Re: [mailop] too many bad IP blocked

2024-06-21 Thread Bernardo Reino via mailop
On Fri, 21 Jun 2024, Jeff Pang via mailop wrote: today I clear up iptables rules, and run fail2ban again. in half of an hour, it blocked 1400+ IPs. $ sudo iptables -L -n|grep DROP|wc -l 1407 it seems the black ips are coming endlessly. most of the bad actions are like this one:

Re: [mailop] MTA-STS errors?

2024-03-06 Thread Bernardo Reino via mailop
On Wed, 6 Mar 2024, Michael W. Lucas via mailop wrote: Hi, First time playing with MTA-STS. I have a test domain, ratoperatedvehicle.com. The mxtoolbox check says everything exists: https://mxtoolbox.com/SuperTool.aspx?action=mta-sts%3aratoperatedvehicle.com=toolpage My reports from Google

Re: [mailop] DMARC processing

2023-12-19 Thread Bernardo Reino via mailop
On Tue, 19 Dec 2023, Eduardo Diaz Comellas via mailop wrote: I'm starting to deploy DMARC records in all our managed domains, but we don't have any specific tool to parse and extract meaningful information from the reports. Do you have any recomendations? I process such reports using a

Re: [mailop] Success MiTM attack

2023-10-24 Thread Bernardo Reino via mailop
On Tue, 24 Oct 2023, Slavko via mailop wrote: Dňa 24. 10. o 4:04 Ian Kelling via mailop napísal(a): Anyone know how to monitor C-T logs? I looked around a bit and didn't see how to actually do it for let's encrypt certs. I recently installed https://github.com/SSLMate/certspotter Hard to

Re: [mailop] GitHub DMARC inbox bounces

2023-10-15 Thread Bernardo Reino via mailop
On Sun, 15 Oct 2023, Patrick Cernko via mailop wrote: Hi Marcel, hi list, On 13.10.23 12:13, Patrick Cernko via mailop wrote: Hi Marcel, hi list, On 13.10.23 10:55, Marcel Menzel via mailop wrote: sending DMARC reports to dm...@github.com stopped working for me since the 4th of October,

Re: [mailop] DMARC report rejections - was Re: Recent increase in GMail 421-4.7.28 responses

2023-10-06 Thread Bernardo Reino via mailop
On Fri, 6 Oct 2023, Gellner, Oliver via mailop wrote: On 06.10.2023 at 20:19 Bernardo Reino via mailop wrote: On Fri, 6 Oct 2023, Andrew C Aitchison via mailop wrote: I trust that you are applying RFC 7489 section 7.1. where appropriate. If the domain for dmarc reports is not the same

Re: [mailop] DMARC report rejections - was Re: Recent increase in GMail 421-4.7.28 responses

2023-10-06 Thread Bernardo Reino via mailop
Sorry for the additional noise, but I wrote "DMARC considers" where I meant "RSPAMD considers" :( On Fri, 6 Oct 2023, Bernardo Reino via mailop wrote: This is unrelated, but yes, I believe RSPAMD considers that when deciding when/whom

Re: [mailop] DMARC report rejections - was Re: Recent increase in GMail 421-4.7.28 responses

2023-10-06 Thread Bernardo Reino via mailop
On Fri, 6 Oct 2023, Andrew C Aitchison via mailop wrote: On Thu, 5 Oct 2023, Bernardo Reino via mailop wrote: On Thu, 5 Oct 2023, Slavko via mailop wrote: Dňa 2. 10. o 18:34 Brandon Long via mailop napísal(a): I've raised a bug to take a look, this looks like a too broad dkim replay

Re: [mailop] Recent increase in GMail 421-4.7.28 responses

2023-10-06 Thread Bernardo Reino via mailop
On Fri, 6 Oct 2023, Slavko via mailop wrote: Dňa 5. 10. o 9:58 Bernardo Reino via mailop napísal(a): I have the same issue. Unfortunately there's a lot of servers which request DMARC reports, but then outright reject them (or use an invalid address). My list

Re: [mailop] Recent increase in GMail 421-4.7.28 responses

2023-10-05 Thread Bernardo Reino via mailop
On Thu, 5 Oct 2023, Slavko via mailop wrote: Dňa 2. 10. o 18:34 Brandon Long via mailop napísal(a): I've raised a bug to take a look, this looks like a too broad dkim replay rule. I am not sure if that is the same, but in last two days i see these bounces from github's DMARC rua address

[mailop] DMARC reporting for gmx.ch (via gmx.net)

2022-11-16 Thread Bernardo Reino via mailop
Hello there, I've noticed that even though @gmx.ch wants DMARC reports: $ dig +short TXT _dmarc.gmx.ch "v=DMARC1; p=none; rua=mailto:dmarcrep...@gmx.net; ruf=mailto:dmarc-...@gmx.net; fo=1" they use a @gmx.net address, which requires an external reporting authorization record

Re: [mailop] Tangent: Banks and imprint requirements in Germany

2022-10-22 Thread Bernardo Reino via mailop
On Sat, 22 Oct 2022, Slavko via mailop wrote: Dňa Sat, 22 Oct 2022 11:12:28 +0200 Ralph Seichter via mailop napísal: I don't know of any German bank where this is the case. In my experience, banks are quite strict when it comes to account access; one always needs both athentication and

Re: [mailop] Update: it's not. Re: T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-21 Thread Bernardo Reino via mailop
On Fri, 21 Oct 2022, michael.zork--- via mailop wrote: [...] Here is my story: [...] I still didn't know what to do, so I asked again for details. Two emails later they still didn't tell me what the exact problem was, so I put my postal address on the website, maybe that helps. It didn't,

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-20 Thread Bernardo Reino via mailop
On Thu, 20 Oct 2022, Kai 'wusel' Siering via mailop wrote: [...] Basically "Max" states that he needed to put an "simple imprint" at http://his.do.main/index.html, which made t...@rx.t-online.de whitelist his mailserver's IP. Thus, even in December 2020 they were keen on this imprint

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-20 Thread Bernardo Reino via mailop
On 2022-10-20 14:51, Jaroslaw Rafa via mailop wrote: Dnia 19.10.2022 o godz. 20:08:30 Bernardo Reino via mailop pisze: > That seems really "interesting". How does that impressum look like, which > has the magical power of transforming a private server into a "commercia

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-20 Thread Bernardo Reino via mailop
On 2022-10-20 09:10, Dominique Rousseau via mailop wrote: Le Wed, Oct 19, 2022 at 01:33:04PM +0200, Heiko Schlittermann via mailop [mailop@mailop.org] a écrit: (...) (translation by me): Sorry, we only accept messages from proven commercial or similiar servers. Please use the SMTP relay of

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-20 Thread Bernardo Reino via mailop
On 2022-10-20 01:40, Ángel via mailop wrote: On 2022-10-19 at 21:28 +0200, Bernardo Reino via mailop wrote: Yup. I have another server for which I have to request whitelisting.. but it's a bit more difficult because the front page of the domain is the webmail (roundcube), so I have to figure

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-20 Thread Bernardo Reino via mailop
On 2022-10-20 08:48, Florian Effenberger via mailop wrote: Hello, I actually ran into a similar problem last year after a mail server migration. Here's what I documented back then in my blog: "Deutsche Telekom, respectively T-Online, by default blocks IP addresses that haven’t been used for

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On Wed, 19 Oct 2022, Kai 'wusel' Siering via mailop wrote: Am 19.10.22 um 21:28 schrieb Bernardo Reino via mailop: On Wed, 19 Oct 2022, Renaud Allard via mailop wrote: If you try deleting the impressum, please share your experience on what happens with t-online. Yup. I have another

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On Wed, 19 Oct 2022, Kai 'wusel' Siering via mailop wrote: Which OTOH means that Deutsche Telekom is still whitelisting mailservers that comply with their request to be able to identify the other side. And which means that the subject is false, nothing has basically changed besides the

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On Wed, 19 Oct 2022, Renaud Allard via mailop wrote: On 10/19/22 20:08, Bernardo Reino via mailop wrote: I wonder what happens if I delete the "Impressum" in a few days, but who knows, maybe they do add some monitoring for *that* ¯\_(ツ)_/¯ If you try deleting the impressum, pl

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On Wed, 19 Oct 2022, Kirill Miazine via mailop wrote: • Bernardo Reino via mailop [2022-10-19 14:51]: On 2022-10-19 14:25, Stefano Bagnara via mailop wrote: On Wed, 19 Oct 2022 at 13:32, Heiko Schlittermann via mailop wrote: A given mailhost (ran privately for smaller entities) can't send

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On Wed, 19 Oct 2022, Jaroslaw Rafa via mailop wrote: Dnia 19.10.2022 o godz. 18:56:17 Bernardo Reino via mailop pisze: After I contacted them they told me that they only accept e-mail from commercial servers, so in my case (private/family server) I would have to add an "Impr

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On 19/10/2022 17:16, Renaud Allard via mailop wrote: On 10/19/22 16:10, Kai 'wusel' Siering via mailop wrote: On 19.10.22 15:55, Renaud Allard via mailop wrote: They blocked at least my non commercial mail server until I added an impressum. So, I guess they now block everyone without an

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On 2022-10-19 14:25, Stefano Bagnara via mailop wrote: On Wed, 19 Oct 2022 at 13:32, Heiko Schlittermann via mailop wrote: A given mailhost (ran privately for smaller entities) can't send messages to T-Online anymore. 554 IP=168.119.159.241 - A problem occurred. … Do you get this error at

Re: [mailop] T-Online is now really blocking messages from non-commercial and simliar senders

2022-10-19 Thread Bernardo Reino via mailop
On 2022-10-19 13:33, Heiko Schlittermann via mailop wrote: Hello, I'm not sure how to complain and where. But I hope that here we can start a discussion again. I'm quite upset. Is this the new world? A given mailhost (ran privately for smaller entities) can't send messages to T-Online

Re: [mailop] Odd DNS-cache avoidance queries (Spam Assassin / Unbound / AWS)

2022-09-13 Thread Bernardo Reino via mailop
On 13/09/2022 07:55, Cyril - ImprovMX via mailop wrote: Hi everyone! > [...] > Here's the Unbound configuration: https://pastebin.com/Bn7B3uCv (expires in a month). > [...] > 1. The first issue is that it seems that we are querying URIBL using random lower/upper case domains. We had

Re: [mailop] Talking DOXING of spammers on this mailing list..

2022-06-02 Thread Bernardo Reino via mailop
On Wed, 1 Jun 2022, Anne Mitchell via mailop wrote: I *really* want to see the original email to which MDR is replying, however, ironically, our default install of rspamd rejected it (which is saying a lot because to be rejected by the default install you have to amass 15 points or more...).

Re: [mailop] Contact at Contabo?

2022-05-31 Thread Bernardo Reino via mailop
On 31/05/2022 07:26, Hans-Martin Mosner via mailop wrote: Hello, does anybody have a working contact at Contabo? Mail to abuse@ does not seem to have an effect. Cheers, Hans-Martin I would try with supp...@contabo.com (and/or supp...@contabo.de) I'm a Contabo customer, but before that I

Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-05-05 Thread Bernardo Reino via mailop
On Thu, 5 May 2022, Alessandro Vesely via mailop wrote: On Fri 29/Apr/2022 18:24:04 +0200 Bernardo Reino wrote: On Fri, 29 Apr 2022, Tobias Fiebig via mailop wrote: This might be a bit of a theoretical attack thing, but looking over the bounces for my nightly outbound DMARC reports I

Re: [mailop] DMARC/TLSRPT to non-existing accounts/reflection and sender reputation

2022-04-29 Thread Bernardo Reino via mailop
On Fri, 29 Apr 2022, Tobias Fiebig via mailop wrote: Heho, This might be a bit of a theoretical attack thing, but looking over the bounces for my nightly outbound DMARC reports I actually started to wonder about this; (Mostly because I am getting scared by regularly sending DMARC reports to non

Re: [mailop] Anyone from BNETZA.DE ?

2022-03-30 Thread Bernardo Reino via mailop
On Tue, 29 Mar 2022, Glowfish Domainadministrator via mailop wrote: Even when I try to telnet the servers from a totally different network I get a connection refused: telnet 194.156.223.27 25 Trying 194.156.223.27... Connected to 194.156.223.27. Escape character is '^]'. 554 5.7.1 SMTP

Re: [mailop] IPv6 reverse DNS from office365

2022-02-10 Thread Bernardo Reino via mailop
On Thu, 10 Feb 2022, Tim Bray via mailop wrote: Hi, Is anybody else having trouble relaying email out of office365. I think they have broken their reverse DNS. Our method to trust *.outbound.protection.outlook.com 2022-02-10 09:51:46 H=(GBR01-LO2-obe.outbound.protection.outlook.com)

Re: [mailop] Google considers DMARC reports to be unsolicited mail :(

2022-02-09 Thread Bernardo Reino via mailop
On Wed, 9 Feb 2022, Patrick Ben Koetter via mailop wrote: * Bernardo Reino via mailop : Dear all, I have already experienced Google ratelimiting DMARC reports every now and then, which may be OK if they want it like that.. but this is new (to me): [snip] Diagnostic-Code: smtp; 550-5.7.1

[mailop] Google considers DMARC reports to be unsolicited mail :(

2022-02-08 Thread Bernardo Reino via mailop
Dear all, I have already experienced Google ratelimiting DMARC reports every now and then, which may be OK if they want it like that.. but this is new (to me): Reporting-MTA: dns; katara.bbmk.org X-Postfix-Queue-ID: 3D2D71BE02E2 X-Postfix-Sender: rfc822; rep...@dmarc.bbmk.org Arrival-Date:

Re: [mailop] Google not sending DMARC Aggregate Reports

2021-10-09 Thread Bernardo Reino via mailop
Hello, On Fri, 8 Oct 2021, Al Iverson via mailop wrote: You're not alone. Both Google's DMARC reports and Google Postmaster Tools updates stopped, last update / last notification sent seems to be around October 3rd. I blogged about this just a few hours ago:

Re: [mailop] Gmail putting messages to spam

2021-09-22 Thread Bernardo Reino via mailop
On Tue, 21 Sep 2021, Jaroslaw Rafa via mailop wrote: Dnia 20.09.2021 o godz. 14:17:27 Jaroslaw Rafa via mailop pisze: I want to return to an old issue, which repeatedly happens again and again, that is, Google putting emails from me to recipient's spam folder. What's absurd, this happens not

Re: [mailop] Low Volume Senders

2021-09-20 Thread Bernardo Reino via mailop
On Mon, 20 Sep 2021, Brielle via mailop wrote: On Sep 20, 2021, at 9:05 AM, Florian Effenberger via mailop wrote: seems rspamd supports this: https://rspamd.com/doc/modules/dmarc.html (see "Reporting" section). Didn't try it myself though, I don't send reports yet. Hah, that makes it easy

Re: [mailop] UCEPROTECT and Gmail (was Re: When RBLs go bad)

2021-02-16 Thread Bernardo Reino via mailop
On Tue, 16 Feb 2021, Vittorio Bertola via mailop wrote: Il 14/02/2021 07:42 André Peters via mailop ha scritto: Hi, Have you guys already read this? https://blog.sucuri.net/2021/02/uceprotect-when-rbls-go-bad.html I have seen the discussion and found it fits. Will you

Re: [mailop] t-online.de outage?

2020-06-10 Thread Bernardo Reino via mailop
On Wed, 10 Jun 2020, Ralph Seichter via mailop wrote: * Hetzner Blacklist via mailop: For the past few years, T-Online have been moving to a system where they block all unknown IPs. [...] This statement matches what I experienced. Freshly installed mail servers (with matching SPF entries)

Re: [mailop] mail.com rep on the list?

2020-01-28 Thread Bernardo Reino via mailop
Hello, On Tue, 28 Jan 2020, Kenneth Vedder via mailop wrote: Was wondering if there was anyone representing mail.com on the list. It appears that I've been blacklisted and can't get a response from the usual channels. The error you show below is from gmx and not from mail.com (?) (host