Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15958

Re: VS: Dumb Question is an A or AAAA record required?

Path csiph.com!news.uzoreto.com!news.szaf.org!nntp-feed.chiark.greenend.org.uk!ewrotcd!usenet-its.stanford.edu!usenet.stanford.edu!not-for-mail
From Reindl Harald <h.reindl@thelounge.net>
Newsgroups comp.protocols.dns.bind
Subject Re: VS: Dumb Question is an A or AAAA record required?
Date Thu, 9 Jul 2020 16:44:37 +0200
Organization the lounge interactive design
Lines 60
Approved bind-users@lists.isc.org
Message-ID <mailman.681.1594307375.942.bind-users@lists.isc.org> (permalink)
References <B1C7B197-34CE-42AB-92CC-69F65B35D3FD@kreme.com> <7ab19939-3025-c874-e5a4-97721eb435fc@ripe.net> <ep8egf1jv84i97uev69vr17ld66g4fave6@m78> <cdf3e561418942c399a22a74182a93df@qnet.fi> <7d0bc131-1019-06ba-d7e5-2b0c02ad0069@thelounge.net>
NNTP-Posting-Host lists.isc.org
Mime-Version 1.0
Content-Type text/plain; charset=utf-8
Content-Transfer-Encoding 8bit
X-Trace usenet.stanford.edu 1594307409 21089 149.20.1.60 (9 Jul 2020 15:10:09 GMT)
X-Complaints-To action@cs.stanford.edu
To bind-users@lists.isc.org
Return-Path <h.reindl@thelounge.net>
X-Original-To bind-users@lists.isc.org
Delivered-To bind-users@lists.isc.org
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.10.0
In-Reply-To <cdf3e561418942c399a22a74182a93df@qnet.fi>
Content-Language en-US
X-Spam-Status No, score=0.8 required=5.0 tests=KAM_MXURI,RCVD_IN_DNSWL_LOW, RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL,SPF_HELO_PASS,SPF_PASS autolearn=disabled version=3.4.2
X-Spam-Checker-Version SpamAssassin 3.4.2 (2018-09-13) on mx.pao1.isc.org
X-Mailman-Approved-At Thu, 09 Jul 2020 15:09:34 +0000
X-BeenThere bind-users@lists.isc.org
X-Mailman-Version 2.1.29
Precedence list
List-Id BIND Users Mailing List <bind-users.lists.isc.org>
List-Unsubscribe <https://lists.isc.org/mailman/options/bind-users>, <mailto:bind-users-request@lists.isc.org?subject=unsubscribe>
List-Archive <https://lists.isc.org/pipermail/bind-users/>
List-Post <mailto:bind-users@lists.isc.org>
List-Help <mailto:bind-users-request@lists.isc.org?subject=help>
List-Subscribe <https://lists.isc.org/mailman/listinfo/bind-users>, <mailto:bind-users-request@lists.isc.org?subject=subscribe>
X-Mailman-Original-Message-ID <7d0bc131-1019-06ba-d7e5-2b0c02ad0069@thelounge.net>
X-Mailman-Original-References <B1C7B197-34CE-42AB-92CC-69F65B35D3FD@kreme.com> <7ab19939-3025-c874-e5a4-97721eb435fc@ripe.net> <ep8egf1jv84i97uev69vr17ld66g4fave6@m78> <cdf3e561418942c399a22a74182a93df@qnet.fi>
Xref csiph.com comp.protocols.dns.bind:15958

Show key headers only | View raw



Am 09.07.20 um 16:38 schrieb Jukka Pakkanen:
> Many spammers send in addition to MX to A records, if available.  Still, it is a good practice to not to publish an A record for the mail zone, if not specifically needed for something else.  Of course if it points to somewhere else than the receiving SMTP server, not much harm done mail-traffic-wise.

why should it be a good practice not publish an A record?

nothing better can happen than a spammer trying the wrong server at all
as you don't accept random unauthenticated inbound mail on random machines

> -----Alkuperäinen viesti-----
> Lähettäjä: bind-users <bind-users-bounces@lists.isc.org> Puolesta Matthew Richardson
> Lähetetty: 9. heinäkuuta 2020 16:06
> Vastaanottaja: bind-users <bind-users@lists.isc.org>
> Aihe: Re: Dumb Question is an A or AAAA record required?
> 
> On a related issues there were (perhaps long ago) issues if the A record for a domain had an SMTP server on it, where email could sometimes be delivered to that A record rather than the MX.  I had (again long ago:
> 10-15 years) actually seen this occur.
> 
> Do people think that this problem could still occur these days?  What sort of transient (presumably DNS) failure might cause an SMTP server to deliver to A rather than MX?
> 
>> From: Anand Buddhdev <anandb@ripe.net>
>> To: "@lbutlr" <kremels@kreme.com>, bind-users 
>> <bind-users@lists.isc.org>
>> Cc: 
>> Date: Thu, 9 Jul 2020 14:43:04 +0200
>> Subject: Re: Dumb Question is an A or AAAA record required?
> 
>> On 09/07/2020 14:21, @lbutlr wrote:
>>
>>> Given a domain that is hosted and used for email and web, is an A 
>>> record for that domain actually required?
>>
>> It's not *required*. But see below.
>>
>>> That is, if bob.tld is hosted by example.com can you simply have
>>>
>>> 	NS ns1.example.com
>>> 	NS ns2.example.com
>>> 	MX mx.example.com
>>>
>>> www	CNAME www.example.com
>>>
>>> Without specifying
>>>
>>> 	A 11.22.33.444
>>
>> These days, many folk try to reach websites by typing just the bare 
>> domain name without the "www" prefix.
>>
>> If a user types "bob.tld" into a browser, the browser will issue an 
>> address lookup for "bob.tld", causing the resolver to ask for A and 
>> AAAA records for "bob.tld". If you don't have an A record at the zone 
>> apex, the browser will not get back any address and display an error 
>> message for the user. An alert user might try "www.bob.tld" but most 
>> users are likely to just give up.
>>
>> So while it's not *required* to have an address record at the apex, 
>> it's good practice to have one.

Back to comp.protocols.dns.bind | Previous | Next | Find similar


Thread

Re: VS: Dumb Question is an A or AAAA record required? Reindl Harald <h.reindl@thelounge.net> - 2020-07-09 16:44 +0200

csiph-web