I'm having an issue with messages that should be getting through, but
seem to get dropped after passing spamdyke tests. I'm trying to
determine if my servers or the sending servers are dropping the
connection, and if my servers, what to do about it.
Most of my log analysis and research took place on the 19th, I've been
interrupted several times while trying to get this email off.
A client's been trying to send messages to one of our salespeople since
the 15th of July. I can see in the Spamdyke logs several instances per
day, from the 15th to the 19th, of messages coming in from this client
and passing Spamdyke tests.
Here's /var/log/qmail/smtp log entries for a message that did not get
through, slightly sanitized:
2010-07-18 01:36:23.551112500 tcpserver: pid 20120 from 209.85.214.172
2010-07-18 01:36:23.706122500 tcpserver: ok 20120
mail.me.example.com:10.10.10.7:25
mail-iw0-f172.google.com:209.85.214.172::57247
2010-07-18 01:36:29.245261500 CHKUSER accepted rcpt: from
<[email protected]::> remote
<:mail-iw0-f172.google.com:209.85.214.172> rcpt
<[email protected]> : found existing recipient
2010-07-18 01:36:29.245261500 policy_check: remote
[email protected] -> local [email protected]
(UNAUTHENTICATED SENDER)
2010-07-18 01:36:29.245261500 policy_check: policy allows transmission
2010-07-18 01:36:29.245261500 spamdyke[20120]: ALLOWED from:
[email protected] to: [email protected] origin_ip:
209.85.214.172 origin_rdns: mail-iw0-f172.google.com auth: (unknown)
2010-07-18 01:36:29.380284500 tcpserver: end 20120 status 0
I notice that there's a spamdyke[<PID1>]: ALLOWED entry but no
simscan:[<PID2>]:<STATUS> entry. Also, there's no tcpserver: status:
X/100 entry before the tcpserver: end <PID1> entry. All the attempts
that seemed to be dropped follow this pattern, and all of the attempts
are coming from the same gmail server: mail-iw0-f172.google.com
Here's log entries for the message on the 19th that got through:
2010-07-19 08:09:05.039406500 tcpserver: pid 7474 from 209.85.213.44
2010-07-19 08:09:05.259977500 tcpserver: ok 7474
mail.me.example.com:10.10.10.7:25
mail-yw0-f44.google.com:209.85.213.44::47827
2010-07-19 08:09:11.145427500 CHKUSER accepted rcpt: from
<[email protected]::> remote
<:mail-yw0-f44.google.com:209.85.213.44> rcpt
<[email protected]> : found existing recipient
2010-07-19 08:09:11.145437500 policy_check: remote
[email protected] -> local [email protected]
(UNAUTHENTICATED SENDER)
2010-07-19 08:09:11.145442500 policy_check: policy allows transmission
2010-07-19 08:09:11.145446500 spamdyke[7474]: ALLOWED from:
[email protected] to: [email protected] origin_ip:
209.85.213.44 origin_rdns: mail-yw0-f44.google.com auth: (unknown)
2010-07-19 08:09:13.221158500 tcpserver: status: 10/100
2010-07-19 08:09:13.223886500 simscan:[7475]:CLEAN
(-0.90/15.00):2.0214s:IPRO
Demo:209.85.213.44:[email protected]:[email protected]
2010-07-19 08:09:36.273672500 tcpserver: end 7474 status 0
There's a tcpserver: status: X/100 entry and a simscan:[PID2]:CLEAN
entry. Also, the message came in from a different gmail server:
mail-yw0-f44.google.com.
I've been researching undesired interactions between gmail and spamdyke
or standard components of qmailtoaster, but I haven't found anything
noteworthy.
The client was getting a status message, generated by his mail system,
that the salesperson was able to get a copy of and forward to me:
Delivery to the following recipient failed permanently:
[email protected]
Technical details of permanent failure:
Missed upload deadline (state SENT_MESSAGE)
Researching this message, I see that it's generated by gmail and may be
related to sending large attachments, but the client wasn't sending any
attachments.
Does the list have any ideas?
My environment:
32-bit CentOS 5.3 running as a guest on a 64-bit VMware Server 2 on
64-bit CentOS 5.3
spamdyke 4.0.10+TLS+CONFIGTEST+DEBUG, installed using qtp-install-spamdyke
autorespond-toaster.i386 2.0.4-1.3.6
clamav-toaster.i386 0.95.2-1.3.30
control-panel-toaster.noarch 0.5-1.3.7
courier-authlib-toaster.i386 0.59.2-1.3.10
courier-imap-toaster.i386 4.1.2-1.3.10
daemontools-toaster.i386 0.76-1.3.6
ezmlm-cgi-toaster.i386 0.53.324-1.3.6
ezmlm-toaster.i386 0.53.324-1.3.6
isoqlog-toaster.i386 2.1-1.3.7
libdomainkeys-toaster.i386 0.68-1.3.6
libsrs2-toaster.i386 1.0.18-1.3.6
maildrop-toaster.i386 2.0.3-1.3.8
maildrop-toaster-devel.i386 2.0.3-1.3.8
qmail-pop3d-toaster.i386 1.03-1.3.20
qmail-toaster.i386 1.03-1.3.20
qmailadmin-toaster.i386 1.2.12-1.3.8
qmailmrtg-toaster.i386 4.2-1.3.6
qmailtoaster-plus.noarch 0.3.1-1.4.15
qmailtoaster-plus.repo.noarch 0.2-2
ripmime-toaster.i386 1.4.0.6-1.3.6
simscan-toaster.i386 1.4.0-1.3.8
spamassassin-toaster.i386 3.2.5-1.3.17
squirrelmail-toaster.noarch 1.4.19-1.3.15
ucspi-tcp-toaster.i386 0.88-1.3.9
vpopmail-toaster.i386 5.4.17-1.3.7
vqadmin-toaster.i386 2.3.4-1.3.6
All mail (that passes tests) is forwarded to an internal Exchange server.
Brent Gardner
---------------------------------------------------------------------------------
Qmailtoaster is sponsored by Vickers Consulting Group
(www.vickersconsulting.com)
Vickers Consulting Group offers Qmailtoaster support and installations.
If you need professional help with your setup, contact them today!
---------------------------------------------------------------------------------
Please visit qmailtoaster.com for the latest news, updates, and packages.
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]