> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On
> Behalf Of Syafril Hermansyah
> Sent: Tuesday, April 17, 2012 1:12 PM
> To: Milis Komunitas MDaemon Indonesia
> Subject: [MDaemon-L] how to solve Permanent delivery failure


> Itu sebabnya saya sarankan cari siapa pengirim sebenarnya dari smtp-in log
> bukan berkutat di smtp-out log.

Di email sebelumnya bapak minta dicarikan log dengan Message-ID:
<48871013DF075B9D8CE8F43579B46E29@pebgnsok>
Berikut saya sertakan lognya

Tue 2012-04-17 00:14:58: ----------
Tue 2012-04-17 00:09:34: Parsing message
<d:\mdaemon\queues\remote\retry\pd90000004226.msg>
Tue 2012-04-17 00:09:34: *  From: [email protected]
Tue 2012-04-17 00:09:34: *  To: [email protected]
Tue 2012-04-17 00:09:34: *  Subject:
=?utf-8?B?NOaciDIwLTIx5pel5LiKL+a1t+OAgTXmnIgxMS0xMuaXpQ==?=
=?utf-8?B?5YyXL+S6rOOAgTXmnIgxOC0xOeaXpea3sS/lnLMg5Y2zIOWwhiA=?=
=?utf-8?B?5byAIOivviBmbW5nZXc=?=
Tue 2012-04-17 00:09:34: *  Size (bytes): 20550
Tue 2012-04-17 00:09:34: *  Message-ID:
<48871013DF075B9D8CE8F43579B46E29@pebgnsok>
Tue 2012-04-17 00:09:34: *  Route slip host: sohu.com
Tue 2012-04-17 00:09:34: *  Route slip port: 25
Tue 2012-04-17 00:09:34: Attempting SMTP connection to [sohu.com]
Tue 2012-04-17 00:09:34: Resolving MX records for [sohu.com] (DNS Server:
202.92.202.93)...
Tue 2012-04-17 00:09:34: *  P=005 S=000 D=sohu.com TTL=(0)
MX=[sohumx1.sohu.com]
Tue 2012-04-17 00:09:34: *  P=010 S=001 D=sohu.com TTL=(0)
MX=[sohumx.h.a.sohu.com]
Tue 2012-04-17 00:09:34: Attempting SMTP connection to [sohumx1.sohu.com:25]
Tue 2012-04-17 00:09:34: Resolving A record for [sohumx1.sohu.com] (DNS
Server: 202.92.202.93)...
Tue 2012-04-17 00:09:34: *  D=sohumx1.sohu.com TTL=(0) A=[61.135.132.110]
Tue 2012-04-17 00:09:34: Attempting SMTP connection to [61.135.132.110:25]
Tue 2012-04-17 00:09:34: Waiting for socket connection...
Tue 2012-04-17 00:09:35: *  Connection established (192.168.1.254:4370 ->
61.135.132.110:25)
Tue 2012-04-17 00:09:35: Waiting for protocol to start...
Tue 2012-04-17 00:11:46: Socket connection closed by the other side (how
rude!)
Tue 2012-04-17 00:11:46: *  Winsock Error 10053 Connection abort.
Tue 2012-04-17 00:11:46: Connection closed
Tue 2012-04-17 00:11:46: Attempting SMTP connection to
[sohumx.h.a.sohu.com:25]
Tue 2012-04-17 00:11:46: Resolving A record for [sohumx.h.a.sohu.com] (DNS
Server: 202.92.202.93)...
Tue 2012-04-17 00:11:46: *  D=sohumx.h.a.sohu.com TTL=(2) A=[61.135.132.110]
Tue 2012-04-17 00:11:46: Attempting SMTP connection to [61.135.132.110:25]
Tue 2012-04-17 00:11:46: Waiting for socket connection...
Tue 2012-04-17 00:11:46: *  Connection established (192.168.1.254:4416 ->
61.135.132.110:25)
Tue 2012-04-17 00:11:46: Waiting for protocol to start...
Tue 2012-04-17 00:14:58: Socket connection closed by the other side (how
rude!)
Tue 2012-04-17 00:14:58: *  Winsock Error 10053 Connection abort.
Tue 2012-04-17 00:14:58: Connection closed
Tue 2012-04-17 00:14:58: This message is 0 days old; it has 1 days left to
get delivered
Tue 2012-04-17 00:14:58: SMTP session terminated (Bytes in/out: 0/0)
Tue 2012-04-17 00:14:58: ----------

> 
> Transaksi di smtp-out log hanya symptom (dampak, indikasi), kalau ingin
> beres tuntas harus dicari tahu sumbernya dari transaksi di smtp-in log.

Cara mencari nya bagaimana yah pak lognya kan ribuan ?
Ini ada log yang agak mencurigakan apakah ini penyebabnya
Tue 2012-04-17 00:01:04: ----------
Tue 2012-04-17 00:01:45: Session 37347; child 3
Tue 2012-04-17 00:01:45: Accepting SMTP connection from [110.52.6.132:4448]
to [192.168.1.254:25]
Tue 2012-04-17 00:01:45: Performing PTR lookup (132.6.52.110.IN-ADDR.ARPA)
Tue 2012-04-17 00:01:47: *  Error: *  Name server reports domain name
unknown
Tue 2012-04-17 00:01:47: *  No PTR records found
Tue 2012-04-17 00:01:47: ---- End PTR results
Tue 2012-04-17 00:01:47: --> 220 mail.pttms.co.id ESMTP MDaemon 12.5.4; Tue,
17 Apr 2012 00:01:47 +0700
Tue 2012-04-17 00:01:47: <-- EHLO ckl
Tue 2012-04-17 00:01:47: Performing IP lookup (ckl)
Tue 2012-04-17 00:01:47: *  Error: *  The name server reports that it is
having technical problems
Tue 2012-04-17 00:01:47: ---- End IP lookup results
Tue 2012-04-17 00:01:47: --> 250-mail.pttms.co.id Hello ckl, pleased to meet
you
Tue 2012-04-17 00:01:47: --> 250-ETRN
Tue 2012-04-17 00:01:47: --> 250-AUTH LOGIN CRAM-MD5 PLAIN
Tue 2012-04-17 00:01:47: --> 250-8BITMIME
Tue 2012-04-17 00:01:47: --> 250 SIZE
Tue 2012-04-17 00:01:47: <-- AUTH LOGIN
Tue 2012-04-17 00:01:47: --> 334 VXNlcm5hbWU6
Tue 2012-04-17 00:01:48: <-- aXZvbm5lQHB0dG1zLmNvLmlk
Tue 2012-04-17 00:01:48: --> 334 UGFzc3dvcmQ6
Tue 2012-04-17 00:01:48: <-- ******
Tue 2012-04-17 00:01:48: --> 235 Authentication successful
Tue 2012-04-17 00:01:48: Authenticated as [email protected]
Tue 2012-04-17 00:01:48: <-- MAIL FROM: <[email protected]>
Tue 2012-04-17 00:01:48: --> 250 <[email protected]>, Sender ok
Tue 2012-04-17 00:01:49: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:49: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:49: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:49: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:49: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:49: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:49: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:49: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:50: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:50: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:50: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:50: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:50: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:50: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:51: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:51: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:51: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:51: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:51: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:51: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:52: <-- DATA
Tue 2012-04-17 00:01:52: Creating temp file (SMTP):
d:\mdaemon\queues\temp\md50000014118.tmp
Tue 2012-04-17 00:01:52: --> 354 Enter mail, end with <CRLF>.<CRLF>
Tue 2012-04-17 00:01:54: Message size: 49746 bytes
Tue 2012-04-17 00:01:54: Passing message through AntiVirus (Size: 49746)...
Tue 2012-04-17 00:01:54: *  Message is clean (no viruses found)
Tue 2012-04-17 00:01:54: ---- End AntiVirus results
Tue 2012-04-17 00:01:54: Message creation successful:
d:\mdaemon\queues\inbound\md50000629903.msg
Tue 2012-04-17 00:01:54: --> 250 Ok, message saved <Message-ID:
5E0B81216ABA87E6C06D0009AE3418E5@ckl>
Tue 2012-04-17 00:01:54: <-- QUIT
Tue 2012-04-17 00:01:54: --> 221 See ya in cyberspace
Tue 2012-04-17 00:01:54: SMTP session successful (Bytes in/out: 50177/853)
Tue 2012-04-17 00:01:54: ----------
Tue 2012-04-17 00:01:56: Session 37349; child 3
Tue 2012-04-17 00:01:56: Accepting SMTP connection from [110.52.6.132:4598]
to [192.168.1.254:25]
Tue 2012-04-17 00:01:56: Performing PTR lookup (132.6.52.110.IN-ADDR.ARPA)
Tue 2012-04-17 00:01:56: *  Error: *  Name server reports domain name
unknown
Tue 2012-04-17 00:01:56: *  No PTR records found
Tue 2012-04-17 00:01:56: ---- End PTR results
Tue 2012-04-17 00:01:56: --> 220 mail.pttms.co.id ESMTP MDaemon 12.5.4; Tue,
17 Apr 2012 00:01:56 +0700
Tue 2012-04-17 00:01:56: <-- EHLO nqlkwjnre
Tue 2012-04-17 00:01:56: Performing IP lookup (nqlkwjnre)
Tue 2012-04-17 00:01:57: *  Error: *  The name server reports that it is
having technical problems
Tue 2012-04-17 00:01:57: ---- End IP lookup results
Tue 2012-04-17 00:01:57: --> 250-mail.pttms.co.id Hello nqlkwjnre, pleased
to meet you
Tue 2012-04-17 00:01:57: --> 250-ETRN
Tue 2012-04-17 00:01:57: --> 250-AUTH LOGIN CRAM-MD5 PLAIN
Tue 2012-04-17 00:01:57: --> 250-8BITMIME
Tue 2012-04-17 00:01:57: --> 250 SIZE
Tue 2012-04-17 00:01:57: <-- AUTH LOGIN
Tue 2012-04-17 00:01:57: --> 334 VXNlcm5hbWU6
Tue 2012-04-17 00:01:57: <-- aXZvbm5lQHB0dG1zLmNvLmlk
Tue 2012-04-17 00:01:57: --> 334 UGFzc3dvcmQ6
Tue 2012-04-17 00:01:57: <-- ******
Tue 2012-04-17 00:01:57: --> 235 Authentication successful
Tue 2012-04-17 00:01:57: Authenticated as [email protected]
Tue 2012-04-17 00:01:58: <-- MAIL FROM: <[email protected]>
Tue 2012-04-17 00:01:58: --> 250 <[email protected]>, Sender ok
Tue 2012-04-17 00:01:58: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:58: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:58: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:58: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:01:59: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:01:59: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:00: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:02:00: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:00: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:02:00: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:00: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:02:00: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:01: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:02:01: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:01: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:02:01: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:01: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:02:01: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:01: <-- RCPT TO: <[email protected]>
Tue 2012-04-17 00:02:01: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:02: <-- DATA
Tue 2012-04-17 00:02:02: Creating temp file (SMTP):
d:\mdaemon\queues\temp\md50000014119.tmp
Tue 2012-04-17 00:02:02: --> 354 Enter mail, end with <CRLF>.<CRLF>
Tue 2012-04-17 00:02:03: Message size: 49758 bytes
Tue 2012-04-17 00:02:03: Passing message through AntiVirus (Size: 49758)...
Tue 2012-04-17 00:02:03: *  Message is clean (no viruses found)
Tue 2012-04-17 00:02:03: ---- End AntiVirus results
Tue 2012-04-17 00:02:04: Message creation successful:
d:\mdaemon\queues\inbound\md50000629904.msg
Tue 2012-04-17 00:02:04: --> 250 Ok, message saved <Message-ID:
A608AA0B051FC30B769E11DD29902CD5@nqlkwjnre>
Tue 2012-04-17 00:02:04: <-- QUIT
Tue 2012-04-17 00:02:04: --> 221 See ya in cyberspace
Tue 2012-04-17 00:02:04: SMTP session successful (Bytes in/out: 50196/866)
Tue 2012-04-17 00:02:04: ----------
Tue 2012-04-17 00:02:10: Session 37361; child 3
Tue 2012-04-17 00:02:10: Accepting SMTP connection from
[220.181.15.209:49334] to [192.168.1.254:25]
Tue 2012-04-17 00:02:10: Performing PTR lookup (209.15.181.220.IN-ADDR.ARPA)
Tue 2012-04-17 00:02:10: *  D=209.15.181.220.IN-ADDR.ARPA TTL=(950)
PTR=[m15-209.126.com]
Tue 2012-04-17 00:02:10: *  Gathering A records...
Tue 2012-04-17 00:02:10: *  D=m15-209.126.com TTL=(3830) A=[220.181.15.209]
Tue 2012-04-17 00:02:10: ---- End PTR results
Tue 2012-04-17 00:02:10: --> 220 mail.pttms.co.id ESMTP MDaemon 12.5.4; Tue,
17 Apr 2012 00:02:10 +0700
Tue 2012-04-17 00:02:10: <-- EHLO m12-11.126.com
Tue 2012-04-17 00:02:10: Performing IP lookup (m12-11.126.com)
Tue 2012-04-17 00:02:12: *  D=163a.xxcache.z.lxdns.com TTL=(2)
A=[123.125.50.22]
Tue 2012-04-17 00:02:12: ---- End IP lookup results
Tue 2012-04-17 00:02:12: --> 250-mail.pttms.co.id Hello m15-209.126.com (may
be forged), pleased to meet you
Tue 2012-04-17 00:02:12: --> 250-ETRN
Tue 2012-04-17 00:02:12: --> 250-AUTH LOGIN CRAM-MD5 PLAIN
Tue 2012-04-17 00:02:12: --> 250-8BITMIME
Tue 2012-04-17 00:02:12: --> 250 SIZE
Tue 2012-04-17 00:02:12: <-- MAIL FROM:<[email protected]>
Tue 2012-04-17 00:02:12: Performing IP lookup (126.com)
Tue 2012-04-17 00:02:13: *  D=126.com TTL=(300) A=[220.181.12.218]
Tue 2012-04-17 00:02:13: *  D=126.com TTL=(300) A=[123.125.50.22]
Tue 2012-04-17 00:02:13: *  P=010 S=000 D=126.com TTL=(59)
MX=[126mx02.mxmail.netease.com]
Tue 2012-04-17 00:02:13: *  P=010 S=002 D=126.com TTL=(59)
MX=[126mx01.mxmail.netease.com] {220.181.15.132}
Tue 2012-04-17 00:02:13: *  P=050 S=001 D=126.com TTL=(59)
MX=[126mx00.mxmail.netease.com]
Tue 2012-04-17 00:02:13: *  D=126.com TTL=(300) A=[123.125.50.22]
Tue 2012-04-17 00:02:13: *  D=126.com TTL=(300) A=[220.181.12.218]
Tue 2012-04-17 00:02:13: ---- End IP lookup results
Tue 2012-04-17 00:02:13: Performing SPF lookup (126.com / 220.181.15.209)
Tue 2012-04-17 00:02:13: *  126.com 220.181.15.209; matched to SPF cache
Tue 2012-04-17 00:02:13: *  Result: pass
Tue 2012-04-17 00:02:13: ---- End SPF results
Tue 2012-04-17 00:02:13: --> 250 <[email protected]>, Sender ok
Tue 2012-04-17 00:02:13: <-- RCPT TO:<[email protected]>
Tue 2012-04-17 00:02:13: Performing DNS-BL lookup (220.181.15.209 -
connecting IP)
Tue 2012-04-17 00:02:13: *  bl.spamcop.net - passed
Tue 2012-04-17 00:02:14: *  zen.spamhaus.org - passed
Tue 2012-04-17 00:02:14: ---- End DNS-BL results
Tue 2012-04-17 00:02:14: --> 250 <[email protected]>, Recipient ok
Tue 2012-04-17 00:02:14: <-- DATA
Tue 2012-04-17 00:02:14: Creating temp file (SMTP):
d:\mdaemon\queues\temp\md50000014121.tmp
Tue 2012-04-17 00:02:14: --> 354 Enter mail, end with <CRLF>.<CRLF>
Tue 2012-04-17 00:02:15: Message size: 1421 bytes
Tue 2012-04-17 00:02:15: Performing VBR certification (Domain: 126.com,
Auth: SPF)
Tue 2012-04-17 00:02:15: *  File: d:\mdaemon\queues\temp\md50000014121.tmp
Tue 2012-04-17 00:02:15: *  Message-ID: <4F8C507D.3B43CA.11930>
Tue 2012-04-17 00:02:15: *  Certifier (trusted): vbr.emailcertification.org
...
Tue 2012-04-17 00:02:15: *    Querying:
126.com._vouch.vbr.emailcertification.org ...
Tue 2012-04-17 00:02:16: *    Certifier does not recognize that domain
Tue 2012-04-17 00:02:16: *  Certification result: message not certified
Tue 2012-04-17 00:02:16: ---- End VBR results
Tue 2012-04-17 00:02:16: Performing DKIM lookup
Tue 2012-04-17 00:02:16: *  File: d:\mdaemon\queues\temp\md50000014121.tmp
Tue 2012-04-17 00:02:16: *  Message-ID: 4F8C507D.3B43CA.11930
Tue 2012-04-17 00:02:16: *  Result: neutral
Tue 2012-04-17 00:02:16: ---- End DKIM results
Tue 2012-04-17 00:02:16: Performing DomainKeys lookup (Sender:
[email protected])
Tue 2012-04-17 00:02:16: *  File: d:\mdaemon\queues\temp\md50000014121.tmp
Tue 2012-04-17 00:02:16: *  Message-ID: 4F8C507D.3B43CA.11930
Tue 2012-04-17 00:02:16: *  Querying for policy: 126.com
Tue 2012-04-17 00:02:16: *    Querying: _domainkey.126.com ...
Tue 2012-04-17 00:02:17: *    DNS: *  Name server has no valid records of
the requested type for that domain
Tue 2012-04-17 00:02:17: *  Result: neutral
Tue 2012-04-17 00:02:17: ---- End DomainKeys results
Tue 2012-04-17 00:02:17: Passing message through AntiVirus (Size: 1421)...
Tue 2012-04-17 00:02:17: *  Message is clean (no viruses found)
Tue 2012-04-17 00:02:17: ---- End AntiVirus results
Tue 2012-04-17 00:02:17: Message creation successful:
d:\mdaemon\queues\inbound\md50000629905.msg
Tue 2012-04-17 00:02:17: --> 250 Ok, message saved <Message-ID:
4F8C507D.3B43CA.11930>
Tue 2012-04-17 00:02:17: <-- QUIT
Tue 2012-04-17 00:02:17: --> 221 See ya in cyberspace
Tue 2012-04-17 00:02:17: SMTP session successful (Bytes in/out: 1521/426)
Tue 2012-04-17 00:02:17: ----------

Thanks
Yarohim






--[MDaemon-L]------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: <http://www.netmeister.org/news/learn2quote>
Arsip: <http://mdaemon-l.dutaint.com>
Dokumentasi : <http://mdaemon.dutaint.co.id>
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 12.5.4, SP 4.1.4, OC 2.2.9, SG 2.0.7, PP 2.0.0

Kirim email ke