[SOLVED] Matching Rule: Block outgoing Spam


Apr 16, 2023
Hello. I am a little bit confused, and dunne where to dig

I have some users and they (not always) complains that mails they had sent bounced back

First I have this log on Proxmox v8.0.1

2023-10-03T08:42:21.732689+04:00 mail postfix/smtpd[49953]: connect from exch01.exchange.local[]
2023-10-03T08:42:21.746346+04:00 mail postfix/smtpd[49953]: Anonymous TLS connection established from exch01.exchange.local[]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
2023-10-03T08:42:21.766407+04:00 mail postfix/smtpd[49953]: BB0E8900442: client=exch01.exchange.local[]
2023-10-03T08:42:21.767841+04:00 mail postfix/cleanup[49956]: BB0E8900442: message-id=<f2a284fcc89e410087a06f7c2d3e0141@zeynally.com>
2023-10-03T08:42:21.769069+04:00 mail postfix/qmgr[22481]: BB0E8900442: from=<sender@domain.com>, size=12261, nrcpt=1 (queue active)
2023-10-03T08:42:21.770168+04:00 mail postfix/smtpd[49953]: disconnect from exch01.exchange.local[] ehlo=2 starttls=1 mail=1 rcpt=1 bdat=1 quit=1 commands=7
2023-10-03T08:42:27.868785+04:00 mail postfix/lmtp[49957]: BB0E8900442: to=<recipient@gmail.com>, relay=[]:10023, delay=6.1, delays=0.01/0.05/0.05/6, dsn=5.7.1, status=bounced (host[] said: 554 5.7.1 Rejected for policy reasons (90046E651B9BADD5649) (in reply to end of DATA command))
2023-10-03T08:42:27.872007+04:00 mail postfix/qmgr[22481]: BB0E8900442: removed

and immediately after that a user receives mail from postmaster thet is pointed in my SPF record

Proxmox Notification:

Sender:  sender@domain.com
Receiver: recipient@gmail.com
Targets:  recipient@gmail.com

Subject: TEST

Matching Rule: Block outgoing Spam

Rule: Block outgoing Spam
  Receiver: recipient@gmail.com
  Action: block message
  Action: notify support@domain.az
  Action: notify sender@domain.com

Spam detection results:  3
AWL                     0.411 Adjusted score from AWL reputation of From: address
HELO_NO_DOMAIN          0.001 Relay reports its domain incorrectly
HTML_MESSAGE            0.001 HTML included in message
KAM_DMARC_QUARANTINE      1.5 DKIM has Failed or SPF has failed on the message and the domain has a DMARC quarantine policy
KAM_DMARC_STATUS         0.01 Test Rule for DKIM or SPF Failure with Strict Alignment
RDNS_NONE               1.274 Delivered to internal network by a host with no rDNS
TVD_SPACE_RATIO         0.001 -
TVD_SPACE_RATIO_MINFP   0.001 Space ratio (vertical text obfuscation?)

I have the rule Rule: Block outgoing Spam and Spam level was 3 before I raised to 5.

I immediately sending mails from the OWA and mails are delivered to recipient. I take remote control of a computer - mail not sent from offline client.
Strange. But after some time, User can send and receive mails using offline client...

Have u ever faced with this kind of behavior....
Seems it relates to DKIM record in DNS.... I had wrong value in TXT. Not Wrong, but incomplete.. Have no idea how could I input incomplete vale there


