[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]

Re: sendmail forgery



Kai-Min Sung wrote:
> 
> Lately I've noticed repeated entries in my /var/spool/maillog looking like
> this:
> 
> maillog:Apr 7 21:16:33 host sendmail[12802]: VAA12802:
> ruleset=check_mail, arg 1=<sd000001 polbox com>, relay=smtp2.polbox.com
> [195.116.6.12] (may be forged),

> However, trying to nslookup smtp2.polbox.com returns a "non-existent
> host/domain" error. 

Disregard my previous post.  The name smtp2.polbox.com DOES
resolve here:

**rfg amber[/]$ nslookup 195.116.6.12
Server:  green.nook.net
Address:  216.47.28.11

Name:    smtp2.polbox.com
Address:  195.116.6.12

**rfg amber[/]$ nslookup smtp2.polbox.com
Server:  green.nook.net
Address:  216.47.28.11

Name:    smtp2.polbox.com
Address:  195.116.6.12

**rfg amber[/]$ 

My guess is this is a new server and when you querried it, the
DNS information had not propagated yet.  This happens from
time to time.

-- 
Ramon Gandia ================= Sysadmin ================ Nook Net
http://www.nook.net                                  rfg nook net
285 West First Avenue                           tel. 907-443-7575
P.O. Box 970                                    fax. 907-443-2487
Nome, Alaska 99762-0970 ========== Alaska Toll Free. 888-443-7525



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]