I'm having an issue with messages that should be getting through, but seem to get dropped after passing spamdyke tests. I'm trying to determine if my servers or the sending servers are dropping the connection, and if my servers, what to do about it.

Most of my log analysis and research took place on the 19th, I've been interrupted several times while trying to get this email off.

A client's been trying to send messages to one of our salespeople since the 15th of July. I can see in the Spamdyke logs several instances per day, from the 15th to the 19th, of messages coming in from this client and passing Spamdyke tests.

Here's /var/log/qmail/smtp log entries for a message that did not get through, slightly sanitized:

2010-07-18 01:36:23.551112500 tcpserver: pid 20120 from 209.85.214.172
2010-07-18 01:36:23.706122500 tcpserver: ok 20120 mail.me.example.com:10.10.10.7:25 mail-iw0-f172.google.com:209.85.214.172::57247 2010-07-18 01:36:29.245261500 CHKUSER accepted rcpt: from <[email protected]::> remote <:mail-iw0-f172.google.com:209.85.214.172> rcpt <[email protected]> : found existing recipient 2010-07-18 01:36:29.245261500 policy_check: remote [email protected] -> local [email protected] (UNAUTHENTICATED SENDER)
2010-07-18 01:36:29.245261500 policy_check: policy allows transmission
2010-07-18 01:36:29.245261500 spamdyke[20120]: ALLOWED from: [email protected] to: [email protected] origin_ip: 209.85.214.172 origin_rdns: mail-iw0-f172.google.com auth: (unknown)
2010-07-18 01:36:29.380284500 tcpserver: end 20120 status 0


I notice that there's a spamdyke[<PID1>]: ALLOWED entry but no simscan:[<PID2>]:<STATUS> entry. Also, there's no tcpserver: status: X/100 entry before the tcpserver: end <PID1> entry. All the attempts that seemed to be dropped follow this pattern, and all of the attempts are coming from the same gmail server: mail-iw0-f172.google.com


Here's log entries for the message on the 19th that got through:

2010-07-19 08:09:05.039406500 tcpserver: pid 7474 from 209.85.213.44
2010-07-19 08:09:05.259977500 tcpserver: ok 7474 mail.me.example.com:10.10.10.7:25 mail-yw0-f44.google.com:209.85.213.44::47827 2010-07-19 08:09:11.145427500 CHKUSER accepted rcpt: from <[email protected]::> remote <:mail-yw0-f44.google.com:209.85.213.44> rcpt <[email protected]> : found existing recipient 2010-07-19 08:09:11.145437500 policy_check: remote [email protected] -> local [email protected] (UNAUTHENTICATED SENDER)
2010-07-19 08:09:11.145442500 policy_check: policy allows transmission
2010-07-19 08:09:11.145446500 spamdyke[7474]: ALLOWED from: [email protected] to: [email protected] origin_ip: 209.85.213.44 origin_rdns: mail-yw0-f44.google.com auth: (unknown)
2010-07-19 08:09:13.221158500 tcpserver: status: 10/100
2010-07-19 08:09:13.223886500 simscan:[7475]:CLEAN (-0.90/15.00):2.0214s:IPRO Demo:209.85.213.44:[email protected]:[email protected]
2010-07-19 08:09:36.273672500 tcpserver: end 7474 status 0


There's a tcpserver: status: X/100 entry and a simscan:[PID2]:CLEAN entry. Also, the message came in from a different gmail server: mail-yw0-f44.google.com.


I've been researching undesired interactions between gmail and spamdyke or standard components of qmailtoaster, but I haven't found anything noteworthy.


The client was getting a status message, generated by his mail system, that the salesperson was able to get a copy of and forward to me:

 Delivery to the following recipient failed permanently:

    [email protected]

 Technical details of permanent failure:
 Missed upload deadline (state SENT_MESSAGE)


Researching this message, I see that it's generated by gmail and may be related to sending large attachments, but the client wasn't sending any attachments.


Does the list have any ideas?


My environment:

32-bit CentOS 5.3 running as a guest on a 64-bit VMware Server 2 on 64-bit CentOS 5.3

spamdyke 4.0.10+TLS+CONFIGTEST+DEBUG, installed using qtp-install-spamdyke

autorespond-toaster.i386    2.0.4-1.3.6
clamav-toaster.i386    0.95.2-1.3.30
control-panel-toaster.noarch    0.5-1.3.7
courier-authlib-toaster.i386    0.59.2-1.3.10
courier-imap-toaster.i386    4.1.2-1.3.10
daemontools-toaster.i386    0.76-1.3.6
ezmlm-cgi-toaster.i386    0.53.324-1.3.6
ezmlm-toaster.i386    0.53.324-1.3.6
isoqlog-toaster.i386    2.1-1.3.7
libdomainkeys-toaster.i386    0.68-1.3.6
libsrs2-toaster.i386    1.0.18-1.3.6
maildrop-toaster.i386    2.0.3-1.3.8
maildrop-toaster-devel.i386    2.0.3-1.3.8
qmail-pop3d-toaster.i386    1.03-1.3.20
qmail-toaster.i386    1.03-1.3.20
qmailadmin-toaster.i386    1.2.12-1.3.8
qmailmrtg-toaster.i386    4.2-1.3.6
qmailtoaster-plus.noarch    0.3.1-1.4.15
qmailtoaster-plus.repo.noarch    0.2-2
ripmime-toaster.i386    1.4.0.6-1.3.6
simscan-toaster.i386    1.4.0-1.3.8
spamassassin-toaster.i386    3.2.5-1.3.17
squirrelmail-toaster.noarch    1.4.19-1.3.15
ucspi-tcp-toaster.i386    0.88-1.3.9
vpopmail-toaster.i386    5.4.17-1.3.7
vqadmin-toaster.i386    2.3.4-1.3.6

All mail (that passes tests) is forwarded to an internal Exchange server.



Brent Gardner




---------------------------------------------------------------------------------
Qmailtoaster is sponsored by Vickers Consulting Group 
(www.vickersconsulting.com)
   Vickers Consulting Group offers Qmailtoaster support and installations.
     If you need professional help with your setup, contact them today!
---------------------------------------------------------------------------------
    Please visit qmailtoaster.com for the latest news, updates, and packages.
To unsubscribe, e-mail: [email protected]
    For additional commands, e-mail: [email protected]


Reply via email to