Chapter 32 Email Security
ZyWALL ATP Series User’s Guide
566
Figure 367
Conflicting DNSBL Replies Example
1
The Zyxel Device receives an email that was sent from IP address a.b.c.d and relayed by an email server
at IP address w.x.y.z. The Zyxel Device sends a separate query to each of its DNSBL domains for IP
address a.b.c.d. The Zyxel Device sends another separate query to each of its DNSBL domains for IP
address w.x.y.z.
2
DNSBL A replies that IP address a.b.c.d does not match any entries in its list (not spam).
3
While waiting for a DNSBL reply about IP address w.x.y.z, the Zyxel Device receives a reply from DNSBL B
saying IP address a.b.c.d is in its list.
4
The Zyxel Device immediately classifies the email as spam and takes the action for spam that you
defined in the email security policy. In this example it was an SMTP mail and the defined action was to
drop the mail. The Zyxel Device does not wait for any more DNSBL replies.
DNSBL A
DNSBL B
DNSBL C
IPs: a.b.c.d
w.x.y.z
1
2
a.b
.c.
d N
ot
sp
am
3
4
a.b
.c.
d?
w.
x.y
.z?
a.b
.c.d
?
w.x
.y.z
?
a.b.c.d?
w.x.y.z?
a.b.c.d Spam!