We have a Webmail server at our Organization which sends out/ Receives mails using a sendmail Mail Relay Agent.
When i check the connections w.r.t this server on my Cisco ASA i see around 3000-4000 from Multiple Public Ip's to UDP 53 on My server.
I have checked by doing DNS lookup of the PUblic IPs and they seem to be Public Relay agents on the Internet,
I would Like to know if it is normal characteristic to get hits on UDP 53 on Mail relay Agents.
I tried Blocking these requests once but our relay stopped sending mails to the internet after about 2 days from when i blocked it.
Please throw some light on it working.