Community Discussions and Support
Reverse DNS check

That would be a good option to check.

Another would be to see if the FQDN in a HELO resolves.

 

<p>That would be a good option to check.</p><p>Another would be to see if the FQDN in a HELO resolves.</p><p> </p>

Morning all,

Is there any way to perform a RDNS check in MercuryS.

What I want to do is check the HELO/EHLO text against RDNS and if they don't match, reject the connection since most email servers provide a FQDN as the HELO/EHLO command.

i.e This IP has no RDNS info:-

Connection from 202.134.4.162
T 20190331 103329 5c59bad3 EHLO dua.iix.mx
T 20190331 103329 5c59bad3 STARTTLS
T 20190331 103330 5c59bad3 EHLO dua.iix.mx
T 20190331 103331 5c59bad3 MAIL FROM:<bkk@ambon.go.id> SIZE=247690

Checking RIPEstat the IP resolves to an address in jakata with no RDNS

https://stat.ripe.net/202.134.4.162#tabId=at-a-glance

I've looked at the SmtpEvt module, but didn't find anything that might help. It might be a good addition though.

GreyWall works well to remove a lot of instances, but a few still get through.

Thanks in advance

John.

 

&lt;p&gt;Morning all,&lt;/p&gt;&lt;p&gt;Is there any way to perform a RDNS check in MercuryS.&lt;/p&gt;&lt;p&gt;What I want to do is check the HELO/EHLO text against RDNS and if they don&#039;t match, reject the connection since most email servers provide a FQDN as the HELO/EHLO command.&lt;/p&gt;&lt;p&gt;i.e This IP has no RDNS info:- &lt;/p&gt;&lt;p&gt;Connection from 202.134.4.162 T 20190331 103329 5c59bad3 EHLO dua.iix.mx T 20190331 103329 5c59bad3 STARTTLS T 20190331 103330 5c59bad3 EHLO dua.iix.mx T 20190331 103331 5c59bad3 MAIL FROM:&amp;lt;bkk@ambon.go.id&amp;gt; SIZE=247690&lt;/p&gt;&lt;p&gt;Checking RIPEstat the IP resolves to an address in jakata with no RDNS&lt;/p&gt;&lt;p&gt;&lt;a mce_href=&quot;https://stat.ripe.net/202.134.4.162#tabId=at-a-glance&quot; target=&quot;_blank&quot; title=&quot;https://stat.ripe.net/202.134.4.162#tabId=at-a-glance&quot; href=&quot;https://stat.ripe.net/202.134.4.162#tabId=at-a-glance&quot;&gt;https://stat.ripe.net/202.134.4.162#tabId=at-a-glance&lt;/a&gt;&lt;/p&gt;&lt;p&gt;I&#039;ve looked at the SmtpEvt module, but didn&#039;t find anything that might help. It might be a good addition though.&lt;/p&gt;&lt;p&gt;GreyWall works well to remove a lot of instances, but a few still get through.&lt;/p&gt;&lt;p&gt;Thanks in advance&lt;/p&gt;&lt;p&gt;John. &lt;/p&gt;&lt;p&gt;&amp;nbsp; &lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft