first time setting up Spamassassin, I was getting refusals when trying to query URIBL.com when my nameservers were set to 8.8.8.8
I solved it by using my own bind9 dns recursive server...
and now I would like to understand how URIBL.com knew the originating source of my dns queries, i.e. how did it know my queries were coming from 8.8.8.8, and not that the queries were coming from the WAN ip of my email server?
Some light reading pointed me to rfc7871, which might explain the source of the dns query is now contained in the payload of the request headers? is it similar to a referrer ip in a http request?
As a followup question, why does URIBL.com care if it gets requests from 8.8.8.8 vs counting the qty of requests from individual ip addresses that are making the actual queries to URIBL.com?
Is it easier, more cost effective to use the largest dns source ip addresses as filters, than trying to track a million+ individual ip addresses from countless email servers?