01/05/2009

some DNS server tests are totally wrong on emailresponse

from experience

when you do the automatic online DNS server test, the online test says that an email was sent and was received and it shows that everything is OK

It is not OK because the server has send an email saying that this address is not in its maildirectory and doesn't exist.

The purpose of a contact address for problems is that the emailaddress exists, not that the mailserver sends you a message that nobody has seen your mail and that nobody will respond

This is off course dangerous because if the emailadress for technical contacts doesn't exsit, technical and securitypeople can't contact you when something goes extremely wrong. After a while they will give up and just block you. Period. And than you can start clearning up the mess.

It is better to include in the test that you or the program sends a test mail to the contact and that if it doesn't give a 'no mailaddress by this name' response it is good.

Test for yourself if your own emailadresses on your installations are still working.

It is better to have a generic address like for example incident@ or infosec@ or something like that.... so that no matters who is working where when he or she will have access to the mails that are coming in and give a sign of life.

12:33 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment