1 |
On 18-Aug-20 8:43, Caveman Al Toraboran wrote: |
2 |
> |
3 |
> would i get blacklisted for simply not using |
4 |
> spf/dkim/etc? even if no other user is using the |
5 |
> mail service other than me and i'm not mass |
6 |
> mailing? |
7 |
|
8 |
Well, hear my story: I too was running simple mail-server. Just |
9 |
a few users I trust, no public relaying, so what could possibly |
10 |
go wrong? As it turned out later: everything! |
11 |
|
12 |
For a few months all was running as expected, but then some time |
13 |
later all valid email sent by my mail-server was suddenly flagged |
14 |
as spam and rejected. It took me some time to investigate but |
15 |
finally I found my domain (not IP) was on Spamhaus' DBL (domain |
16 |
block list). How did it get there? |
17 |
|
18 |
It seems that someone has created faked spf-record for my domain |
19 |
(I was not using dnssec at that time) and somehow spread it out |
20 |
(maybe using dns cache-poisoning?) to many public dn-resolvers. |
21 |
With that spf-record he authorised many spam-sending hosts to |
22 |
send email with sender field pointing to my domain. |
23 |
|
24 |
And that was even bigger problem, because one can easily switch |
25 |
to different vps/IP if it gets blacklisted, but I did not want to |
26 |
abandon my domain. It took me quite long time to fix everything. |
27 |
|
28 |
So short answer is yes! Even if you are not mass-mailing, you can |
29 |
still get blacklisted, if you do not secure your IP, domain and |
30 |
mail-server properly... |
31 |
|
32 |
Jarry |
33 |
|
34 |
-- |
35 |
_______________________________________________________________ |
36 |
This mailbox accepts e-mails only from selected mailing-lists! |
37 |
Everything else is considered to be spam and therefore deleted. |