At 08:27 PM 10/2/2003, Brad Knowles wrote:
Over 50% of the ccTLD nameservers are open public
caching/recursive nameservers and vulnerable to cache
pollution/poisoning.
[[snip]]
I recognize that there is a problem with DNS that has potential for
abuse, but I seriously question whether the mail transfer protocol is
the appropriate place to deal with it.
Is this problem, by itself, justification for the additional overhead of
X.509 authentication for the *receiving* MTA as a requirement in the
mail transfer protocol? I tend to think it's a problem that should be
dealt with in DNS.
Please take a look at the archive, we had an extensive discussion a
while back in regards to DNS security and DNS-SEC.