Hi,
I receive a massive amount of spam every day. I am searching for the root cause and checked one of the messages. The IP of the sending server does appear on the Barracuda Blacklist, if I manually check this, nevertheless it gets delivered to me.
It seems that there is no RBL check at all:
Should the RBL check produce any log output?
This is my DNSBL Sites config:
DNSBL Threshold is set to 2.
PMG 7.1-3.
Thank you!
Greetings
Sebastian
I receive a massive amount of spam every day. I am searching for the root cause and checked one of the messages. The IP of the sending server does appear on the Barracuda Blacklist, if I manually check this, nevertheless it gets delivered to me.
It seems that there is no RBL check at all:
Code:
Jul 1 06:35:58 mx postfix/smtpd[14240]: connect from nuttire.ru.com[163.123.141.182]
Jul 1 06:35:59 mx postfix/smtpd[14240]: NOQUEUE: client=nuttire.ru.com[163.123.141.182]
Jul 1 06:37:07 mx pmg-smtp-filter[12466]: 1200C562BE79F38E274: new mail message-id=<YIo2xxTJiOvkWxL9hwmT8sJJJlQZEKAdsjGrB-EP7-0.egTmr4LuNaZyP0WtFUkpitJrj2uCJwQkKewUZHkJLS0@nuttire.ru.com>#012
Jul 1 06:37:09 mx pmg-smtp-filter[12466]: 1200C562BE79F38E274: SA score=0/5 time=2.017 bayes=undefined autolearn=disabled hits=HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.635),KAM_DMARC_STATUS(0.01),MIME_HTML_ONLY(0.1),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),T_SCC_BODY_TEXT_LINE(-0.01)
Jul 1 06:37:09 mx postfix/smtpd[14276]: connect from localhost.localdomain[127.0.0.1]
Jul 1 06:37:09 mx postfix/smtpd[14276]: 9C5EC120192: client=localhost.localdomain[127.0.0.1], orig_client=nuttire.ru.com[163.123.141.182]
Jul 1 06:37:09 mx postfix/cleanup[14277]: 9C5EC120192: message-id=<YIo2xxTJiOvkWxL9hwmT8sJJJlQZEKAdsjGrB-EP7-0.egTmr4LuNaZyP0WtFUkpitJrj2uCJwQkKewUZHkJLS0@nuttire.ru.com>
Jul 1 06:37:09 mx postfix/qmgr[836]: 9C5EC120192: from=<lobby@nuttire.ru.com>, size=6976, nrcpt=1 (queue active)
Jul 1 06:37:09 mx pmg-smtp-filter[12466]: 1200C562BE79F38E274: accept mail to <xxx@yyy.de> (9C5EC120192) (rule: default-accept)
Jul 1 06:37:09 mx postfix/smtpd[14276]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Jul 1 06:37:09 mx pmg-smtp-filter[12466]: 1200C562BE79F38E274: processing time: 2.061 seconds (2.017, 0.021, 0)
Jul 1 06:37:09 mx postfix/smtpd[14240]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (1200C562BE79F38E274); from=<lobby@nuttire.ru.com> to=<xxx@yyy.de> proto=ESMTP helo=<nuttire.ru.com>
Jul 1 06:37:09 mx postfix/smtp[14278]: Trusted TLS connection established to 192.168.X.X[192.168.X.X]:25: TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)
Jul 1 06:37:09 mx postfix/smtp[14278]: 9C5EC120192: to=<xxx@yyy.de>, relay=192.168.X.X[192.168.X.X]:25, delay=0.05, delays=0.01/0.01/0.01/0.02, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as A72191809BE)
Jul 1 06:37:09 mx postfix/qmgr[836]: 9C5EC120192: removed
Jul 1 06:37:22 mx postfix/smtpd[14240]: disconnect from nuttire.ru.com[163.123.141.182] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Should the RBL check produce any log output?
This is my DNSBL Sites config:
Code:
zen.spamhaus.org*2,bl.spamcop.net*2,psbl.surriel.com*2,spamrbl.imp.ch*2,noptr.spamrats.com*2,escalations.dnsbl.sorbs.net*2,bl.score.senderscore.com*2,bl.spameatingmonkey.net*2,rbl.realtimeblacklist.com*2,dnsbl.dronebl.org*2,ix.dnsbl.manitu.net,b.barracudacentral.org,truncate.gbudb.net,bl.blocklist.de
DNSBL Threshold is set to 2.
PMG 7.1-3.
Thank you!
Greetings
Sebastian