On 12/30/2013 2:20 PM, Syafril Hermansyah wrote:
Dinon aktifkan saja HELO delay check, useless untuk jaman broadband
sekarang ini.
http://mdaemon.dutaint.co.id/13.6.1/security--tarpit_settings.htm
SMTP EHLO/HELO delay = 0
[ ] Authenticated IPs experience a single EHLO/HELO delay per day
BTW. Sepertinya ada tcp filtering yang aktif sehingga semua lognya ada
penanda angka dibelakang date stamp.
TCP filtering bisa berupa filter di firewall atau antivirus (diluar
securityplus).
Pak Syafril,
Ternyata lama-kelamaan queuenya tinggi lagi, bahkan hold di inbound
queue. berikut lognya :
Mon 2013-12-30 14:56:33: 01: ----------
Mon 2013-12-30 14:55:44: 05: Session 431797; child 0041
Mon 2013-12-30 14:55:44: 05: Accepting SMTP connection from
[106.10.149.85:31339] to [172.16.84.16:25]
Mon 2013-12-30 14:55:44: 03: --> 220 mail.ocbcnisp.com ESMTP MDaemon
13.6.0; Mon, 30 Dec 2013 14:55:44 +0700
Mon 2013-12-30 14:55:44: 02: <-- HELO nm17-vm6.bullet.mail.sg3.yahoo.com
Mon 2013-12-30 14:55:44: 03: --> 250 mail.ocbcnisp.com Hello
nm17-vm6.bullet.mail.sg3.yahoo.com, pleased to meet you
Mon 2013-12-30 14:55:44: 02: <-- MAIL FROM:<[email protected]>
Mon 2013-12-30 14:55:44: 05: Performing PTR lookup
(85.149.10.106.IN-ADDR.ARPA)
Mon 2013-12-30 14:55:44: 05: * D=85.149.10.106.IN-ADDR.ARPA TTL=(21)
PTR=[nm17-vm6.bullet.mail.sg3.yahoo.com]
Mon 2013-12-30 14:55:44: 05: * Gathering A records...
Mon 2013-12-30 14:55:44: 05: * D=nm17-vm6.bullet.mail.sg3.yahoo.com
TTL=(27) A=[106.10.149.85]
Mon 2013-12-30 14:55:44: 05: ---- End PTR results
Mon 2013-12-30 14:55:44: 05: Performing IP lookup
(nm17-vm6.bullet.mail.sg3.yahoo.com)
Mon 2013-12-30 14:55:44: 05: * D=nm17-vm6.bullet.mail.sg3.yahoo.com
TTL=(27) A=[106.10.149.85]
Mon 2013-12-30 14:55:44: 05: ---- End IP lookup results
Mon 2013-12-30 14:55:44: 05: Performing IP lookup (yahoo.com)
Mon 2013-12-30 14:55:44: 05: * D=yahoo.com TTL=(26) A=[98.139.183.24]
Mon 2013-12-30 14:55:44: 05: * D=yahoo.com TTL=(26) A=[206.190.36.45]
Mon 2013-12-30 14:55:44: 05: * D=yahoo.com TTL=(26) A=[98.138.253.109]
Mon 2013-12-30 14:55:44: 05: * P=001 S=000 D=yahoo.com TTL=(16)
MX=[mta7.am0.yahoodns.net]
Mon 2013-12-30 14:55:44: 05: * P=001 S=001 D=yahoo.com TTL=(16)
MX=[mta6.am0.yahoodns.net]
Mon 2013-12-30 14:55:44: 05: * P=001 S=002 D=yahoo.com TTL=(16)
MX=[mta5.am0.yahoodns.net]
Mon 2013-12-30 14:55:44: 05: * D=yahoo.com TTL=(26) A=[98.138.253.109]
Mon 2013-12-30 14:55:44: 05: * D=yahoo.com TTL=(26) A=[206.190.36.45]
Mon 2013-12-30 14:55:44: 05: * D=yahoo.com TTL=(26) A=[98.139.183.24]
Mon 2013-12-30 14:55:44: 05: ---- End IP lookup results
Mon 2013-12-30 14:55:44: 09: Performing SPF lookup (yahoo.com /
106.10.149.85)
Mon 2013-12-30 14:55:44: 09: * Result: none; no SPF record in DNS
Mon 2013-12-30 14:55:44: 09: ---- End SPF results
Mon 2013-12-30 14:55:44: 03: --> 250 <[email protected]>, Sender ok
Mon 2013-12-30 14:55:45: 02: <-- RCPT TO:<[email protected]>
Mon 2013-12-30 14:55:45: 05: Performing DNS-BL lookup (106.10.149.85 -
connecting IP)
Mon 2013-12-30 14:55:45: 05: * zen.spamhaus.org - passed
Mon 2013-12-30 14:55:45: 05: ---- End DNS-BL results
Mon 2013-12-30 14:55:45: 03: --> 250 <[email protected]>,
Recipient ok
Mon 2013-12-30 14:55:45: 02: <-- DATA
Mon 2013-12-30 14:55:45: 01: Creating temp file (SMTP):
g:\mdaemon\queues\temp\md50000252115.tmp
Mon 2013-12-30 14:55:45: 03: --> 354 Enter mail, end with <CRLF>.<CRLF>
Mon 2013-12-30 14:55:46: 01: Message size: 15179 bytes
Mon 2013-12-30 14:55:46: 10: Performing DKIM lookup
Mon 2013-12-30 14:55:46: 10: * File:
g:\mdaemon\queues\temp\md50000252115.tmp
Mon 2013-12-30 14:55:46: 10: * Message-ID:
[email protected]
Mon 2013-12-30 14:55:46: 10: * Signature (1):
;v=1;a=rsa-sha256;c=relaxed/relaxed;d=yahoo.com;s=s1024;t=1388390659;b
h=<not logged>;
Mon 2013-12-30 14:55:46: 10: * Verification result: [0] good
Mon 2013-12-30 14:55:46: 10: * Result: pass
Mon 2013-12-30 14:55:46: 10: ---- End DKIM results
Mon 2013-12-30 14:55:46: 08: Performing VBR certification (Domain:
yahoo.com, Auth: DKIM)
Mon 2013-12-30 14:55:46: 08: * File:
g:\mdaemon\queues\temp\md50000252115.tmp
Mon 2013-12-30 14:55:46: 08: * Message-ID:
[email protected]
Mon 2013-12-30 14:55:46: 08: * Certifier (trusted):
vbr.emailcertification.org ...
Mon 2013-12-30 14:55:46: 08: * Querying:
yahoo.com._vouch.vbr.emailcertification.org ...
Mon 2013-12-30 14:55:46: 08: * Certifier does not recognize that domain
Mon 2013-12-30 14:55:46: 08: * Certification result: message not certified
Mon 2013-12-30 14:55:46: 08: ---- End VBR results
Mon 2013-12-30 14:55:46: 06: Passing message through AntiVirus (Size:
15179)...
Mon 2013-12-30 14:55:46: 06: * Message is clean (no viruses found)
Mon 2013-12-30 14:55:46: 06: ---- End AntiVirus results
Mon 2013-12-30 14:55:46: 07: Passing message through Spam Filter (Size:
15179)...
Mon 2013-12-30 14:56:32: 07: g:\mdaemon\queues\temp\md50000252115.tmp
Mon 2013-12-30 14:56:32: 04: An error occured during Spam Filter processing
Mon 2013-12-30 14:56:32: 01: Message creation successful:
g:\mdaemon\queues\inbound\md50001517917.msg
Mon 2013-12-30 14:56:32: 03: --> 250 Ok, message saved <Message-ID:
<[email protected]>>
Mon 2013-12-30 14:56:33: 02: <-- QUIT
Mon 2013-12-30 14:56:33: 03: --> 221 See ya in cyberspace
Mon 2013-12-30 14:56:33: 01: SMTP session successful (Bytes in/out:
15306/411)
Mon 2013-12-30 14:56:33: 01: ----------
--
Salam,
Yugi Trianto Purba
Data Center Management Unit
Central Operation Technology Division
PT. Bank OCBC NISP, Tbk
--
--[MDaemon-L]------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.
Netiket: http://www.netmeister.org/news/learn2quote
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 13.6.1, SP 4.1.5, BES 2.0.2, OC 2.3.3, SG 2.1.2, PP 2.0.1