Elektrine lite

← Feed

@cks@mastodon.social

Post #1475624

2026-04-20 18:34 UTC

I did some more digging using our firewall PF logs and it appears pretty definite that some people showed up to do SMTP authentication probes only after this host appeared in DNS MX and got a TLS certificate. It's possible that the TLS certificate is the trigger for SMTP auth attempts, but they're very bad SMTP auth attempts (they aren't starting TLS, for a start, and this backup MX doesn't do SMTP auth).

Replies (1)

  • @JdeBP@mastodonapp.uk 2026-04-21 01:41

    @cks@mastodon.social Yes, no surprises here. People are definitely still scraping DNS content for attacks. I regularly get services being requested for domain names that only appear at all for the sake of NS resource records. #DomainNameSystem

    Open ##1475623