[mailop] Heads up on Exim, gnutls, TLS1.3 and gmail

2019-08-28 Thread Tim Bray via mailop
Hi, Probably mainly for Debian users. libgnutls30 3.6.7-4(Debian Buster) exim4-daemon-heavy 4.89-2+deb9u5 (Debian Stretch) Run these together and it tries to use TLS1.3 when sending email. And google seems to close the connection straight away. log entry: 2019-08-28 10:01:37

Re: [mailop] No response on DNS queries to NS for zen.spamhaus.org

2019-10-30 Thread Tim Bray via mailop
Hi, I think you really need to use your own recursive resolver to use spamhaus.  Like install unbound and use localhost as resolver. like using 8.8.8.8 results in no answer.   Maybe your ISP's resolvers have the same problem.    Does your provider transparently proxy port 53 traffic?

[mailop] Blank emails to office 365

2019-11-26 Thread Tim Bray via mailop
Hi, Weird problem. We have a system that sends order updates to our customers. Plain text emails.  Not changed for years. Same system, same customers. We suddenly have a problem  for some where customers receive the email, but it looks blank.  The problem has only occurred with people using

Re: [mailop] Blank emails to office 365

2019-11-26 Thread Tim Bray via mailop
ot hotmail or Microsoft here) --srs *From:* mailop on behalf of Tim Bray via mailop *Sent:* Tuesday, November 26, 2019 3:40 PM *To:* mailop@mailop.org *Subject:* [mailop] Blank emails to office 365 Hi, Weird problem. We hav

Re: [mailop] Certified Senders Alliance

2019-10-03 Thread Tim Bray via mailop
On 03/10/2019 08:46, Neil Youngman via mailop wrote: It is now October. The emails are still coming and there has been no further communication from CSA. I'd be tempted to complain to the information commissioner.   You are lucky because you actually know who is sending the stuff, and they

Re: [mailop] DNSxL lookups IPv6 - one /128 per DNS query

2020-02-03 Thread Tim Bray via mailop
On 02/02/2020 18:48, Matthias Leisi via mailop wrote: From one particular IPv6 range, each and every DNS query was sent from a unique IPv6 /128, and every /128 seen was used exactly once. Um, I do this.   To guard against cache poisoning attacks.   Each nameserver has a /64 to use for

Re: [mailop] Abandoning self hosting and moving to Protonmail - experiences?

2020-01-27 Thread Tim Bray via mailop
On 27/01/2020 12:57, Lennert Van Alboom via mailop wrote: Alternatives? https://www.migadu.com/ Tim ___ mailop mailing list mailop@mailop.org https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Re: [mailop] STARTTLS - Constant Contact and yahoo.co.jp

2020-08-26 Thread Tim Bray via mailop
On 26/08/2020 21:33, Scott Mutter via mailop wrote: I just wanted to gauge what other mail server administrators were doing in regards to this.  The response is kind of what i expected, but the shift in wanting TLS and encryption on every connection, kind of made me question what the response

Re: [mailop] Deutsche Telekom rejects connections because of missing "provider identification"

2020-08-27 Thread Tim Bray via mailop
On 27/08/2020 10:30, G. Miliotis via mailop wrote: Not everyone is a business with already-public information. I run my own server and host some domains on that. What assurances do I have that my personal information is protected by T-Mobile / DT after I send it to them? Why should I be forced

Re: [mailop] ANN: MTA-STS/TLSRPT for mailop.org MX

2020-09-30 Thread Tim Bray via mailop
On 30/09/2020 08:17, Patrick Ben Koetter via mailop wrote: At the moment the SMTP server itself supports STARTTLS and DANE. We plan to add MTA-STS when the feature becomes available. Should it be using TLS for outbound connections?  I'm not seeing that? (no problem if that is something you

Re: [mailop] ANN: MTA-STS/TLSRPT for mailop.org MX

2020-09-30 Thread Tim Bray via mailop
On 30/09/2020 09:59, Thomas Mechtersheimer via mailop wrote: It does. Exim adds "s" to received_protocol for encrypted connections. Check your exim log for the cipher that was used... Oh, it is. My bad.  I was just expecting to see the cipher in the header. TLS1.3 - all good :) Tim

Re: [mailop] The 'DNS only requires UDP' misconception vs SPF et al -- historical reasons?

2020-09-30 Thread Tim Bray via mailop
On 30/09/2020 10:08, Peter N. M. Hansteen via mailop wrote: Back in the day I suppose you could get a sort of working setup with UDP-only DNS, but this has me wondering, is there a quasi-rational historical reason for blocking 53/TCP? As in, was there at some point in time a 'ping of

[mailop] Force double opt in for marketing list companies per email address

2020-06-02 Thread Tim Bray via mailop
Hi, So seems to be spam/ham day today.  I've just done 6 unsubscribes.  Orgs I have never heard of, or maybe an organization I once bought something from 10 years ago (or their sister company) I think people are trying to kick start their businesses in the UK by digging out all their old

Re: [mailop] Google: 'Low reputation of the sending domain'

2020-06-02 Thread Tim Bray via mailop
On 02/06/2020 09:37, Benoit Panizzon via mailop wrote: Still 'Spamrate' and 'IP Reputation' and 'Domain Reputation' (all other items too) still show 'there is no data available yet'. At work (provu.co.uk) we send hundreds of emails a day, but always no data in postmaster tools.  I just

Re: [mailop] Is Gmails DMARC check broken?

2020-06-02 Thread Tim Bray via mailop
On 02/06/2020 16:42, Ken O'Driscoll via mailop wrote: Without seeing the actual message my guess is that the *aspf=s* is the problem. This is telling receivers that you want to enforce strict SPF alignment, which means the FQDNs used the SPF tests must match. So, if your 5321.From is using a

Re: [mailop] Outlook 2016: Excessive IMAP connections

2020-08-10 Thread Tim Bray via mailop
On 07/08/2020 19:31, Brandon Long via mailop wrote: Anyways, the point of my story is that it may not be a change to Outlook at all, but a Windows networking change or maybe just more network flakiness among your customers or even your own network (less likely). I wonder if the original

Re: [mailop] Delisting request from sendgrid customer about ip used in recent phishing campaign.

2020-08-12 Thread Tim Bray via mailop
On 11/08/2020 20:41, Matt Harris via mailop wrote: We'd been using sendgrid in production for some stuff, but we're looking at changing that now because it seems like their lack of concern regarding abuse on their platform will lead to more and more deliverability issues as time

[mailop] Sendgrid and phishing

2020-06-17 Thread Tim Bray via mailop
Hi, Anybody else seeing increase phishing through sendgrid?  They look fairly convincing. A few paypals, and a few amazons. I thought sendgrid were ok?    Has somebody leaked a big pile of sendgrid usernames and passwords or something? -- Tim Bray Huddersfield, GB t...@kooky.org

Re: [mailop] SendGrid and Phishing

2020-06-17 Thread Tim Bray via mailop
On 17/06/2020 16:01, Len Shneyder via mailop wrote: Hi All, Appreciate the discussion. As was mentioned in another forum we are aware of the problem—the entire time is engaged in deploying a comprehensive fix that will prevent a wave like this in the future. Just to be perfectly clear, there

Re: [mailop] Microsoft Block list (S3150)

2020-06-26 Thread Tim Bray via mailop
On 24/06/2020 23:03, Al Iverson via mailop wrote: Yep, fill out this form:http://go.microsoft.com/fwlink/?LinkID=614866 Wait a few days for a reply. First reply might just be a "we're routing your ticket" response. Second reply might be useful, or it might be completely bonkers. You might have

Re: [mailop] Force double opt in for marketing list companies per email address

2020-06-05 Thread Tim Bray via mailop
On 04/06/2020 20:08, Matthew Grove via mailop wrote: Of course, there is always a remote possibility that some misconfiguration on our side is causing us to reclassify your specific bounce message. You can compare our /X-MC-User/ header to verify that we are not suppressing the address at

Re: [mailop] [EXTERNAL] Re: Force double opt in for marketing list companies per email address

2020-06-02 Thread Tim Bray via mailop
On 02/06/2020 21:22, Michael Wise via mailop wrote: It would need to be a standard... a SINGLE standard. Like the FTC "Do Not Call" list. I wasn't thinking about something central at all.  I was just thinking about it as something top 1 or 2 market leaders could do to be helpful. (like

Re: [mailop] Force double opt in for marketing list companies per email address

2020-06-02 Thread Tim Bray via mailop
On 02/06/2020 21:52, Oreva Akpolo via mailop wrote: Hey Tom, I'm Oreva, a Deliverability Engineer at Mailchimp. There currently isn't a system to force double opt-in on recipients per email address. What we can recommend is to set up filters or folders, so that you're only seeing mail from

Re: [mailop] openssl on Ubuntu 20.04 - implications for email

2021-01-06 Thread Tim Bray via mailop
On 06/01/2021 13:23, Dan Malm via mailop wrote: Just thought I'd spare others some troubleshooting in case you run in to this, and see if anyone else have any thoughts on it. :) My thoughts are `time for mail operators to pull their fingers out and upgrade`.   Because we are really saying

[mailop] scam prevention

2020-12-08 Thread Tim Bray via mailop
Hi, I'm wondering if it might be a good idea to strip all sender names from emails coming into our corporate email system.   To avoid a false name being used by a scammer. So rewrite a header like `From: Bob Smith ` to  `From: b...@example.org` Because the domain part is checked by SPF and

Re: [mailop] scam prevention

2020-12-08 Thread Tim Bray via mailop
On 08/12/2020 12:32, Mary via mailop wrote: A solid idea, but you would have to avoid modifications to DKIM signed emails that sign the From header field via the h= tag as specified by RFC6376 secton 5.4 and 5.4.1. They aren't going to go any further once they will come in.   So I don't

Re: [mailop] Effeciveness (or not) of SPF

2020-12-08 Thread Tim Bray via mailop
On 08/12/2020 09:22, Paul Smith via mailop wrote: Forwarding is still useful nowadays, but 'willy nilly' forwarding shouldn't be. Nowadays, there needs to be a way to limit forwarding to the forwarding you actually want to happen. The risk of spoofed mail can be catastrophic for a company, and

Re: [mailop] scam prevention

2020-12-09 Thread Tim Bray via mailop
On 08/12/2020 21:35, Ángel via mailop wrote: By the way, how did the "buy amazon and google vouchers" work? That is a new one for me. I am used to CEO fraud wanting to transfer a big amount from the company account, not having the employees buying (with their own money?) amazon vouchers.

Re: [mailop] JSON mail server logs ?

2020-11-20 Thread Tim Bray via mailop
On 20/11/2020 08:01, Andrew C Aitchison via mailop wrote: The developers would like to use a "standard" schema; does anyone use or know of a JSON schema for mail servers logs ? Tricky - a streaming file format is not going to be a valid JSON document? Unless you do 1 JSON document per line,

Re: [mailop] How stale is too stale for contacts?

2021-05-04 Thread Tim Bray via mailop
On 04/05/2021 20:16, Al Iverson via mailop wrote: But on a 1-10 scale of spam problems, I'd call this one about a 1.5. I don't find it worthy of navel gazing. I got the same message.  It's from Hardenize.  I thought the contents were proper useful.   I don't care that I registered my account

Re: [mailop] incoming rate limits

2021-04-19 Thread Tim Bray via mailop
On 16/04/2021 13:44, micah via mailop wrote: It seems to be a fun past-time for some people to mailbomb users (10k emails in minutes), to blow up a person's mailbox so they are over quota, or to make them miss an important email. I'm curious what others have settled on for reasonable rate

Re: [mailop] Greylisting never passing on retry

2021-04-21 Thread Tim Bray via mailop
On 21/04/2021 11:23, Neil Youngman via mailop wrote: It doesn't behave exactly like a normal mail server, but it does retry more than five times. Not all retries are from the same IP, but I have observed that retries from the same IP don't get delivered. Can you just deliver to a normal

Re: [mailop] Current OSS anti-spam software best practice?

2021-02-16 Thread Tim Bray via mailop
On 16/12/2020 10:50, Thomas Walter via mailop wrote: we switched over to rspamd quite a while ago and will not look back. I switched on the back your suggestion.   rspamd seems way better. And switching on the dmarc module sends away the scammers. -- Tim Bray Huddersfield, GB t...@kooky.org

[mailop] google at spamhaus

2021-08-31 Thread Tim Bray via mailop
Hi all, I noticed that a google IPv6 address was recently listed in spamhaus XBL. 2607:f8b0:4864:20::82c at  2021-08-30 19:27:45 UTC I just thought this a bit unusual and worth a mention.  Probably the first time I've seen spamhaus block a genuine sender (to me)

Re: [mailop] I disabled Spamhaus checking due to false-positives

2021-07-15 Thread Tim Bray via mailop
On 15/07/2021 12:29, Mark Milhollan via mailop wrote: Spamhaus has been working fine for me and has been a wonderful resource for many years, but I recently decided I had to disable using them on my personal, low volume mail server because of a few recent surprises (that's right, I don't look

Re: [mailop] IMAP and SMTP in the same or separated IPs?

2021-10-15 Thread Tim Bray via mailop
Hi, I've used different hostnames (and therefore different certificates) on the same IP for years on one service. And different IPs with different IPs on another service. And same IP, same hostname (same certificate) on another. Makes no difference.  Do what suits you. Tim On 15/10/2021

Re: [mailop] spamhaus blocking Linode IPv6 (2a01:7e01)

2021-11-25 Thread Tim Bray via mailop
On 25/11/2021 14:22, Mary via mailop wrote: But that is not a real solution is it? Maybe linode and spamhaus can come up with a better solution between them? Why is it not a real solution? It's a bigger problem than Linode and Spamhaus. (I refer to Linode in my writings, but I don't

Re: [mailop] SMTP AUTH harassment

2021-07-18 Thread Tim Bray via mailop
On 17/07/2021 21:13, Slavko via mailop wrote: Please, i want ask others if are these (mostly) Brasil attempts know to others too or am i "special" target? I seem to get continuous SMTP stuff.  Work is much worse than my personal server.  But we have 10's of domains and due to historical

Re: [mailop] mail.ru broke mailing lists

2021-07-19 Thread Tim Bray via mailop
On 12/07/2021 12:00, Jaroslaw Rafa via mailop wrote: They required SMTP AUTH for all messages received on port 25 with the sender from their domain and rejected the messages if the session was not authenticated. A crazy idea, but they did exactly this. I do this.  For a corporate email

Re: [mailop] mail.ru broke mailing lists

2021-07-19 Thread Tim Bray via mailop
On 19/07/2021 10:16, Thomas Walter via mailop wrote: On 19.07.21 10:56, Tim Bray via mailop wrote: I do this.  For a corporate email system is makes a lot of sense.   I shouldn't be receiving email externally with a From: domain which is local. As long as your users don't have an external

Re: [mailop] I disabled Spamhaus checking due to false-positives

2021-07-16 Thread Tim Bray via mailop
On 16/07/2021 17:58, Al Iverson via mailop wrote: If you want to guide this dummy on how to run a local resolver like that, I'd appreciate the tips.:) I was trying to get out of the DNS business but if I want to do any local DNSBL querying, I guess I have to reconsider that. On an

[mailop] IPv6 reverse DNS from office365

2022-02-10 Thread Tim Bray via mailop
Hi, Is anybody else having trouble relaying email out of office365. I think they have broken their reverse DNS. Our method to trust *.outbound.protection.outlook.com 2022-02-10 09:51:46 H=(GBR01-LO2-obe.outbound.protection.outlook.com) [2a01:111:f400:7e15::200] When we receive from

Re: [mailop] How to contact ClamAVNet support

2022-06-06 Thread Tim Bray via mailop
On 03/06/2022 11:13, Carlota Iglesias Martinez via mailop wrote: I have managed to find that “Herustics” refers that they are coming from a financial institution and ‘SpoofedDomain’ means that they contain hyperlinks that are not known to be associated with the organization and may be

Re: [mailop] Filter out emoji from email adresses

2024-03-06 Thread Tim Bray via mailop
On 04/03/2024 21:40, Sebastian Nielsen via mailop wrote: Im thinking to do same as I do when I filter emoji from subject lines, but this will also filter out umlaits from people’s names so “André Andersson” becomes “Andr Andersson” and “Recep Tayyip Erdoğan” would become “Recep Tayyip