MESSAGE
DATE | 2015-12-25 |
FROM | Rick Moen
|
SUBJECT | Subject: [Hangout-NYLXS] Report on dns for nylxs.com and mrbrklyn.com
|
nylxs.com
---------
For this domain, I see three significant issues, which means you're
doing better than most people are.
1. You have only two authoritative nameservers. This is borderline OK,
but RFC2182 section 5 recommends at least 3 nameservers, maximum 3.
I can give you a third, NS1.SVLUG.ORG, IP 64.62.190.98. If you'd like
that, (a) add 64.62.190.98 to the AXFR ACL on your nameserver and let me
know, (b) I'll configure and test a slave setup there and let you know,
and then (c) you add NS1.SVLUG.ORG as an NS line to your zonefile and
add it to auth nameservers at your registrar. Offer is open. Just let
me know.
On the positive side, you have everything correct between your in-zone
NS records and the parent-zone records, so go you!
2. Your nameserver is configured to respond accurately, when asked
anonymously what software version it's running. General consensus is
that it's unwise to leave this ability enabled; it helps attackers find
vulnerable targets. I personally like to make my nameserver _lie_ when
sent that query. Compare:
$ dig -t txt -c CHAOS version.bind -at-www2.mrbrklyn.com. +short
"9.9.5-rpz2+rl.14038.05-P1"
$
$ dig -t txt -c CHAOS version.bind -at-ns1.linuxmafia.com. +short
"Shirley, you're joking."
$
In BIND, you do that by putting something like this in the Options
stanza:
version "Shirley, you're joking.";
3. (a) Your MTA refuses mail to postmaster-at-nylxs.com.
A valid postmaster address is required for any domain that sends mail.
Reference: RFC822 6.3, RFC1123 5.2.7, and RFC2821 4.5.1.
(b) Your MTA refuses mail to abuse-at-nylxs.com.
A valid abuse ddress is required for any domain that sends mail.
Reference: RFC2142 Section 2.
mrbrklyn.com
------------
1. Same as the other domain. Offer's open.
2. Same.
3. Same.
--
Cheers, « Il n'est si homme de bien, qu'il mette à l'examen
Rick Moen des loi toutes ses actions et pensées, qui ne soit
rick-at-linuxmafia.com pendable dix fois en sa vie. »
McQ! (4x80) -- Michel de Montaigne, Essais
_______________________________________________
hangout mailing list
hangout-at-nylxs.com
http://www.nylxs.com/
|
|