False RBL detections

Spacey

Renowned Member
Sep 6, 2013
17
5
68
Hi!
Today while waiting for an eMail I noticed through the PMG Tracking Center that it got rejected by RBL:

2025-02-27T16:17:22.914011+01:00 shield postfix/postscreen[4774]: NOQUEUE: reject: RCPT from [173.0.84.6]:32681: 550 5.7.1 Service unavailable; client [173.0.84.6] blocked using zen.spamhaus.org; from=<service@paypal.de>, to=<my@email.de>, proto=ESMTP, helo=<mx17.slc.paypal.com>

Same for another one earlier today from another RBL:

2025-02-27T11:45:07.262036+01:00 shield postfix/postscreen[337652]: NOQUEUE: reject: RCPT from [94.100.132.91]:33955: 550 5.7.1 Service unavailable; client [94.100.132.91] blocked using cbl.abuseat.org; from=<sender@email.de>, to=<my@email.de>, proto=ESMTP, helo=<mx-relay91-hz1.antispameurope.com>

When query'ing the 2 sender-server-IPs 173.0.84.6 & 94.100.132.91 through spamhaus.org I could not get any negative report on them there?!
The eMails themselves were good ones - one from PayPal and another one from an HR company.

Any idea?

Of course running the latest version of PMG - everything updated to today.

Thanks!
 
hm - maybe you're running into the query limits at the dns-bls (although those usually result in nothing being listed for you anymore):
https://www.spamhaus.org/faqs/dnsbl-usage/

What kind of DNS-Server are you using for PMG?
(There used to be some problems with pfsense and the unbound config there if I recall correctly)
 
  • Like
Reactions: Spacey
My PMG sit's at Hetzner - I'm using their DNS primary (185.12.64.1) & secondary (185.12.64.2) & 8.8.8.8 as 3rd.

I don't think that it's query limit's - only my private server with about 150 mails per day.
 
Ah.. OK, stupid me... of course. So It'd be better to run & use my own DNS then instead...
 
I installed the local quick unbound and set this one up to be used. Monitoring the results.... thanks a lot!