In the previous material, I showed the basic version of early filtering of incoming traffic on MikroTik through Spamhaus ZEN. The approach turned out to work - the load on mail services decreased by 30-70%, and the number of SMTP sessions decreased several times.
But during operation, important shortcomings surfaced:
Single point of failure - if Spamhaus DNS is unavailable, filtering stops completely and new malicious IPs are no longer blocked until service is restored.
False sense of security - NXDOMAIN was perceived by the script as an error, which is why the IP remained in the queue forever.
There is no understanding of the reasons for blocking - it is impossible to determine which DNSBL worked and for what reason.
These problems prompted us to rework the script.
Read more..