Hi,
i have read the threads regarding the MX record and DNS issues, but still don't understand this. I have pasted below extract from the log and message headers. the second log extract shows exactly the same behaviour but from a different host.
The email is being sent from @za.verizonbusiness.com which has valid MX records. Why does logsat report that the email is from "EMail from mailto:dnsar@mx01.uunet.co.za - dnsar@mx01.uunet.co.za " (4th line on the log), and why is it considered to be spam?
The options "reject if no reverse dns" and "reject if sender domain has invalid MX record" are selected.
Surely the "reject if sender domain has no invalid mx record" isn't true here, as is evident from a nslookup for za.verizonbusiness.com.
the most peculiar thing here is the return-path, where does this value come from, and why is spamfilter checking against this value as opposed to the sender value?
Thanks for your assistance
Amir
Here are extracts from the logfile:
06/13/06 09:57:30:375 -- (2700) Connection from: 196.31.48.143 - Originating country : South Africa 06/13/06 09:57:30:578 -- (2700) Resolving 196.31.48.143 - mx01.uunet.co.za 06/13/06 09:57:30:640 -- (2700) - Invalid MX record - 06/13/06 09:57:30:640 -- (2700) 196.31.48.143 - Mail from: mailto:dnsar@mx01.uunet.co.za - dnsar@mx01.uunet.co.za To: julian@???????.??? will be spam-tagged 06/13/06 09:57:30:703 -- (2700) EMail from mailto:dnsar@mx01.uunet.co.za - dnsar@mx01.uunet.co.za to julian@?????????.??? was queued. Size: 1 KB, 1024 bytes 06/13/06 09:57:30:703 -- (2108) Sending email from mailto:dns-admin@za.verizonbusiness.com - dns-admin@za.verizonbusiness.com to julian@????????.??? 06/13/06 09:57:30:750 -- (1932) Time to add Msg to Bayes corpus:0 06/13/06 09:57:30:781 -- (2700) Blacklist cache - Added 196.31.48.143 to limbo 06/13/06 09:57:30:781 -- (2700) Disconnect 06/13/06 09:57:32:375 -- (2108) EMail from mailto:dns-admin@za.verizonbusiness.com - dns-admin@za.verizonbusiness.com to julian@??????????.??? was forwarded to 000.00.00.00:25
06/13/06 09:59:56:546 -- (2300) Connection from: 206.223.136.195 - Originating country : South Africa 06/13/06 09:59:56:781 -- (2300) Resolving 206.223.136.195 - ns0.coza.net.za 06/13/06 09:59:56:828 -- (2300) - Invalid MX record - 06/13/06 09:59:56:828 -- (2300) 206.223.136.195 - Mail from: mailto:coza@ns0.coza.net.za - coza@ns0.coza.net.za To: xxxxx@???????.??? will be spam-tagged 06/13/06 09:59:56:875 -- (2300) - Invalid MX record - 06/13/06 09:59:56:875 -- (2300) 206.223.136.195 - Mail from: mailto:coza@ns0.coza.net.za - coza@ns0.coza.net.za To: xxxxxx@???????.??? will be spam-tagged 06/13/06 09:59:57:078 -- (2300) EMail from mailto:coza@ns0.coza.net.za - coza@ns0.coza.net.za to xxxxxxx@?????????.???, xxxxx@?????????.??? was queued. Size: 2 KB, 2048 bytes 06/13/06 09:59:57:078 -- (2188) Sending email from mailto:ticketman@co.za - ticketman@co.za to xxxxxx@????????.???, xxx@?????????.??? 06/13/06 09:59:57:125 -- (1932) Time to add Msg to Bayes corpus:0 06/13/06 09:59:58:859 -- (2188) EMail from mailto:ticketman@co.za - ticketman@co.za to xxxxxx@????????.???, xxx@?????????.??? was forwarded to 000.00.00.00:25 06/13/06 10:00:01:203 -- (2300) Blacklist cache - Added 206.223.136.195 to limbo 06/13/06 10:00:01:203 -- (2300) Disconnect
The message headers are:
Reply-To: "Verizon Business DNS Team" < mailto:dns-admin@za.verizonbusiness.com - dns-admin@za.verizonbusiness.com > From: "Verizon Business DNS Team" < mailto:dns-admin@za.verizonbusiness.com - dns-admin@za.verizonbusiness.com > To: <julian@????????????> Subject: {SPAMF} Your message to mailto:dns-admin@za.verizonbusiness.com - dns-admin@za.verizonbusiness.com Date: Tue, 13 Jun 2006 09:56:30 +0200 Message-ID: < mailto:200606130756.k5D7uUFK079027@mx01.uunet.co.za - 200606130756.k5D7uUFK079027@mx01.uunet.co.za > MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Mailer: Microsoft Office Outlook, Build 11.0.6353 Thread-Index: AcaOvtQZhSIvggmbQ2alW7MHQ9gE+Q== X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180 X-Server: LogSat Software SMTP Server - Unlicensed Evaluation Copy X-SF-RX-Return-Path: < mailto:dnsar@mx01.uunet.co.za - dnsar@mx01.uunet.co.za > SIZE=2594 X-SF-HELO-Domain: mx01.uunet.co.za X-SF-SPAM: Y
* This is an automated response *
Thank you for contacting the Verizon Business Customer Service Centre.
This auto-response confirms that we have received your DNS query.
|