Conversation

Replying to
By all means, build a tool that does this. Instructions and code are linked at the bottom. This tool doesn't, because that would make it less useful as a tool (i.e. knowing where you stand without social risk).
2
1
The risk is a false sense of security if resolv.conf lists at least one non-loopback resolver. The portable C-library DNS resolver routines don't expose any getters or setters for the nameserver list, so Postfix is blind to the security of the configured resolvers. Caveat admin.