 Matchstick
join:2001-09-08 UK
| reply to Mr Pilkington Re: Public pressure works against prominent compan
Errrm I'm no DNS expert but AIUI, if a SMTP server asks a DNS server for an MX record for which it is non-authoritative, the only way for the DNS server to find the MX record is to request it from a DNS server which *is* authoritative for the domain.
So if this is correct, you HAVE to continue to allow DNS requests for MX records from outside a small ACL of IPs.
And then how can the authoritative DNS server easily tell the difference between a legitimate request from a non-authoritative DNS server and a request direct from a zombied PC ? |