Submission + - whitehouse.gov web site is not RFC complaint 4
Oh, hell, why not?
https://www.ietf.org/rfc/rfc21...,
MAILBOX NAMES FOR COMMON SERVICES, ROLES AND FUNCTIONS
"If a host is not configured to accept mail directly, but it implements a service for which this specification defines a mailbox name, that host must have an MX RR set (see [RFC974]) and the mail exchangers specified by this RR set must recognize the referenced host's domain name as 'local' for the purpose of accepting mail bound for the defined mailbox name."
Oops.
> $ dig -4 +trace whitehouse.gov mx
>
> ; > DiG 9.18.30-0ubuntu0.20.04.1-Ubuntu > -4 +trace whitehouse.gov mx
>
> . 7067 IN NS k.root-servers.net.
> . 7067 IN NS c.root-servers.net.
> . 7067 IN NS m.root-servers.net.
> . 7067 IN NS g.root-servers.net.
> . 7067 IN NS i.root-servers.net.
> . 7067 IN NS e.root-servers.net.
> . 7067 IN NS l.root-servers.net.
> . 7067 IN NS h.root-servers.net.
> . 7067 IN NS j.root-servers.net.
> . 7067 IN NS b.root-servers.net.
> . 7067 IN NS f.root-servers.net.
> . 7067 IN NS a.root-servers.net.
> . 7067 IN NS d.root-servers.net.
>
>
> gov. 172800 IN NS b.ns.gov.
> gov. 172800 IN NS d.ns.gov.
> gov. 172800 IN NS a.ns.gov.
> gov. 172800 IN NS c.ns.gov.
> gov. 86400 IN DS 2536 13 2 0BAF26B7BBF313A859046FD3B1EE49DDFBA33934CFB3E717C21E2A29 35C2F259 > gov. 86400 IN RRSIG DS 8 1 86400 20250203170000 20250121160000 26470 . hHJeQcyc3e5II0ZhUzsA/uYkVXy5/40pPc5d/BI+7AseSos1QMhFNpPJ 0Qge0Smo8/pTdzvjXa2S4tRuOaGXPjoBVrHBwI8c5wrzT8gNHcIdhi/o hNjOfA5BhOQfxGf63akjFsrt0zlJ0yExu05jcm5QE4tXObp/7rG1Z7Rd j92R82ysbpRmD4aDWJzeO0O561O1E8ubt47EC7MdxQ7R7Y09piitoxM5 m/c8txtnbMSFvOWv+PK0BWhf2k5TxhnQ854zF9LBM5eRCPLPGjcWGUEk H2FlJNUNxXUco/tFKID4iKrlkTzo/E4z6jBv2T9uvUhLZ4ZnqTVGOacK rvuMVA==
>
>
> whitehouse.gov. 10800 IN NS ernest.ns.cloudflare.com.
> whitehouse.gov. 10800 IN NS wally.ns.cloudflare.com.
> whitehouse.gov. 3600 IN DS 2371 13 2 BE4C7B11AD123596BA672B13FFDA04CA73C9FE0652E66542AEFADAF2 06B381AE > whitehouse.gov. 3600 IN RRSIG DS 13 2 3600 20250122191209 20250120171209 35496 gov. AonGq9nTzH43zWIGFt2AmaDNWQTxW1Yr36f8GqyvRhj7zQwPhanwNjUR IxfN1X+fd5rEbPORUw+ha7jwibwtrg==
>
>
> whitehouse.gov. 1800 IN SOA ernest.ns.cloudflare.com. dns.cloudflare.com. 2362876422 10000 2400 604800 1800
> whitehouse.gov. 1800 IN NSEC \000.whitehouse.gov. A NS SOA HINFO TXT AAAA LOC SRV NAPTR CERT SSHFP RRSIG NSEC DNSKEY TLSA SMIMEA HIP CDS CDNSKEY OPENPGPKEY SVCB HTTPS URI CAA
> whitehouse.gov. 1800 IN RRSIG NSEC 13 2 1800 20250122191209 20250120171209 34505 whitehouse.gov. paP+qyptYxKTXoGNXkC0PLKcyeW9ZL9e60v0x4TQjhDX7HQoK5bgRuc3 gYF02w5SFUGbXWOfhvDaBclx+MsRCA==
> whitehouse.gov. 1800 IN RRSIG SOA 13 2 1800 20250122191209 20250120171209 34505 whitehouse.gov. uflQie+N0ILZXaYPd/NHxyLiNMR0tpZvsyLuwTCuL2fcSaJtQ/lARb2s n1OuRG8z4Z6tA+2fFb55Z/1lT8SlFA==
>
------------------------------------------------------------------------
No MX record.
That means a mail exchanger would use the A record for the mail server.
> ; > DiG 9.18.30-0ubuntu0.20.04.1-Ubuntu > whitehouse.gov a
>
>
>
>
>
> ; EDNS: version: 0, flags:; udp: 65494
>
>
>
>
> whitehouse.gov. 300 IN A 192.0.66.168
------------------------------------------------------------------------
That implies that there is a service running on port 25. Well, is there?
> Jan 21 09:44:22 smtp postfix/smtp[58429]: E6A0A9FDDE: to=, relay=none, delay=30, delays=0.22/0.02/30/0, dsn=4.4.1, status=deferred (connect to whitehouse.gov[192.0.66.130]:25: Connection timed out)
> Jan 21 09:50:33 smtp postfix/smtp[58589]: E6A0A9FDDE: to=, relay=none, delay=402, delays=371/0.03/30/0, dsn=4.4.1, status=deferred (connect to whitehouse.gov[192.0.66.223]:25: Connection timed out)
> Jan 21 10:00:33 smtp postfix/smtp[58663]: E6A0A9FDDE: to=, relay=none, delay=1002, delays=972/0.03/30/0, dsn=4.4.1, status=deferred (connect to whitehouse.gov[192.0.66.136]:25: Connection timed out)
Nope. Not RFC complaint.
Q.E.D.