Re: [Exim] Require A records for host names in HELOs?

Top Page
Delete this message
Reply to this message
Author: Edgar Lovecraft
Date:  
To: exim
Old-Topics: [Exim] Require A records for host names in HELOs? {Warning: possible flame war inducing content}
Subject: Re: [Exim] Require A records for host names in HELOs?
Juha Saarinen wrote:
>
> Greg Woods emailed me off list asking if I was running an open relay
> (no, Greg, I am not, and hope you're not either) but when I replied to
> his message, it bounced back with :
>
> 2004-02-05 12:38:58 1AoWaU-0006o5-1B ** woods@??? R=dnslookup
> T=remote_smtp: SMTP error from remote mailer after HELO <hostname>: host
> mail.weird.com [204.92.254.2]: 501-fatal error while validating 'HELO'
> host name '<hostname>'.\n501-connection rejected from <domain_name>
> remote address [ip_address].\n501-Reason given was:\n501 there are no
> DNS A records for the hostname '<hostname>'
>

What are you trying to hide by not giving information that is already in
your message headers (if you really did send this email the same as you
did to Greg).

Received: from saarinen.org ([203.79.82.189]:52499 helo=vim2.saarinen.org)
    by exim-colo-01.whoc.theplanet.co.uk with esmtp (Exim 4.30)
    id 1AoXZy-0001w2-0B
    for exim-users@???; Thu, 05 Feb 2004 00:41:14 +0000
Received: from [192.168.1.200] (helo=futhermucker.net)
    by vim2.saarinen.org with esmtp (Exim 4.30)
    id 1AoXZl-0006qY-8f
    for exim-users@???; Thu, 05 Feb 2004 13:41:01 +1300

>
> This is correct, the hostname doesn't have an A record, but a CNAME
> record instead. Can't do much about that, unfortunately.
>

Which host did Greg reject?? vim2.saarinen.org does not even have a CNAME
record, host record, etc, so it will never resolve. Very bad thing
for a 'valid' email server.
>
> Greg's mailer is the only one that I've seen that behaves like this.
> Surely insisting on hosts in HELOs having A records would lead to masses
> of bounces? Most HELOs I see aren't even FQDNs.
>

And almost all of those that use only host and not host.domain should be
rejected as they are not valid email servers. And Greg is not the only
one that requires host information to valid in many different ways.
--

--EAL--