On Aug 2, 2010, at 2:11 AM, Jake Vickers wrote:
On 08/01/2010 10:21 AM, Jim Bassett wrote:
Hi all. Hopefully this is on topic enough for the qmail list. I'm
running qmail toaster and have a handful of account holders (on
various virtual domains) who have their mail forwarded from their [email protected]
on my server to their [email protected]. This has always worked
fine - I just set the forwarding in virtualdomain.com/qmailadmin/
But for the past few days I have been getting tons of bounced
emails that all are connected to these accounts that forward to
gmail, and I'm having a hard time figuring out exactly what is
going on, and most importantly, whether I am in danger of having my
whole mail server blacklisted by google. Here is a typical one
below. I'm very thankful if anyone can take the time to look at
what is happening here. I've replaced the real email addresses with
the following fake, but hopefully clear, addresses:
[email protected]: replaces the spammers email address. This is
constantly changing from email to email.
[email protected]: is a legitimate user of my mail server
through his own virtual domain on my server.
[email protected]: is the same legitimate user's gmail account where [email protected]
is set to forward to.
my.mailserver.com: is my fake mail server domain
1.2.3.4: is my fake mail server IP
74.125.95.27: is google IP and has not been changed.
Below is a typical message:
Hi. This is the qmail-send program at ash.datamantic.com.
I tried to deliver a bounce message to this address, but the bounce
bounced!
<[email protected]>:
User and password not set, continuing without authentication.
74.125.95.27 does not like recipient.
Remote host said: 550-5.1.1 The email account that you tried to
reach does not exist. Please try
550-5.1.1 double-checking the recipient's email address for typos or
550-5.1.1 unnecessary spaces. Learn more at
550 5.1.1 http://mail.google.com/support/bin/answer.py?answer=6596
f14si10875163ibb.15
Giving up on 74.125.95.27.
--- Below this line is the original bounce.
Return-Path: <>
Received: (qmail 32438 invoked for bounce); 1 Aug 2010 09:01:22 -0000
Date: 1 Aug 2010 09:01:22 -0000
From: [email protected]
To: [email protected]
Subject: failure notice
Hi. This is the qmail-send program at my.mailserver.com.
I'm afraid I wasn't able to deliver your message to the following
addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<[email protected]>:
User and password not set, continuing without authentication.
<[email protected]> 74.125.95.27 failed after I sent the message.
Remote host said: 550-5.7.1 [1.2.3.4 7] Our system has detected an
unusual rate of unsolicited
550-5.7.1 mail originating from your IP address. To protect our
users from
550-5.7.1 spam, mail sent from your IP address has been blocked.
Please visit
550-5.7.1 http://www.google.com/mail/help/bulk_mail.html to review
our Bulk
550 5.7.1 Email Senders Guidelines. v16si10850185ibh.66
--- Below this line is a copy of the message.
Return-Path: <[email protected]>
Received: (qmail 32426 invoked by uid 89); 1 Aug 2010 09:01:20 -0000
Delivered-To: [email protected]
Received: (qmail 32421 invoked by uid 89); 1 Aug 2010 09:01:20 -0000
Received: by simscan 1.4.0 ppid: 32403, pid: 32412, t: 1.3451s
scanners: attach: 1.4.0 clamav: 0.95.2/m:51/d:9872 spam: 3.2.5
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on
my.mailserver.com
X-Spam-Level: *****
X-Spam-Status: Yes, score=5.0 required=4.5
tests=BAYES_99,HTML_MESSAGE,
ONLINE_PHARMACY,RDNS_NONE autolearn=no version=3.2.5
X-Spam-Report:
* 3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
* [score: 1.0000]
* 0.0 ONLINE_PHARMACY BODY: Online Pharmacy
* 0.0 HTML_MESSAGE BODY: HTML included in message
* 1.5 RDNS_NONE Delivered to trusted network by a host with no
rDNS
Received: from unknown (HELO microsof09249f) (94.178.58.77)
by my.mailserver.com with SMTP; 1 Aug 2010 09:01:19 -0000
Received-SPF: unknown (ash.datamantic.com: Multiple SPF records
returned)
Received: (qmail 4495 by uid 495); Sun, 1 Aug 2010 13:00:53 -0300
From: "Try Viagra4Free" <[email protected]>
To: <[email protected]>
Subject: ***SPAM*** The magical blue pills will do it
Date: Sun, 1 Aug 2010 12:19:55 -0300
Message-ID: <000c01cb3179$9aca8ac0$d05fa0...@org>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_000B_01CB3179.9ACA8AC0"
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcjrHiuRR5w52cipMs1HC4vOVsX2gg==
Content-Language: en-us
X-Spam-Prev-Subject: The magical blue pills will do it
This is a multipart message in MIME format.
------=_NextPart_000_000B_01CB3179.9ACA8AC0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit
Your cheapest sex drugs online
http://friendmoral.com/
The way I see it, spam is being received by my mail server. It is
correctly marked as spam by my spamassassin. And then it is
forwarded (as the user wants) to his gmail account. But I think
gmail is seeing this as my mailserver sending it spam! Of course
I'm most worried about this part:
Remote host said: 550-5.7.1 [1.2.3.4 7] Our system has detected an
unusual rate of unsolicited
550-5.7.1 mail originating from your IP address. To protect our
users from
550-5.7.1 spam, mail sent from your IP address has been blocked.
Please visit
550-5.7.1 http://www.google.com/mail/help/bulk_mail.html to review
our Bulk
550 5.7.1 Email Senders Guidelines. v16si10850185ibh.66
Am I really in danger of being blocked? It doesn't seem like I have
been at this point. Is there a better way to set up these forwards
so that gmail doesn't think I am a spammer for forwarding spam to a
users account who actually wants these messages forwarded?
Gmail does appear to see your IP as the one sending the mail, since
it is being forwarded. You could look at SRS (I think there's
documentation on the wiki about this), as well as some other initial
front-line spam deterrents (more/better blacklists, additional
clamav/spamassassin definitions, greylisting, etc.).
Thank you for the reply. My server is correctly marking the emails as
spam. It then forwards them to gmail with ***SPAM*** included in the
subject. According to this google support page, that should be enough
to avoid google thinking my server is spamming:
http://mail.google.com/support/bin/answer.py?hl=en&answer=175365
Except this doesn't appear to be the case, as google is still seeing
my server as sending the spam. The support page above includes this
note about procmail causing this exact problem:
Please note that procmail is one of the most common reasons why the
envelope sender gets changed when forwarding. Adding the following to
your config file will fix this issue:
SENDER=`formail -c -x Return-Path`
SENDMAILFLAGS="-oi -f $SENDER"
I know qmail toaster does not use procmail, but could a similar thing
still be happening? Does my stock qmail toaster setup change the
envelope sender when forwarding emails?
Alternately, is there a way to not forward messages that my toaster
has marked as spam?
Thank you.
---------------------------------------------------------------------------------
Qmailtoaster is sponsored by Vickers Consulting Group
(www.vickersconsulting.com)
Vickers Consulting Group offers Qmailtoaster support and installations.
If you need professional help with your setup, contact them today!
---------------------------------------------------------------------------------
Please visit qmailtoaster.com for the latest news, updates, and packages.
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]