On 08/02/2010 09:47 AM, Jim Bassett wrote:

On Aug 2, 2010, at 2:11 AM, Jake Vickers wrote:

On 08/01/2010 10:21 AM, Jim Bassett wrote:
Hi all. Hopefully this is on topic enough for the qmail list. I'm running qmail toaster and have a handful of account holders (on various virtual domains) who have their mail forwarded from their [email protected] on my server to their [email protected]. This has always worked fine - I just set the forwarding in virtualdomain.com/qmailadmin/

But for the past few days I have been getting tons of bounced emails that all are connected to these accounts that forward to gmail, and I'm having a hard time figuring out exactly what is going on, and most importantly, whether I am in danger of having my whole mail server blacklisted by google. Here is a typical one below. I'm very thankful if anyone can take the time to look at what is happening here. I've replaced the real email addresses with the following fake, but hopefully clear, addresses:

[email protected]: replaces the spammers email address. This is constantly changing from email to email.

[email protected]: is a legitimate user of my mail server through his own virtual domain on my server.

[email protected]: is the same legitimate user's gmail account where [email protected] is set to forward to.

my.mailserver.com: is my fake mail server domain
1.2.3.4: is my fake mail server IP

74.125.95.27: is google IP and has not been changed.

Below is a typical message:

Hi. This is the qmail-send program at ash.datamantic.com.
I tried to deliver a bounce message to this address, but the bounce bounced!

<[email protected]>:
User and password not set, continuing without authentication.
74.125.95.27 does not like recipient.
Remote host said: 550-5.1.1 The email account that you tried to reach does not exist. Please try
550-5.1.1 double-checking the recipient's email address for typos or
550-5.1.1 unnecessary spaces. Learn more at
550 5.1.1 http://mail.google.com/support/bin/answer.py?answer=6596 f14si10875163ibb.15
Giving up on 74.125.95.27.

--- Below this line is the original bounce.

Return-Path: <>
Received: (qmail 32438 invoked for bounce); 1 Aug 2010 09:01:22 -0000
Date: 1 Aug 2010 09:01:22 -0000
From: [email protected]
To: [email protected]
Subject: failure notice

Hi. This is the qmail-send program at my.mailserver.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<[email protected]>:
User and password not set, continuing without authentication.
<[email protected]> 74.125.95.27 failed after I sent the message.
Remote host said: 550-5.7.1 [1.2.3.4 7] Our system has detected an unusual rate of unsolicited 550-5.7.1 mail originating from your IP address. To protect our users from 550-5.7.1 spam, mail sent from your IP address has been blocked. Please visit 550-5.7.1 http://www.google.com/mail/help/bulk_mail.html to review our Bulk
550 5.7.1 Email Senders Guidelines. v16si10850185ibh.66

--- Below this line is a copy of the message.

Return-Path: <[email protected]>
Received: (qmail 32426 invoked by uid 89); 1 Aug 2010 09:01:20 -0000
Delivered-To: [email protected]
Received: (qmail 32421 invoked by uid 89); 1 Aug 2010 09:01:20 -0000
Received: by simscan 1.4.0 ppid: 32403, pid: 32412, t: 1.3451s
       scanners: attach: 1.4.0 clamav: 0.95.2/m:51/d:9872 spam: 3.2.5
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on my.mailserver.com
X-Spam-Level: *****
X-Spam-Status: Yes, score=5.0 required=4.5 tests=BAYES_99,HTML_MESSAGE,
   ONLINE_PHARMACY,RDNS_NONE autolearn=no version=3.2.5
X-Spam-Report:
   *  3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
   *      [score: 1.0000]
   *  0.0 ONLINE_PHARMACY BODY: Online Pharmacy
   *  0.0 HTML_MESSAGE BODY: HTML included in message
   *  1.5 RDNS_NONE Delivered to trusted network by a host with no rDNS
Received: from unknown (HELO microsof09249f) (94.178.58.77)
by my.mailserver.com with SMTP; 1 Aug 2010 09:01:19 -0000
Received-SPF: unknown (ash.datamantic.com: Multiple SPF records returned)
Received: (qmail 4495 by uid 495); Sun, 1 Aug 2010 13:00:53 -0300
From: "Try Viagra4Free" <[email protected]>
To: <[email protected]>
Subject: ***SPAM*** The magical blue pills will do it
Date: Sun, 1 Aug 2010 12:19:55 -0300
Message-ID: <000c01cb3179$9aca8ac0$d05fa0...@org>
MIME-Version: 1.0
Content-Type: multipart/alternative;
   boundary="----=_NextPart_000_000B_01CB3179.9ACA8AC0"
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: AcjrHiuRR5w52cipMs1HC4vOVsX2gg==
Content-Language: en-us
X-Spam-Prev-Subject: The magical blue pills will do it

This is a multipart message in MIME format.

------=_NextPart_000_000B_01CB3179.9ACA8AC0
Content-Type: text/plain;
   charset="us-ascii"
Content-Transfer-Encoding: 7bit

Your cheapest sex drugs online
http://friendmoral.com/


The way I see it, spam is being received by my mail server. It is correctly marked as spam by my spamassassin. And then it is forwarded (as the user wants) to his gmail account. But I think gmail is seeing this as my mailserver sending it spam! Of course I'm most worried about this part:

Remote host said: 550-5.7.1 [1.2.3.4 7] Our system has detected an unusual rate of unsolicited 550-5.7.1 mail originating from your IP address. To protect our users from 550-5.7.1 spam, mail sent from your IP address has been blocked. Please visit 550-5.7.1 http://www.google.com/mail/help/bulk_mail.html to review our Bulk
550 5.7.1 Email Senders Guidelines. v16si10850185ibh.66

Am I really in danger of being blocked? It doesn't seem like I have been at this point. Is there a better way to set up these forwards so that gmail doesn't think I am a spammer for forwarding spam to a users account who actually wants these messages forwarded?


Gmail does appear to see your IP as the one sending the mail, since it is being forwarded. You could look at SRS (I think there's documentation on the wiki about this), as well as some other initial front-line spam deterrents (more/better blacklists, additional clamav/spamassassin definitions, greylisting, etc.).


Thank you for the reply. My server is correctly marking the emails as spam. It then forwards them to gmail with ***SPAM*** included in the subject. According to this google support page, that should be enough to avoid google thinking my server is spamming:

http://mail.google.com/support/bin/answer.py?hl=en&answer=175365

Except this doesn't appear to be the case, as google is still seeing my server as sending the spam. The support page above includes this note about procmail causing this exact problem:

Please note that procmail is one of the most common reasons why the envelope sender gets changed when forwarding. Adding the following to your config file will fix this issue:
SENDER=`formail -c -x Return-Path`

SENDMAILFLAGS="-oi -f $SENDER"



I know qmail toaster does not use procmail, but could a similar thing still be happening? Does my stock qmail toaster setup change the envelope sender when forwarding emails?

Alternately, is there a way to not forward messages that my toaster has marked as spam?

Thank you.

Not going to read through all of Gmail's rules, but it appears they want "SPAM" instead of "***SPAM***" if this is read literally. This can be changed in the /etc/mail/spamassassin/local.cf file. You need to get a copy of a message that is forwarded to a Gmail account and review the headers to see if it is following their guidelines. If there are still doubts, you may want to ask the email support people at Gmail what they want.



---------------------------------------------------------------------------------
Qmailtoaster is sponsored by Vickers Consulting Group 
(www.vickersconsulting.com)
   Vickers Consulting Group offers Qmailtoaster support and installations.
     If you need professional help with your setup, contact them today!
---------------------------------------------------------------------------------
    Please visit qmailtoaster.com for the latest news, updates, and packages.
To unsubscribe, e-mail: [email protected]
    For additional commands, e-mail: [email protected]


Reply via email to