Print Page | Close Window

Unstable last 24hours

Printed From: LogSat Software
Category: Spam Filter ISP
Forum Name: Spam Filter ISP Support
Forum Description: General support for Spam Filter ISP
URL: https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6762
Printed Date: 05 February 2025 at 12:05pm


Topic: Unstable last 24hours
Posted By: morten44
Subject: Unstable last 24hours
Date Posted: 15 October 2009 at 5:03pm
Hi
We have had quite a number of complaint the last 24 hour on mails that does not arrive.
I have had a look through the log files but as I am not an expert, I am not sure what to look for. I have stopped using quarantene database in mysql due to some problems. since I did that , it has been running fine for about 1 month now
 
 
The only strange thing I can see from the log is this:
 
10-15-09 00:55:45:171 -- (2384) TBayesianThread - LoadFromFile for Corpus.db - copied db.dat -> IndACA.tmp
10-15-09 00:55:45:171 -- (2384) TBayesianThread - LoadFromFile for Corpus.db - copied db.dat.prb -> IndACB.tmp
10-15-09 00:55:45:281 -- (2384) TBayesianThread - corpus.db copy of files not exist - exiting
10-15-09 00:55:45:281 -- (2384) TBayesianThread - End LoadFromFile for corpus.db (db.dat) (0)
10-15-09 00:55:45:281 -- (2384) SpamFilterForm - corpus.db cannot be loaded, waiting 60 seconds
10-15-09 00:55:45:312 -- (2288) TSpamFilterForm - LoadFromFile for Corpus.db - copied db.dat -> IndACE.tmp
10-15-09 00:55:45:312 -- (2288) TSpamFilterForm - LoadFromFile for Corpus.db - copied db.dat.prb -> IndACF.tmp
---------------------------------------------------------------------------------------------------------
 
is this important?
Can I upload the log file over 3 days to your FTP Server and do you mind to have a look at it?
 
Hoping to hear from you soon
Kind Regards
Morten



Replies:
Posted By: LogSat
Date Posted: 16 October 2009 at 5:35am
Morten,

Those errors from the Corpus.db are actually quite common and not a cause of concern. If you wish to upload the logfiles we'll gladly go over them. Please let us know when they're ready and also please indicate, if possible, a few to/from email addresses that were affected by this so we can try to locate the emails in the logs.


-------------
Roberto Franceschetti

http://www.logsat.com" rel="nofollow - LogSat Software

http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP


Posted By: morten44
Date Posted: 16 October 2009 at 2:37pm
Hi
Thanks alot
I have uploadet 3 days to your ftp
20091013.zip
20091014.zip
20091015.zip

The reports on mails not arriving started the 14th am.
My co administrator tried to send and receive the same time and it seemd to work, so we thought it was a local thing for the end user.
But more and more people started to complain
one of them was mailto:jdw@humana-spain.org - jdw@humana-spain.org  and about 10 more that contacted us.
 
Without beeing able to replicate the fault, at about 1400 sometime (DK time), My co administrator restarted the server and then it seemed like a lot of mail that should have been delivered earlier in the day suddenly started to arrive.
We dont think any mails are lost and I think ISP spamfilter works as it should as they where delayed.
We just want to find out why it stopped and why after a restart at about 1400 it started to deliver again.
 
Hope you can see something from the log files
 
Kind Regards
Morten


Posted By: LogSat
Date Posted: 17 October 2009 at 12:42pm
Morten,

SpamFilter logs the time using the local server's time, but we only saw one time that SpamFilter was restarted, it was at 20:38 on the 14th:

10-14-09 20:38:40:828 -- SpamFilter ISP v4.0.1.783 Listening on all IPs port 25

Going thru the logs, we did not see anything that stood out, and traffic seems normal both before and after the above restart. We're not able to locate the specific emails in question, as we needed both the to/from email addresses to locate those emails in the logs. Here's a sample of emails that we see on the 14th for that address. Most were being blocked as the sender's IP was blacklisted. One (the last sample) was delivered instead successfully, even though it looks like it was a piece of spam that slipped thru the various filters.
If you can provide us with more information, specifically both the sender's email and the recipient's email addresses, we can try to do more specific debugging.

10-14-09 00:29:22:875 -- (4160) Connection from: 79.44.115.67  -  Originating country : Italy
10-14-09 00:29:25:578 -- (4160) Received MAIL FROM: <jdw@humana-spain.org>
10-14-09 00:29:25:656 -- (4160) Received RCPT TO: jdw@humana-spain.org
10-14-09 00:29:25:656 -- (4160) - SPF analysis for humana-spain.org done: - none
10-14-09 00:29:25:656 -- (4160) Mail from: jdw@humana-spain.org
10-14-09 00:29:25:921 -- (4160) - MAPS search done... 521 The IP 79.44.115.67 is Blacklisted by bl.spamcop.net. Blocked - see http://www.spamcop.net/bl.shtml?79.44.115.67 -- 521 The IP 79.44.115.67 is Blacklisted by sbl-xbl.spamhaus.org. http://www.spamhaus.org/query/bl?ip=79.44.115.67 -- 
10-14-09 00:29:25:921 -- (4160) 79.44.115.67 - Mail from: jdw@humana-spain.org To: jdw@humana-spain.org will be rejected


10-14-09 00:35:07:843 -- (2272) Connection from: 173.78.94.126  -  Originating country : N/A
10-14-09 00:35:08:625 -- (2272) Received MAIL FROM: <jdw@humana-spain.org>
10-14-09 00:35:08:812 -- (2272) Received RCPT TO: jdw@humana-spain.org
10-14-09 00:35:08:812 -- (2272) - SPF analysis for humana-spain.org done: - none
10-14-09 00:35:08:812 -- (2272) Mail from: jdw@humana-spain.org
10-14-09 00:35:09:171 -- (2272) - MAPS search done... 521 The IP 173.78.94.126 is Blacklisted by bl.spamcop.net. Blocked - see http://www.spamcop.net/bl.shtml?173.78.94.126 -- 521 The IP 173.78.94.126 is Blacklisted by sbl-xbl.spamhaus.org. http://www.spamhaus.org/query/bl?ip=173.78.94.126 -- 
10-14-09 00:35:09:171 -- (2272) 173.78.94.126 - Mail from: jdw@humana-spain.org To: jdw@humana-spain.org will be rejected


10-14-09 01:29:42:140 -- (4064) Connection from: 190.97.131.82  -  Originating country : Colombia
10-14-09 01:29:43:046 -- (4064) Received MAIL FROM: <jdw@humana-spain.org>
10-14-09 01:29:43:281 -- (4064) Received RCPT TO: jdw@humana-spain.org
10-14-09 01:29:43:281 -- (4064) - SPF analysis for humana-spain.org done: - none
10-14-09 01:29:43:281 -- (4064) Mail from: jdw@humana-spain.org
10-14-09 01:29:43:437 -- (4064) - MAPS search done... 521 The IP 190.97.131.82 is Blacklisted by bl.spamcop.net. Blocked - see http://www.spamcop.net/bl.shtml?190.97.131.82 -- 521 The IP 190.97.131.82 is Blacklisted by sbl-xbl.spamhaus.org. http://www.spamhaus.org/query/bl?ip=190.97.131.82 -- 
10-14-09 01:29:43:437 -- (4064) 190.97.131.82 - Mail from: jdw@humana-spain.org To: jdw@humana-spain.org will be rejected


10-14-09 07:45:35:703 -- (4492) Connection from: 189.75.245.180  -  Originating country : Brazil
10-14-09 07:45:36:765 -- (4492) Received MAIL FROM: <jdw@humana-spain.org>
10-14-09 07:45:37:046 -- (4492) Received RCPT TO: jdw@humana-spain.org
10-14-09 07:45:37:046 -- (4492) - SPF analysis for humana-spain.org done: - none
10-14-09 07:45:37:046 -- (4492) Mail from: jdw@humana-spain.org
10-14-09 07:45:37:265 -- (4492) - MAPS search done... 521 The IP 189.75.245.180 is Blacklisted by bl.spamcop.net. Blocked - see http://www.spamcop.net/bl.shtml?189.75.245.180 -- 521 The IP 189.75.245.180 is Blacklisted by sbl-xbl.spamhaus.org. http://www.spamhaus.org/query/bl?ip=189.75.245.180 -- 
10-14-09 07:45:37:265 -- (4492) 189.75.245.180 - Mail from: jdw@humana-spain.org To: jdw@humana-spain.org will be rejected


10-14-09 05:08:59:593 -- (5472) Connection from: 189.18.154.250  -  Originating country : Brazil
10-14-09 05:09:00:812 -- (5472) Received MAIL FROM: <jdw@humana-spain.org>
10-14-09 05:09:01:156 -- (5472) Received RCPT TO: jdw@humana-spain.org
10-14-09 05:09:01:156 -- (5472) - SPF analysis for humana-spain.org done: - none
10-14-09 05:09:01:156 -- (5472) Mail from: jdw@humana-spain.org
10-14-09 05:09:01:609 -- (5472) - MAPS search done... 
10-14-09 05:09:01:609 -- (5472) RCPT TO: jdw@humana-spain.org accepted
10-14-09 05:09:02:734 -- (5472) Checking SURBL
10-14-09 05:09:02:750 -- (5472) Starting queueing procedures
10-14-09 05:09:02:765 -- (5472) EMail from jdw@humana-spain.org to jdw@humana-spain.org was queued. Size: 4 KB, 4096 bytes
10-14-09 05:09:03:078 -- (4264) EMail from jdw@humana-spain.org to jdw@humana-spain.org --  was forwarded to 172.18.0.16:2225




-------------
Roberto Franceschetti

http://www.logsat.com" rel="nofollow - LogSat Software

http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP


Posted By: morten44
Date Posted: 17 October 2009 at 1:56pm
Hi Thanks for your help looking through it all.
I am happy to see that every thing looks right
 
The mails in question are obviously spam
received and sender with same address...
mailto:jdw@humana-spain.org - jdw@humana-spain.org
 
We have a lot of mails like this. As this are spam and we actually have this address and domain on our webserver, can this cause that the domain get blocked and therefore affect our real mail trafic, or will it only affect the IP that it was sent from that is the spammers?
 
Kind Regards
Morten



Print Page | Close Window