Gentoo Archives: gentoo-user

From: Jarry <mr.jarry@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] tips on running a mail server in a cheap vps provider run but not-so-trusty admins?
Date: Tue, 18 Aug 2020 13:26:34
Message-Id: 690bab6d-9f02-51b3-05a6-f79963a8bfe8@gmail.com
In Reply to: Re: [gentoo-user] tips on running a mail server in a cheap vps provider run but not-so-trusty admins? by Caveman Al Toraboran
1 On 18-Aug-20 8:43, Caveman Al Toraboran wrote:
2 >
3 > would i get blacklisted for simply not using
4 > spf/dkim/etc? even if no other user is using the
5 > mail service other than me and i'm not mass
6 > mailing?
7
8 Well, hear my story: I too was running simple mail-server. Just
9 a few users I trust, no public relaying, so what could possibly
10 go wrong? As it turned out later: everything!
11
12 For a few months all was running as expected, but then some time
13 later all valid email sent by my mail-server was suddenly flagged
14 as spam and rejected. It took me some time to investigate but
15 finally I found my domain (not IP) was on Spamhaus' DBL (domain
16 block list). How did it get there?
17
18 It seems that someone has created faked spf-record for my domain
19 (I was not using dnssec at that time) and somehow spread it out
20 (maybe using dns cache-poisoning?) to many public dn-resolvers.
21 With that spf-record he authorised many spam-sending hosts to
22 send email with sender field pointing to my domain.
23
24 And that was even bigger problem, because one can easily switch
25 to different vps/IP if it gets blacklisted, but I did not want to
26 abandon my domain. It took me quite long time to fix everything.
27
28 So short answer is yes! Even if you are not mass-mailing, you can
29 still get blacklisted, if you do not secure your IP, domain and
30 mail-server properly...
31
32 Jarry
33
34 --
35 _______________________________________________________________
36 This mailbox accepts e-mails only from selected mailing-lists!
37 Everything else is considered to be spam and therefore deleted.