This forum is closed to new posts and
responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:
Forgive my frustation, but... ~Umberto Nongeroson 8.Jan.03 03:57 PM a Web browser Domino Administrator 6.0All Platforms
... this is whitelisting how exactly?
This functionality exists solely so that sites using SMTP within a secure, trusted perimeter as well as externally can choose to use DNSRBL for external hosts, knowing that SMTP hosts they have chosen to trust (i.e. hosts they control, inside their trusted perimeter) will not cause redundant DNSRBL look-ups. There really is no point in doing a DNSRBL look-up on hosts like 192.168.0.1 or 10.0.0.1, for example.
The scenario we are debating here is different.
Company A uses a Domino host with DNSRBL site blocklist.org.
Company B, a customer of company A has failed to secure its own SMTP MTA against third party relay and so ends up listed in blocklist.org
Company A wishes to accept mail from company B's host regardless of its listing in the block list (i.e. wishes to whitelist it)
However, company B's host is both an unsecure relay and outside of company A's control, therefore company A does not wish to make company B's MTA exempt from all anti relay checking.
Now, where's the whitelist?
This has been debated here before (read through some of these threads and these ones) and the workaround you propose is just that, a workaround, with one very significant weakness - it makes your Domino MTA the output stage of a multi-stage open relay, where your "whitelisted" site is the input stage.
I really hope Domino 6 admins are not going to adopt this technique en masse - spammy is sure to discover and exploit it - in fact there is some anecdotal evidence that he already has.
IBM/Lotus, please tell me you understand this and please give us our white list some time soon - surely can't be so difficult for you?