<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tom's blog &#187; backscatter</title>
	<atom:link href="http://tom.knaupp.com/tag/backscatter/feed/" rel="self" type="application/rss+xml" />
	<link>http://tom.knaupp.com</link>
	<description>free software, security and a bunch of my strange thoughts</description>
	<lastBuildDate>Fri, 21 Jan 2011 00:13:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Should I use DNSBL?</title>
		<link>http://tom.knaupp.com/2008/03/05/should-i-use-dnsbl/</link>
		<comments>http://tom.knaupp.com/2008/03/05/should-i-use-dnsbl/#comments</comments>
		<pubDate>Tue, 04 Mar 2008 23:18:25 +0000</pubDate>
		<dc:creator>tom</dc:creator>
				<category><![CDATA[Mailserver]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[backscatter]]></category>
		<category><![CDATA[RBL]]></category>
		<category><![CDATA[spamhaus]]></category>

		<guid isPermaLink="false">http://tom.knaupp.com/2008/03/05/should-i-use-dnsbl/</guid>
		<description><![CDATA[RBLs &#8211; yes / no.. a big discussion always.. Right now, I can recommend zen.spamhaus.org &#38; ix.dnsbl.manitu.net (&#60;- especially for german MXs). I&#8217;ve never seen a false positive on these lists .. Nevertheless, use the lists for scoring (i.e. with spamassassin), not for instant blocking! Nowadays, prosecuting &#8220;backscatter&#8221;, sender callouts, etc. seems to be a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/DNSBL" title="DNSBL" target="_blank">RBLs</a> &#8211; yes / no.. a big discussion always..<br />
Right now, I can recommend <a href="http://www.spamhaus.org" title="Spamhaus" target="_blank">zen.spamhaus.org</a> &amp; <a href="http://www.dnsbl.manitu.net/" title="DNSBL IX" target="_blank">ix.dnsbl.manitu.net</a> (&lt;- especially for german MXs).<br />
I&#8217;ve never seen a false positive on these lists ..<br />
<br />
Nevertheless, use the lists for scoring (i.e. with spamassassin), not for instant blocking!<br />
<br />
Nowadays, prosecuting &#8220;backscatter&#8221;, sender callouts, etc. seems to be a new trend &#8211; and it <em>could</em> be useful in future..<br />
I&#8217;ve tested the only free list I know &#8211; backscatterer.org.<br />
Don&#8217;t you use that one for immediate blocking!<br />
Scoring can be ok, but even there &#8211; watch your logs!<br />
<br />
Some &#8220;hits&#8221; (from a test run) to show what I found:<br />
&#8230;<br />
2008-03-04 17:17:42 H=lizzard.sbs.de [194.138.37.39] &#8211; possible backscatter<br />
2008-03-04 17:21:59 H=mail.space.net [195.30.0.8] &#8211; possible backscatter<br />
2008-03-04 17:25:33 H=relay4.ptmail.sapo.pt [212.55.154.24] &#8211; possible backscatter<br />
2008-03-04 17:32:46 H=<strong>relay23.arbeitsagentur.de</strong> [212.204.77.151] &#8211; possible backscatter<br />
2008-03-04 17:33:38 H=mout1.mail.vrmd.de [81.28.224.19] &#8211; possible backscatter<br />
2008-03-04 17:48:33 H=<strong>dgate1.fujitsu-siemens.com</strong> [217.115.66.35] &#8211; possible backscatter<br />
2008-03-04 17:50:05 H=<strong>mailout05.sul.t-online.de</strong> [194.25.134.82] &#8211; possible backscatter<br />
2008-03-04 17:51:27 H=relay0-0.brigade.com [209.249.158.73] &#8211; possible backscatter<br />
2008-03-04 18:04:42 H=<strong>mailout07.sul.t-online.de </strong>[194.25.134.83] &#8211; possible backscatter<br />
2008-03-04 18:11:21 H=bay0-omc2-s24.bay0.hotmail.com [65.54.246.160] &#8211; possible backscatter<br />
2008-03-04 18:13:37 H=mail.space.net [195.30.0.8] &#8211; possible backscatter<br />
2008-03-04 18:13:42 H=<strong>smtp1.versatel.nl</strong> [62.58.50.88] &#8211; possible backscatter<br />
2008-03-04 18:15:29 H=<strong>mailout09.sul.t-online.de</strong> [194.25.134.84] &#8211; possible backscatter<br />
2008-03-04 18:16:33 H=ip17.be3a.com (be3a.com) [213.92.9.17] &#8211; possible backscatter<br />
2008-03-04 18:18:12 H=gamwsm02.mwga.mailwatch.com [216.157.255.16] &#8211; possible backscatter<br />
2008-03-04 18:20:15 H=aps67.muc.ec-messenger.com [195.140.186.67] &#8211; possible backscatter<br />
2008-03-04 18:22:56 H=mout1.mail.vrmd.de [81.28.224.19] &#8211; possible backscatter<br />
2008-03-04 18:25:46 H=mail.gmx.net [213.165.64.20] &#8211; possible backscatter<br />
2008-03-04 18:27:56 H=<strong>mail004.thyssenkrupp.com</strong> [149.211.153.66] &#8211; possible backscatter<br />
2008-03-04 18:30:43 H=<strong>mailout04.sul.t-online.de</strong> [194.25.134.18] &#8211; possible backscatter<br />
2008-03-04 18:33:06 H=<strong>mailout03.sul.t-online.de</strong> [194.25.134.81] &#8211; possible backscatter<br />
2008-03-04 18:39:33 H=<strong>mail.gmx.net</strong> [213.165.64.20] &#8211; possible backscatter<br />
2008-03-04 18:45:20 H=<strong>mail.schule.bayern.de</strong> [194.95.207.92] &#8211; possible backscatter<br />
2008-03-04 18:48:56 H=skibayf20.kirche-bayern.de [141.78.101.100] &#8211; possible backscatter<br />
&#8230;<br />
<br />
A lot of the BIG players (german companies in this example mainly) are found on the list ..<br />
So don&#8217;t get yourself in trouble with users that complain all day long and think about what you&#8217;re blocking ..<br />
<br />
Any suggestion/comment ist highly appreciated.</p>
]]></content:encoded>
			<wfw:commentRss>http://tom.knaupp.com/2008/03/05/should-i-use-dnsbl/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

