which ones to reject.
So how useful are DNS block lists after evaluating the pros and cons? They can be very useful to lower the overall CPU usage of your anti spam strategy. It is advisable to use a small number of carefully chosen blocklists. If you are using a block list, subscribe to the mailing list or newsletter of the organization who runs the block list. That way you will take note of any problems that the block list may have and you will be informed if it gets shut down. DNS blocklists should never be your only strategy against spam. They should be combined with other mechanisms to help keeping spam out of your inbox.
There are some things you should consider before implementing DNS block lists in your anti spam strategy. If you reject a connection from a mail server because it is listed in a block list, return a detailed error message. This enables the admin of a mail server that gets listed wrongfully to see why the mails get rejected and to act accordingly.
If your mail server software allows to select the order of different sender or client restrictions be sure to put DNS blacklists after SMTP authentication. This enables your co-workers (and your customers if you are in the ISP business) to send their mails even if they come from a dial-in IP address that is listed in a block list.
You should consider using DNS block lists for scoring instead of blocking if your mail server has enough resources (CPU, IO, traffic). That would mean to use the block lists in a program like spamassassin that gives points for different criteria of a message and considers it as spam if it surpasses a certain number of points. That way the chances for false positives are lower because a message is not rejected if the sending server is on a single block list only. The message will get rejected if there are other signs of spam.
Huge indexes of available DNS block lists can be found at www.moensted.dk/spam/ and www.declude.com.
![]() TorrentFreak | The Pirate Bay Shows Futility of Domain and DNS Blocks TorrentFreak The last domain in the list certainly piqued our interest and not only because it includes a typo. The nyud.net domain belongs to the peer-to-peer based Coral CDN service which links to IP-addresses all over the world, which is generally a good tool to ... |
SOPA and PIPA Defeat: People Power or Corporate Clout? Forbes The bills could even give the US attorney general power to seek a court order to block the domain name server (DNS) records, effectively cutting off access to the entire site. Derailing the bills was indeed a big victory, but was it “people power” or a ... |
![]() Sydney Morning Herald | Five reasons the Internet's still protesting SOPA and PIPA Washington Post (blog) True, the legislation's House and Senate backers said they'd review a controversial provision that would de-list rogue sites from the Domain Name System (DNS). That was a huge deal. Under this measure, blocked sites would still technically exist, ... The big hammer of SOPA, PIPA will only crush Internet freedom Wikipedia Goes Down Tonight in Protest More Sites Going Dark Over SOPA and PIPA, But Not Twitter |
Changes afoot for polarizing piracy bill Variety By Ted Johnson The major sponsor of the Senate's version of controversial anti-piracy legislation said that changes are afoot, perhaps to one of the bill's most controversial provisions to block the domain names of sites dedicated to trafficking in ... |
![]() Forbes | Android Barcode Scanner App Detects If A Product's Maker Supports SOPA Forbes The app, which requires downloading the free app Barcode Scanner, uses a public UPC database to find a product's manufacturer, then queries a remote server to compare the manufacturer with a list of 800 firms with lobbying ties to the bill. 8 Technological Reasons to Stop SOPA & PIPA |
| |
| |
| |