22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

lookup is used) and IP address of the server, as well as the name of the site<br />

where the server was listed.<br />

In addition to logging the event, you can configure Domino to reject messages<br />

from hosts on the blacklist or to add a special Notes item ($DNSBLSite) to flag<br />

messages accepted from hosts on the list.<br />

Specifying the DNS blacklist sites<br />

After you enable the DNS blacklist filters, you can specify the site or sites the<br />

SMTP task uses to determine if a connecting host is a “known” open relay or<br />

spam source. Specify sites that support IP-based DNS blacklist queries.<br />

If Domino finds a match for a connecting host in one of the blacklists, it does not<br />

continue checking the lists for the other configured sites. For performance<br />

reasons, it's best to limit the number of sites because Domino performs a DNS<br />

lookup to each site for each connection.<br />

You can choose from a number of publicly available and private, paid<br />

subscription services that maintain DNS blacklists. When using a public blacklist<br />

service, Domino performs DNS queries over the Internet. In some cases, it may<br />

take a significant amount of time to resolve DNS queries submitted to an Internet<br />

site. If the network latency of DNS queries made over the Internet results in<br />

slowed performance, consider contracting with a private service that allows zone<br />

transfer, so that Domino can perform the required DNS lookups to a local host.<br />

During a zone transfer, the contents of the DNS zone file at the service provider<br />

are copied to a DNS server in the local network.<br />

Each blacklist service uses its own criteria for adding servers to its list. Blacklist<br />

sites use automated tests and other methods to confirm whether a suspected<br />

server is sending out spam or acting as an open relay. The more restrictive<br />

blacklist sites add servers to their list as soon as they fail the automated tests<br />

and regardless of whether the server is verified as a source of spam. Other less<br />

restrictive sites list a server only if its administrator fails to close the server to<br />

third-party relaying after a specified grace period or if the server plays host to<br />

known spammers.<br />

By searching the Internet, you can find Internet sites that provide periodic reports<br />

on the number of entries in various DNS blacklist services.<br />

Hosts that are exempt from DNS blacklist checks<br />

To avoid unnecessary DNS lookups, Domino performs DNS blacklist checks only<br />

on hosts that are subject to relay checks, as specified in the SMTP inbound relay<br />

restrictions. Any host that is authorized to relay is exempt from blacklist checks.<br />

For example, by default, Domino enforces the inbound relay restrictions only for<br />

external hosts (Router/SMTP → Restrictions and Controls → SMTP Inbound<br />

Chapter 11. Domino/Notes 6 security features 517

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!