[SOLVED] Matching Rule: Block outgoing Spam

vusald

New Member
Apr 16, 2023
18
1
3
Hello. I am a little bit confused, and dunne where to dig

I have some users and they (not always) complains that mails they had sent bounced back

First I have this log on Proxmox v8.0.1

Code:
2023-10-03T08:42:21.732689+04:00 mail postfix/smtpd[49953]: connect from exch01.exchange.local[10.22.10.26]
2023-10-03T08:42:21.746346+04:00 mail postfix/smtpd[49953]: Anonymous TLS connection established from exch01.exchange.local[10.22.10.26]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
2023-10-03T08:42:21.766407+04:00 mail postfix/smtpd[49953]: BB0E8900442: client=exch01.exchange.local[10.22.10.26]
2023-10-03T08:42:21.767841+04:00 mail postfix/cleanup[49956]: BB0E8900442: message-id=<f2a284fcc89e410087a06f7c2d3e0141@zeynally.com>
2023-10-03T08:42:21.769069+04:00 mail postfix/qmgr[22481]: BB0E8900442: from=<sender@domain.com>, size=12261, nrcpt=1 (queue active)
2023-10-03T08:42:21.770168+04:00 mail postfix/smtpd[49953]: disconnect from exch01.exchange.local[10.22.10.26] ehlo=2 starttls=1 mail=1 rcpt=1 bdat=1 quit=1 commands=7
2023-10-03T08:42:27.868785+04:00 mail postfix/lmtp[49957]: BB0E8900442: to=<recipient@gmail.com>, relay=127.0.0.1[127.0.0.1]:10023, delay=6.1, delays=0.01/0.05/0.05/6, dsn=5.7.1, status=bounced (host 127.0.0.1[127.0.0.1] said: 554 5.7.1 Rejected for policy reasons (90046E651B9BADD5649) (in reply to end of DATA command))
2023-10-03T08:42:27.872007+04:00 mail postfix/qmgr[22481]: BB0E8900442: removed


and immediately after that a user receives mail from postmaster thet is pointed in my SPF record

Code:
DİQQƏT: Bu e-poçt kənar təşkilatdan gəlmişdir. Göndərəni tanımadığınız və məzmunun təhlükəsiz olub-olmadığını bilmədiyiniz halda keçidlərə klikləməyin və ya qoşmaları açmayın .




Proxmox Notification:

Sender:  sender@domain.com
Receiver: recipient@gmail.com
Targets:  recipient@gmail.com

Subject: TEST


Matching Rule: Block outgoing Spam

Rule: Block outgoing Spam
  Receiver: recipient@gmail.com
  Action: block message
  Action: notify support@domain.az
  Action: notify sender@domain.com



Spam detection results:  3
AWL                     0.411 Adjusted score from AWL reputation of From: address
HELO_NO_DOMAIN          0.001 Relay reports its domain incorrectly
HTML_MESSAGE            0.001 HTML included in message
KAM_DMARC_QUARANTINE      1.5 DKIM has Failed or SPF has failed on the message and the domain has a DMARC quarantine policy
KAM_DMARC_STATUS         0.01 Test Rule for DKIM or SPF Failure with Strict Alignment
RDNS_NONE               1.274 Delivered to internal network by a host with no rDNS
TVD_SPACE_RATIO         0.001 -
TVD_SPACE_RATIO_MINFP   0.001 Space ratio (vertical text obfuscation?)
T_SCC_BODY_TEXT_LINE    -0.01 -


I have the rule Rule: Block outgoing Spam and Spam level was 3 before I raised to 5.

I immediately sending mails from the OWA and mails are delivered to recipient. I take remote control of a computer - mail not sent from offline client.
Strange. But after some time, User can send and receive mails using offline client...

Have u ever faced with this kind of behavior....
 
Seems it relates to DKIM record in DNS.... I had wrong value in TXT. Not Wrong, but incomplete.. Have no idea how could I input incomplete vale there
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!