On 12/10/2021 8:17 am, Carl Brewer wrote:
This is what's in the SMTP header when it fails : (XXXX's added by me)
The IP address of the mail client's PC is failing the SPF check, as I
would expect it to. I don't know what I've done wrong that's making it
get looked at though? This is authenticated email coming in via the
submit port 587.
Return-Path: <[email protected]>
Received: from rollcage13.aboc.net.au ([unix socket])
by rollcage13.aboc.net.au (Cyrus 3.4.2) with LMTPA;
Mon, 11 Oct 2021 22:10:01 +1100
X-Cyrus-Session-Id:
rollcage13.aboc.net.au-1633950601-14654-1-18391631690331276567
X-Sieve: CMU Sieve 3.0
Received: from RNMhome (unknown [121.219.1.48])
by rollcage13.aboc.net.au (Postfix) with ESMTPSA id 023EEAC12E;
Mon, 11 Oct 2021 22:09:59 +1100 (AEDT)
X-Virus-Status: Clean
X-Virus-Scanned: clamav-milter 0.103.3 at RC13
From: "XXXX" <[email protected]>
To: "XXXX" <[email protected]>
References:
In-Reply-To:
Subject: stuff
Date: Mon, 11 Oct 2021 22:09:46 +1100
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_61641B89.CB78F85C"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: Ade+j8MsV4/CcPo9SP+TwGBa7frkBQAACtHQ
Content-Language: en-au
X-Spam-Flag: YES
X-Spam-Status: Yes, score=5.2 required=5.0 tests=DOS_OUTLOOK_TO_MX,
FSL_HELO_NON_FQDN_1,HELO_NO_DOMAIN,HTML_MESSAGE,HTTPS_HTTP_MISMATCH,
RDNS_NONE,SPF_FAIL,URIBL_BLOCKED autolearn=no autolearn_force=no
version=3.4.5
X-Spam-Level: *****
X-Spam-Checker-Version: SpamAssassin 3.4.5 (2021-03-20) on
rollcage13.aboc.net.au
And this is the message we see :
Spam detection software, running on the system "rollcage13.aboc.net.au",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
[email protected] for details.
Content preview: Hi again Apologies . From: XXXXX
[mailto:[email protected]]
Sent: Monday, 11 October 2021 5:00 PM Subject: stuff
Content analysis details: (5.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
0.0 FSL_HELO_NON_FQDN_1 No description available.
0.9 SPF_FAIL SPF: sender does not match SPF record (fail)
[SPF failed: Please see
http://www.openspf.org/Why?s=mfrom;id=XXXXX%40yvaviation.com.au;ip=121.219.1.48;r=rollcage13.aboc.net.au]
0.1 HTTPS_HTTP_MISMATCH BODY: No description available.
0.0 HTML_MESSAGE BODY: HTML included in message
1.4 HELO_NO_DOMAIN Relay reports its domain incorrectly
1.3 RDNS_NONE Delivered to internal network by a host
with no rDNS
1.4 DOS_OUTLOOK_TO_MX Delivered direct to MX with Outlook headers
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: 2gb.com, mimecast.com]