Hi Ken > If you're wholesaling then aren't you segmenting your sending IP > ranges on a per customer basis to identify ISPs with low quality > customers?
Yes, we do (postfix regex transport rules mapping customer domains to outgoing server(IP) instances). In this case our 'catch all' IP's for sender domains without specific domain to ip binding had bad reputation. In contact with cloudmark I think we were able to pinpoint the problem. One of our wholesale customer recently got acquired by another ISP and all mailboxes were migrated to that ISP's email service. To ensure a smooth transition I configured our platform as a relay for the affected domain so DNS resolvers who were slow in picking up the MX change, would not cause those emails to be rejected by our servers. Unfortunately it looks like especial spam bots are slow in picking up the right DNS (or even use hardcoded MX settings per target domain, as that migration was 3 weeks ago and we set the DNS MX TTL to 300 well in advance). So we started getting and relaying mostly spam to the new MX of that domain, some of which didn't get rejected by our filters (also doing forward lookup to ensure the recipient exists before accepting email). That was agreed with, with the new ISP for that domain, also to ensure he would not SPF check emails forwarded by our servers etc. What still is a mystery, is how this caused us to get a bad reputation. Maybe ex. customers reporting emails they got via our relay to cloudmark? Maybe that hoster re-using mailboxes as cloudmark spamtraps after customers deleted them right after the migration? Cloudmark will mark the affected IP's as trusted relays, so hopefully this will solve the issue. Any I will also probably remove the affected domain from the allowed relay domains quite soon :-) -BenoƮt Panizzon- -- I m p r o W a r e A G - Leiter Commerce Kunden ______________________________________________________ Zurlindenstrasse 29 Tel +41 61 826 93 00 CH-4133 Pratteln Fax +41 61 826 93 01 Schweiz Web http://www.imp.ch ______________________________________________________ _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
