LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-26-2011, 09:16 AM   #1
deathsfriend99
Member
 
Registered: Nov 2007
Distribution: CentOS 6
Posts: 200

Rep: Reputation: 22
unexpected RCODE (REFUSED) & (SERVFAIL)


I run a mail server with a caching DNS. The server is debian and BIND9. I am getting a ton of these in my logwatch:

Code:
 
Query form disallowed client:
    unexpected RCODE (REFUSED) resolving '247.250.236.209.in-addr.arpa/PTR/IN': 209.236.251.114#53: 4 Time(s)
    unexpected RCODE (REFUSED) resolving 'dnsglobal.mantraonline.com/A/IN': 202.56.240.5#53: 1 Time(s)
    unexpected RCODE (REFUSED) resolving '223.45.90.144.in-addr.arpa/PTR/IN': 144.90.136.254#53: 4 Time(s)
    unexpected RCODE (REFUSED) resolving '1.163.245.199.in-addr.arpa/PTR/IN': 139.78.100.1#53: 1 Time(s)
    unexpected RCODE (REFUSED) resolving '62.56.160.14.in-addr.arpa/PTR/IN': 203.162.0.11#53: 4 Time(s)
    unexpected RCODE (SERVFAIL) resolving 'ns01.wl-infra.net/AAAA/IN': 217.70.177.40#53: 4 Time(s)
    unexpected RCODE (REFUSED) resolving 'ns.t-mobile.cz/AAAA/IN': 77.48.254.253#53: 1 Time(s)
    unexpected RCODE (REFUSED) resolving '153.71.226.159.in-addr.arpa/PTR/IN': 159.226.8.28#53: 4 Time(s)
    unexpected RCODE (REFUSED) resolving 'ABTS-TN-dynamic-196.107.164.122.airtelbroadband.in/A/IN': 202.56.240.5#53: 1 Time(s)
    unexpected RCODE (REFUSED) resolving 'iwt.tv/NS/IN': 74.55.69.165#53: 1 Time(s)
    unexpected RCODE (REFUSED) resolving '199.57.102.66.in-addr.arpa/PTR/IN': 208.44.130.120#53: 1 Time(s)
    unexpected RCODE (SERVFAIL) resolving 'fibre.cablebahamas.com/A/IN': 198.6.1.82#53: 1 Time(s)
I suspect that these are spammers hitting my mail server with bogus domains and the DNS is trying to resolve the IP to the domain, it is coming back false, and my mail server drops the message as designed. Am I correct or do I have something misconfigured?
 
Click here to see the post LQ members have rated as the most helpful post in this thread.
Old 11-28-2011, 02:43 AM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Quote:
I suspect that these are spammers hitting my mail server with bogus domains and the DNS is trying to resolve the IP to the domain, it is coming back false, and my mail server drops the message as designed. Am I correct or do I have something misconfigured?
You're correct. BTW you can stop them from appearing in your logs, by adding:
Code:
category lame-servers {null;};
in the logging section of your named.conf

Regards
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
DNS Issue [unexpected rcode (SERVFAIL)] Imranteli Linux - Newbie 11 04-15-2018 08:07 AM
Unexpected RCODE message Md.Abul Quashem Linux - Networking 2 08-22-2009 11:15 PM
BIND - Unexpected RCODE (SERVFAIL/REFUSED) errors beerfest Linux - Server 4 05-02-2008 01:26 PM
Problems with the export & sed commands... Unexpected respose returned..! MC1903 Linux - Newbie 5 02-07-2007 04:20 PM
DNS Log Errors: unexpected RCODE (REFUSED) mr.wobble Linux - Software 1 02-11-2006 10:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration