Seeing the "URIBL_BLOCKED" rule being hit every once in a while in the Syslog...

diamondcomputer

New Member
May 8, 2024
1
0
1
Good afternoon all.

We've recently set up a new Proxmox Email Gateway server and have been pretty impressed so far with all it can do to curb the spam flow to our mail servers. Watching the Syslog feed for a while today I noticed several "URIBL_BLOCKED" messages, which seems strange to me as our mail volume isn't heavy and I have set up and am exclusively using the local unbound DNS server for resolution. It's not consistently being blocked, but I'd still love to chase down the reason why it is every once in a while.

Does anyone know what the threshold is for "too many" queries?

Thanks!

Phil D. Malmstrom
Diamond Computer Incorporated
 
Hi,

What's the result when run this command on your server?
Code:
host -tTXT 2.0.0.127.multi.uribl.com
 
URIBL_BLOCKED"
nd I have set up and am exclusively using the local unbound DNS server for resolution.
just to be on the safe side - is the local unbound:
* really resolving everything by itself (no forward DNS server configured)?
* not shared with any other system (no other system has PMG's IP as DNS server)
* not sharing the public IP with another DNS server which also does DNSBL lookups?

else could you please share some logs of such mails - maybe we see something else there
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!