Sender IP listed in many blacklist but email was still accepted

khangnch

New Member
May 28, 2022
16
1
3
HI everyone,

I have a strange situation lately.

I and many users using Proxmox Mail Gateway have received many virus/spam mails from a spammer. Strange thing is the IP address of spammer got listed by many blacklist however the email still was accepted and sent to out inbox. We do not have any whitelist rules for the senders. And the DNSBL sites we use as following:

zen.spamhaus.org*2,bl.spamcop.net*2,psbl.surriel.com*2,spamrbl.imp.ch*2,noptr.spamrats.com*2,escalations.dnsbl.sorbs.net*2,bl.score.senderscore.com*2,bl.spameatingmonkey.net*2,rbl.realtimeblacklist.com*2,dnsbl.dronebl.org*2,ix.dnsbl.manitu.net,b.barracudacentral.org,truncate.gbudb.net,bl.blocklist.de

I did not know what I may miss. So please recommend if anyone has a solution for this.

Thank you very much for your help.
 
* do you see any messages from postscreen in the system journal (check `journalctl -b` on the console and search for postscreen) ?
* are you sure that the external IPs are submitting mails to the external port of PMG? (defaults to port 25) - since postscreen only runs in that direction

* do you have any modifications to the postfix config or other changes on the system?
 
Hi.

Sorry for late reply.

I cannot see any strange log from the postscreen.

I am pretty sure that mails go through PMG because we can see the spam mail log in PMG Tracking Center.

I just modify the DNSBL threshold as follows:

1655205328304.png

Today, we still have the same situation. The sender IP is blacklisted but email was still accepted:

1655205383970.png

1655205470169.png