<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Greylisting and a backup MX, the start of a problem ?</title>
	<atom:link href="http://switch.richard5.net/2006/11/29/greylisting-and-a-backup-mx-the-start-of-a-problem/feed/" rel="self" type="application/rss+xml" />
	<link>http://switch.richard5.net/2006/11/29/greylisting-and-a-backup-mx-the-start-of-a-problem/</link>
	<description>How to build your Mac into a internet server using open source software</description>
	<lastBuildDate>Tue, 17 Jun 2008 18:25:42 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: James Brown</title>
		<link>http://switch.richard5.net/2006/11/29/greylisting-and-a-backup-mx-the-start-of-a-problem/comment-page-1/#comment-8506</link>
		<dc:creator>James Brown</dc:creator>
		<pubDate>Sun, 03 Dec 2006 14:11:30 +0000</pubDate>
		<guid isPermaLink="false">http://switch.richard5.net/2006/11/29/greylisting-and-a-backup-mx-the-start-of-a-problem/#comment-8506</guid>
		<description>Richard, I&#039;ve had the same problem with my mail setup for ages now. Almost all email goes through the backup MX. We have always used our ISP as the backup MX. Unfortunately they do absolutely not spam filtering.

I have now signed up for a backup MX and DNS service at Rollernet.us - http://www.rollernet.us/

From their web site:

We offer the following configurable anti-spam options:

    * DNSBL (with optional custom lists)
    * Sender Policy Framework (SPF) (optional custom action handling)
    * Greylisting
    * Highly configurable blacklist and whitelist features
    * Inline anti-virus filtering
    * Configurable valid user list


A lot of this is available on a free account, and you can upgrade the full-featured account for US$35/yr. Not bad when you consider that for this price you can have more than one domain.

You&#039;ll still get some spam of course, but a lot less.

Spammers often target the backup MX server directly. And apparently some go after the MX with the lowest priority (ie highest number in the MX record). So some people advocate having your real server as the highest and lowest priority MX - ie the mail server has two MX entries. I don&#039;t know how effective this is.</description>
		<content:encoded><![CDATA[<p>Richard, I&#8217;ve had the same problem with my mail setup for ages now. Almost all email goes through the backup MX. We have always used our ISP as the backup MX. Unfortunately they do absolutely not spam filtering.</p>
<p>I have now signed up for a backup MX and DNS service at Rollernet.us &#8211; <a href="http://www.rollernet.us/" rel="nofollow">http://www.rollernet.us/</a></p>
<p>From their web site:</p>
<p>We offer the following configurable anti-spam options:</p>
<p>    * DNSBL (with optional custom lists)<br />
    * Sender Policy Framework (SPF) (optional custom action handling)<br />
    * Greylisting<br />
    * Highly configurable blacklist and whitelist features<br />
    * Inline anti-virus filtering<br />
    * Configurable valid user list</p>
<p>A lot of this is available on a free account, and you can upgrade the full-featured account for US$35/yr. Not bad when you consider that for this price you can have more than one domain.</p>
<p>You&#8217;ll still get some spam of course, but a lot less.</p>
<p>Spammers often target the backup MX server directly. And apparently some go after the MX with the lowest priority (ie highest number in the MX record). So some people advocate having your real server as the highest and lowest priority MX &#8211; ie the mail server has two MX entries. I don&#8217;t know how effective this is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://switch.richard5.net/2006/11/29/greylisting-and-a-backup-mx-the-start-of-a-problem/comment-page-1/#comment-8139</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Thu, 30 Nov 2006 02:35:04 +0000</pubDate>
		<guid isPermaLink="false">http://switch.richard5.net/2006/11/29/greylisting-and-a-backup-mx-the-start-of-a-problem/#comment-8139</guid>
		<description>Hey Richard,

I&#039;ve noticed the same problem regarding backup MX&#039;s and other situations. For example, I maintain an /etc/postfix/access file which reject&#039;s certain addresses within a domain that I have a catch-all assigned to.

Of course, once the primary rejects with a 554 Access Denied, the sender sends to the secondary, where it rattles around for a while, eventually notifying the secondary MX&#039;s postmaster of its inability to deliver it.

Luckily, I admin the secondary and was able to mimic the /etc/postfix/access file, but your point is very valid.</description>
		<content:encoded><![CDATA[<p>Hey Richard,</p>
<p>I&#8217;ve noticed the same problem regarding backup MX&#8217;s and other situations. For example, I maintain an /etc/postfix/access file which reject&#8217;s certain addresses within a domain that I have a catch-all assigned to.</p>
<p>Of course, once the primary rejects with a 554 Access Denied, the sender sends to the secondary, where it rattles around for a while, eventually notifying the secondary MX&#8217;s postmaster of its inability to deliver it.</p>
<p>Luckily, I admin the secondary and was able to mimic the /etc/postfix/access file, but your point is very valid.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
