Hello,

last few days we've had 2 diferent IP addresses listed in SpamHaus ZEN

1. monitoring server which rarely sends e-mail
- to single address in our internal network
- single address of our customer (outside our network)
- got listed after 4 e-mails within one day.

2. nextcloud server which sends only a few mails in a time
- mostly to our internal network
- one single gmail address on 2024/02/29
- also got listed after 4 e-mails within one day

The only common denominator except our AS is our internal network as destination, running Fortimail, admins told me it's very unlikely to report to SpamHaus.

I have tcpdump running on the latter for over a month because this happened about 3rd time within a few months - no other port 25 connection was made nearly two weeks before listing.

We have delisted both addresses without any feedback but I am really curious what happens here and/or how to avoid it.

Are there any other checks or measures I can do?

Is there anyone from SpamHaus who could help me to solve this?


Thanks for any ideas.

--
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Spam is for losers who can't get business any other way.
_______________________________________________
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop

Reply via email to