> That looks wrong. Where is the first EHLO response line? The above
> starts in the middle of the response.
>
> Can you share a packed dump OFF-LIST so I can see what happens between
> SENDING ehlo and receiving the reply? The entire TCP connection would
> be best.
Yes, I extracted only the interesting part. The full dump is here (server with
IP X.X.X.X is mine. Server with IP Y.Y.Y.Y is remote MX):
1 0.000000 X.X.X.X -> Y.Y.Y.Y TCP 74 64550 → 25 [SYN] Seq=0 Win=29200 Len=0
MSS=1460 SACK_PERM=1 TSval=1363265141 TSecr=0 WS=128
0000 00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00 .PV.0X.PV.d...E.
0010 00 3c 76 fb 40 00 40 06 9a fb ac 11 19 23 d5 29 .<v.@.@......#.)
0020 8e 67 fc 26 00 19 8b 00 b0 8e 00 00 00 00 a0 02 .g.&............
0030 72 10 28 f4 00 00 02 04 05 b4 04 02 08 0a 51 41 r.(...........QA
0040 c6 75 00 00 00 00 01 03 03 07 .u........
2 0.030649 Y.Y.Y.Y -> X.X.X.X TCP 74 25 → 64550 [SYN, ACK] Seq=0 Ack=1
Win=65535 Len=0 MSS=1300 WS=64 SACK_PERM=1 TSval=2347446220 TSecr=1363265141
0000 00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00 .PV.d..PV.0X..E.
0010 00 3c 1e d3 40 00 37 06 fc 23 d5 29 8e 67 ac 11 .<[email protected]..#.).g..
0020 19 23 00 19 fc 26 f3 55 0e 44 8b 00 b0 8f a0 12 .#...&.U.D......
0030 ff ff 12 f3 00 00 02 04 05 14 01 03 03 06 04 02 ................
0040 08 0a 8b eb 2f cc 51 41 c6 75 ..../.QA.u
3 0.030695 X.X.X.X -> Y.Y.Y.Y TCP 66 64550 → 25 [ACK] Seq=1 Ack=1 Win=29312
Len=0 TSval=1363265148 TSecr=2347446220
0000 00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00 .PV.0X.PV.d...E.
0010 00 34 76 fc 40 00 40 06 9b 02 ac 11 19 23 d5 29 .4v.@.@......#.)
0020 8e 67 fc 26 00 19 8b 00 b0 8f f3 55 0e 45 80 10 .g.&.......U.E..
0030 00 e5 28 ec 00 00 01 01 08 0a 51 41 c6 7c 8b eb ..(.......QA.|..
0040 2f cc /.
4 0.063290 Y.Y.Y.Y -> X.X.X.X SMTP 84 S: 220 SMTP Welcome
0000 00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00 .PV.d..PV.0X..E.
0010 00 46 1e d7 40 00 37 06 fc 15 d5 29 8e 67 ac 11 [email protected]....).g..
0020 19 23 00 19 fc 26 f3 55 0e 45 8b 00 b0 8f 80 18 .#...&.U.E......
0030 04 02 cf 47 00 00 01 01 08 0a 8b eb 2f ed 51 41 ...G......../.QA
0040 c6 7c 32 32 30 20 53 4d 54 50 20 57 65 6c 63 6f .|220 SMTP Welco
0050 6d 65 0d 0a me..
5 0.063310 X.X.X.X -> Y.Y.Y.Y TCP 66 64550 → 25 [ACK] Seq=1 Ack=19
Win=29312 Len=0 TSval=1363265156 TSecr=2347446253
0000 00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00 .PV.0X.PV.d...E.
0010 00 34 76 fd 40 00 40 06 9b 01 ac 11 19 23 d5 29 .4v.@.@......#.)
0020 8e 67 fc 26 00 19 8b 00 b0 8f f3 55 0e 57 80 10 .g.&.......U.W..
0030 00 e5 28 ec 00 00 01 01 08 0a 51 41 c6 84 8b eb ..(.......QA....
0040 2f ed /.
6 0.063357 X.X.X.X -> Y.Y.Y.Y SMTP 102 C: EHLO mx02-out.cloud.vadesecure.com
0000 00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00 .PV.0X.PV.d...E.
0010 00 58 76 fe 40 00 40 06 9a dc ac 11 19 23 d5 29 .Xv.@.@......#.)
0020 8e 67 fc 26 00 19 8b 00 b0 8f f3 55 0e 57 80 18 .g.&.......U.W..
0030 00 e5 29 10 00 00 01 01 08 0a 51 41 c6 84 8b eb ..).......QA....
0040 2f ed XX XX XX XX 20 XX XX XX XX 2d XX XX XX 2e /.EHLO xxxx-xxx.
0050 XX XX XX XX XX 2e XX XX XX XX XX XX XX XX XX XX xxxxx.xxxxxxxxxx
0060 2e 63 6f 6d 0d 0a .com..
7 0.096519 Y.Y.Y.Y -> X.X.X.X SMTP 156 S: 250 SIZE 12582912 | 250 DSN | 250
ENHANCEDSTATUSCODES | 250 AUTH NTLM | 250 8BITMIME | 250 OK
0000 00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00 .PV.d..PV.0X..E.
0010 00 8e 1e da 40 00 37 06 fb ca d5 29 8e 67 ac 11 [email protected]....).g..
0020 19 23 00 19 fc 26 f3 55 0e 57 8b 00 b0 b3 80 18 .#...&.U.W......
0030 04 02 25 56 00 00 01 01 08 0a 8b eb 30 0d 51 41 ..%V........0.QA
0040 c6 84 32 35 30 2d 53 49 5a 45 20 31 32 35 38 32 ..250-SIZE 12582
0050 39 31 32 0d 0a 32 35 30 2d 44 53 4e 0d 0a 32 35 912..250-DSN..25
0060 30 2d 45 4e 48 41 4e 43 45 44 53 54 41 54 55 53 0-ENHANCEDSTATUS
0070 43 4f 44 45 53 0d 0a 32 35 30 2d 41 55 54 48 20 CODES..250-AUTH
0080 4e 54 4c 4d 0d 0a 32 35 30 2d 38 42 49 54 4d 49 NTLM..250-8BITMI
0090 4d 45 0d 0a 32 35 30 20 4f 4b 0d 0a ME..250 OK..
8 0.096737 X.X.X.X -> Y.Y.Y.Y SMTP 103 C: MAIL
FROM:<[email protected]>
0000 00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00 .PV.0X.PV.d...E.
0010 00 59 76 ff 40 00 40 06 9a da ac 11 19 23 d5 29 .Yv.@.@......#.)
0020 8e 67 fc 26 00 19 8b 00 b0 b3 f3 55 0e b1 80 18 .g.&.......U....
0030 00 e5 29 11 00 00 01 01 08 0a 51 41 c6 8d 8b eb ..).......QA....
0040 30 0d 4d 41 49 4c 20 46 52 4f 4d 3a 3c XX XX XX 0.MAIL FROM:<xxx
0050 XX XX XX XX XX 2e XX XX XX XX 40 XX XX XX XX XX xxxxx.xxxx@xxxxx
0060 2e 63 6f 6d 3e 0d 0a .com>..
9 0.128714 Y.Y.Y.Y -> X.X.X.X SMTP 87 S: 250 2.1.0 Sender OK
0000 00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00 .PV.d..PV.0X..E.
0010 00 49 1e df 40 00 37 06 fc 0a d5 29 8e 67 ac 11 [email protected]....).g..
0020 19 23 00 19 fc 26 f3 55 0e b1 8b 00 b0 d8 80 18 .#...&.U........
0030 04 02 a9 65 00 00 01 01 08 0a 8b eb 30 2e 51 41 ...e........0.QA
0040 c6 8d 32 35 30 20 32 2e 31 2e 30 20 53 65 6e 64 ..250 2.1.0 Send
0050 65 72 20 4f 4b 0d 0a er OK..
10 0.128822 X.X.X.X -> Y.Y.Y.Y SMTP 140 C: RCPT
TO:<[email protected]> ORCPT=rfc822;[email protected]
0000 00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00 .PV.0X.PV.d...E.
0010 00 7e 77 00 40 00 40 06 9a b4 ac 11 19 23 d5 29 .~w.@.@......#.)
0020 8e 67 fc 26 00 19 8b 00 b0 d8 f3 55 0e c6 80 18 .g.&.......U....
0030 00 e5 29 36 00 00 01 01 08 0a 51 41 c6 95 8b eb ..)6......QA....
0040 30 2e 52 43 50 54 20 54 4f 3a 3c XX 2e XX XX XX 0.RCPT TO:<x.xxx
0050 XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX xx@xxxxxxxxxxxxx
0060 2e 66 72 3e 20 4f 52 43 50 54 3d 72 66 63 38 32 .fr> ORCPT=rfc82
0070 32 3b XX XX XX XX XX XX XX 40 XX XX XX XX XX XX 2;xxxxxx@xxxxxxx
0080 XX XX XX XX XX XX XX 2e 66 72 0d 0a xxxxxxx.fr..
11 0.164675 Y.Y.Y.Y -> X.X.X.X SMTP 90 S: 250 2.1.5 Recipient OK
0000 00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00 .PV.d..PV.0X..E.
0010 00 4c 1e e2 40 00 37 06 fc 04 d5 29 8e 67 ac 11 [email protected]....).g..
0020 19 23 00 19 fc 26 f3 55 0e c6 8b 00 b1 22 80 18 .#...&.U....."..
0030 04 02 e4 53 00 00 01 01 08 0a 8b eb 30 52 51 41 ...S........0RQA
0040 c6 95 32 35 30 20 32 2e 31 2e 35 20 52 65 63 69 ..250 2.1.5 Reci
0050 70 69 65 6e 74 20 4f 4b 0d 0a pient OK..
12 0.164764 X.X.X.X -> Y.Y.Y.Y SMTP 72 C: DATA
0000 00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00 .PV.0X.PV.d...E.
0010 00 3a 77 01 40 00 40 06 9a f7 ac 11 19 23 d5 29 .:w.@.@......#.)
0020 8e 67 fc 26 00 19 8b 00 b1 22 f3 55 0e de 80 18 .g.&.....".U....
0030 00 e5 28 f2 00 00 01 01 08 0a 51 41 c6 9e 8b eb ..(.......QA....
0040 30 52 44 41 54 41 0d 0a 0RDATA..
13 0.197068 Y.Y.Y.Y -> X.X.X.X SMTP 112 S: 354 Start mail input; end with
<CRLF>.<CRLF>
0000 00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00 .PV.d..PV.0X..E.
0010 00 62 1e ee 40 00 37 06 fb e2 d5 29 8e 67 ac 11 [email protected]....).g..
0020 19 23 00 19 fc 26 f3 55 0e de 8b 00 b1 28 80 18 .#...&.U.....(..
0030 04 02 0f 11 00 00 01 01 08 0a 8b eb 30 72 51 41 ............0rQA
0040 c6 9e 33 35 34 20 53 74 61 72 74 20 6d 61 69 6c ..354 Start mail
0050 20 69 6e 70 75 74 3b 20 65 6e 64 20 77 69 74 68 input; end with
0060 20 3c 43 52 4c 46 3e 2e 3c 43 52 4c 46 3e 0d 0a <CRLF>.<CRLF>..
(more than 10k paquets of data…)
10640 15.358175 X.X.X.X -> Y.Y.Y.Y SMTP 2642 C: DATA fragment, 2576 bytes
10641 15.362672 Y.Y.Y.Y -> X.X.X.X TCP 66 25 → 64550 [ACK] Seq=200
Ack=12584250 Win=95872 Len=0 TSval=2347461552 TSecr=1363268963
10642 15.362688 X.X.X.X -> Y.Y.Y.Y SMTP 2642 C: DATA fragment, 2576 bytes
10643 15.363923 Y.Y.Y.Y -> X.X.X.X SMTP 90 S: 552 Data size exceeded
10644 15.363938 X.X.X.X -> Y.Y.Y.Y SMTP 1354 C: DATA fragment, 1288 bytes
10645 15.519580 X.X.X.X -> Y.Y.Y.Y SMTP 1354 C: DATA fragment, 1288 bytes
10646 15.799532 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363269091 TSecr=2347461552
10647 16.351553 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363269229 TSecr=2347461552
10648 17.459539 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363269506 TSecr=2347461552
10649 19.679610 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363270061 TSecr=2347461552
10650 24.107530 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363271168 TSecr=2347461552
10651 32.971650 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363273384 TSecr=2347461552
10652 50.667578 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363277808 TSecr=2347461552
10653 86.059559 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363286656 TSecr=2347461552
10654 156.971556 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363304384 TSecr=2347461552
10655 195.472753 X.X.X.X -> Y.Y.Y.Y 64550 → 25 [RST, ACK] Seq=12656378 Ack=224
Win=29312 Len=0 TSval=1363314009 TSecr=2347461552