How protection decisions are made
Policy explanation is kept separate from live operational evidence so each page has one clear purpose.
ScotNet DNSBL uses retained security evidence and defined safeguards to decide when protection is justified. Decisions are deliberately bounded, reviewable and reversible rather than treated as permanent labels.
Decision principles
Evidence before action
Listings require qualifying security evidence and policy checks. Normal successful visitors, private/internal addresses and weak signals are excluded from automatic action.
Smallest useful scope
Exact-address action is preferred when sufficient. Broader prefix action requires additional independent evidence, thresholds and safety checks.
Reviewable decisions
Listing state, reason, expiry and operator decisions are designed to be traceable without exposing unrestricted attacker data.
Reversible protection
Actions can expire, be reviewed or be delisted after the underlying problem is corrected and the required proof of control is completed.
Typical lifecycle
1 · Observe
Security telemetry records a qualifying event.
2 · Evaluate
Source, confidence, thresholds and scope are checked.
3 · Protect
The narrowest appropriate DNSBL action is applied.
4 · Review
Expiry, operator review or signed delisting ends the action.
Public and private boundaries
What is public
- Bounded exact-address self-checks and DNSBL return reasons.
- Published policy and integration guidance.
- Sanitised aggregate service and recent-event information.
- Release history and high-level decision safeguards.
What remains private
- Raw security logs and unrestricted event history.
- Internal filesystem paths, monitor identifiers and credentials.
- Operator-only evidence, policy-review state and notification configuration.
- Bulk address exports that would turn transparency into a harvesting endpoint.
Operational transparency remains separate
Operational transparency remains the live DNSBL evidence and exact-address accountability interface. This page explains policy and decision safeguards; it does not duplicate the live evidence functions.
This presentation hotfix changes no DNSBL threshold, return code, feed behaviour, database schema, BIND policy or prefix-safety rule.