nanog mailing list archives

Re: blocklists Amazon AWS cloudfront WAF block


From: "John R. Levine via NANOG" <nanog () lists nanog org>
Date: 1 Jun 2025 09:41:59 -0400

On Sun, 1 Jun 2025, John Curran wrote:

Out of curiosity, is there a reasonably clear document somewhere that describes how such network-level block
lists should be operated from the view of network operators; i.e., a “best practice” statement ...

Sort of.  See RFC 6471, Overview of Best Email DNS-Based List (DNSBL) Operational Practices.

Running a useful blocklist is very hard. Everyone who's listed insists that it's a mistake. Sometimes they have odd ideas of their responsibility ("we have no control over the customer, we just take their money and route their packets".) Sometimes they are sure they are special so the regular rules don't apply. Sometimes they are confused. Often they just lie. Occasionally, there really is a mistake but recoginizing it in the noise is not easy.

Regards,
John Levine, johnl () taugh com, Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail. https://jl.ly
_______________________________________________
NANOG mailing list https://lists.nanog.org/archives/list/nanog () lists nanog org/message/JGPS2YI7GAYTDWSJ76RTJHW2JUAPBMIH/

Current thread: