Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

Greylisting wothout apparent reason

$
0
0
Hi community,

on my customer's Astaro 8.305, I recently activated the Mail-Proxy functionality using SMTP-profile mode. Currently, there are two SMTP-profiles set up which are apart from routing settings quite similar.
Unfortunately, a very high percentage of incoming emails are greylisted, including those from my own mail server.
The smtp-log's entry for greylisted emails are something like that:


2012:07:04-14:27:34 srvfirewall exim-in[7134]: 2012-07-04 14:27:34 SMTP connection from [88.x.y.z]:48572 (TCP/IP connection count = 1)
2012:07:04-14:27:35 srvfirewall exim-in[10974]: 2012-07-04 14:27:35 [88.217.162.2] F=<prvs=1532C01275=user@external-domain.de> R=<customer@internal-domain.de> Verifying recipient address in Active Directory
2012:07:04-14:27:35 srvfirewall exim-in[10974]: 2012-07-04 14:27:35 1SmOgB-0002r0-0n ctasd reports 'Unknown' RefID:str=0001.0A0B0201.4FF436B7.016E,ss=1,re=0.00 0,fgs=0
2012:07:04-14:27:35 srvfirewall exim-in[10974]: 2012-07-04 14:27:35 1SmOgB-0002r0-0n Greylisting: Greylisted 88.x.y.z
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [1\26] 2012-07-04 14:27:35 1SmOgB-0002r0-0n H=mail.tetranet-services.de [88.x.y.z]:48572 F=<prvs=1532C01275=user@external-domain.de> temporarily rejected after DATA: Temporary local problem, please try again!
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [2\26] Envelope-from: <prvs=1532C01275=user@external-domain.de>
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [3\26] Envelope-to: <customer@internal-dmain.de>
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [4\26] P Received: from mail.external-domain.de ([88.217.162.2]:48572)
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [5\26] by srvfirewall.internal-domain.local with esmtp (Exim 4.76)
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [6\26] (envelope-from <prvs=1532C01275=user@external-domain.de>)
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [7\26] id 1SmOgB-0002r0-0n
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [8\26] for customer@internal-domain.de; Wed, 04 Jul 2012 14:27:35 +0200
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [9\26] P Received: from srv-exchange.external-domain.local ( [192.168.50.202]) by mail.external-domain.de
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [10\26] (Reddoxx engine) with SMTP id 85320090267; Wed, 4 Jul 2012 14:27:31 +0200
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [11\26] X-CTCH-RefID: str=0001.0A0B0201.4FF436B7.016E,ss=1,re=0.000,fgs= 0
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [12\26] Content-class: urn:content-classes:message
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [13\26] MIME-Version: 1.0
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [14\26] Content-Type: multipart/related;
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [15\26] type="multipart/alternative";
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [16\26] boundary="----_=_NextPart_001_01CD59E0.61F4118B"
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [17\26] Subject: Testmail2
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [18\26] X-MimeOLE: Produced By Microsoft Exchange V6.5
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [19\26] Date: Wed, 4 Jul 2012 14:27:30 +0200
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [20\26] I Message-ID: <09A3626188AB5449A39AD3B4A76FD86333C512@srv-exchange.internal-domain.local>
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [21\26] X-MS-Has-Attach: yes
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [22\26] X-MS-TNEF-Correlator:
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [23\26] Thread-Topic: Testmail2
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [24\26] Thread-Index: Ac1Z4GGNXVrpsicNTJmAn1YJpIBs5Q==
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [25\26] F From: "Tobias Bundy" <user@external-domain.de>
2012:07:04-14:27:35 srvfirewall exim-in[10974]: [26/26] T To: <customer@internal-domain.de>
2012:07:04-14:27:35 srvfirewall exim-in[10974]: 2012-07-04 14:27:35 SMTP connection from mail.external-domain.de [88.217.162.2]:48572 closed by QUIT

Due to this issue, and deactivated greylisting in both SMTP-profiles, and now emails are coming, through.
Could anybody help me out with troubleshooting this problem ?

Thank you very much in advance.

Regards

Tobias

Viewing all articles
Browse latest Browse all 14361

Trending Articles