Question

Spam Blocking Sites

Asked by: vinodmore


How to avoid getting listed in spam blocking sites like Baracuda, Spamhaus etc etc???

Our Router IP address got listed in Spamhaus in XBL list, so we were not able to send mails, mails got stuck in outbox. Incoming mails were fine.

Some how i unlisted the Router IP from site.
But i want to know why it gets listed, and how to avoid it from happening?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-10 at 03:33:25ID24720825
Topics

Spam Black Holes

,

Anti-Spam White Lists

,

Miscellaneous Networking

Participating Experts
1
Points
500
Comments
23

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Spam, Spam, Spam, Spam!
    No, not a call for a Monty Python reunion......... We are a small (40-50 mailboxes) company running a single Exchange 2000 server. Lately our spam has shot through the roof. I am just beginning to look for a blocking solution and would appreciate pointers about what has wo...
  2. Spamming
    hello someone has been intentionally spamming about our company, which caused our company to be in spam list according to my current host theplanet.com, the spam source came from 88.233.128.168 , which is not even ours the email source is also not ours, our company name o...
  3. SPAM
    Spam is starting to get out of control on our domain. We currently apply to two DNS blacklist (spamhaus and dnsbl) which block a large percentage of our spam however users are still reporting 20-50 spam messages are getting through. Is there a better list to subscribe to or p...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: alanhardistyPosted on 2009-09-10 at 04:11:18ID: 25299034

You get listed because something inside your organisation, or outside your organisation using authentication is sending out spam via your server, or directly from inside the network.

Your best bet is to lock down port 25 on your firewall to only allow traffic out from the server's IP address only.  This will stop other Spam sending bots from being able to transmit their crap.

Keep you AV software up-to-date and run regular scans of spyware software such as MalwareBytes - www.malwarebytes.org.

In terms of why you got listed - if you check the blacklisting site - they will give you a reason why you were listed in the first place.  If you have removed the listing, then you will have lost the ability to find out why.  If it hapens again, dig a little deeper and find out why.  It may be a virus infection / trojan that got onto a machine.

 

by: vinodmorePosted on 2009-09-10 at 04:19:53ID: 25299076

alanhardisty

We have Cyberoam C25i UTM+Firewall inbetween so how can security be compromised?

Also
Our mail server is at remote location not in our office premises.
We use POP3 account to Send/Receive mails.

What best can do in this scenario??
 

 

by: alanhardistyPosted on 2009-09-10 at 04:25:24ID: 25299096

If you are using POP3 to send / receive emails, then you will have to allow TCP port 25 from all computers otherwise they won't be able to send emails.

Not familiar with the Cyberoam C25i UTM+Firewall - but assume it is a heavy duty piece of kit.

Unfortunately, if you have de-listed yourself without knowing the cause of the listing, we will not get to the bottom of the reason, so we will just be speculating.

If it happens again, make sure you know why, then you can look into stopping it happening again.

It could be someone your organisation emails reported you as sending spam because they got an email they didn't want.  But again, this is just speculation.

 

by: vinodmorePosted on 2009-09-10 at 05:09:27ID: 25299358

You mean I have to create rule in firewall to access mailserver, so that any host wont able to make any connection other then to mail server.

Cyberoam C25i is Firewall + UTM box.

I de-listed the IP as soon as i saw it, message said something like this "system must be infected by Bot. But i don't think so any system is infected cause we have Symantec Endpoint Protection (updated) on all systems.

Still can you suggest me any good Bot detection and removal tool?






 

by: alanhardistyPosted on 2009-09-10 at 05:36:29ID: 25299516

Yes - if your clients use pop3 to your own server, then make a rule to only allow outbound tcp port 25 from the server.

You can still get infected with anti-virus software on the systems.  All that has to happen is a careless click of the mouse and that gives permission to a nasty to install on your pc and then you are infected.  Symantec or any other AV program will not stop that from happening.

Malwarebytes is a good general tol for detecting unwanted items.  www.malwarebytes.org

 

by: vinodmorePosted on 2009-09-11 at 20:33:03ID: 25314950

ok i will create rule for mail traffic.

But do you think Symantec Endpoint Protection will not able to fix bots??

Shall i install Malwarebytes on all systems and scan?

 

by: vinodmorePosted on 2009-09-11 at 20:48:56ID: 25314999

This IP address getting listed in spam blocking sites, happened previously also when i had just plain router, so i purchased Cyberoam Firewall + UTM box to avoid this situation again.

I made revere DNS entry for ip address also to avoid this situation still no luck.


Man this spam sites are irritating.

 

by: alanhardistyPosted on 2009-09-12 at 02:17:46ID: 25315704

I just dealt with an infection of th waledac spambot and it uses the systems own internal email mechanism to send spam, thus it used my customer's exchange server.  It bugged the hell out of me for ages until I used the ISA server logs to identify traffic destined to port 25 externally, rules out the source as the server and the destination os the server and this left one machine.

I used DHCP to locate that machine and then check the machine for relevant registry entries and found the keys there.  Update MalwareBytes and scanned and it found and removed the infection.

No more spam - no more blacklists.

Have you identified the machine(s) with the infection yet?

 

by: vinodmorePosted on 2009-09-12 at 06:08:41ID: 25316399

I don't understand how can infected systems can spam when they are behind Cyberoam C25i Firewall+UTM box appliance which is having features like Anti-Virus, Anti-Spam, IDP, Web Filtering.

Or can they breach security?

I brought Firewall to avoid this situation till this happening. And same thing happening. Oh god.


Let me tell you few things so that you guide me more appropriately...

- Mailserver is at remote location, its Postfix (unix based) mailing server.
- We users have configured POP3 account to access mails.
- All systems are workgroup environment.

Also to be honest my experience with Malwarebytes is not that good it was not able to fix my any issues up till now.
But since you suggest I'll install & scan all systems with Malwarebytes.

 

by: alanhardistyPosted on 2009-09-12 at 06:13:57ID: 25316412

I thought ISA server was going to be sufficient to stop spam being sent out - boy was I wrong!

Whatever you have in the way of the internet - there is always a way around it if the person is clever enough.

Can you email me your IP address (via my profile) so that I can do some checks for you and see if I can give you some more accurate guidance to remove your problems.  I'll understand if you don't want to.

 

by: vinodmorePosted on 2009-09-12 at 06:36:53ID: 25316487

Mate you didn't answer my few questions.

IP address you want? Like?

Also thing i should mention is that we get lot of Spam mails in our mailbox would that be causing this?
But i don't think, user open this mails, cause till now they aware what is spam and what is not. They straight away delete those mails.

 

by: alanhardistyPosted on 2009-09-12 at 06:46:23ID: 25316511

Sorry (painting at home at the moment) - Once a virus is inside your system, they will find a way out.

All that has to happen is that a user clicks on a webpage with a bad program injected into it and they click OK or Cancel or No or a link (or even just visit the wrong site) and Bang!  Infected.

Even the best firewall / security cannot stop this from happening.

I don't know your firewall at all - so cannot comment on the specifics of what it can / cannot / is supposed to do, but I know that it is always a game of cat and mouse.

If you get lots of spam - ditch the postfix at the remote location and manage it yourself.  I just installed Vamsoft ORF - www.vamsoft.com (on the recommendation of Mestha - EE's leading Exchange expert and Microsoft MVP) and since installing it - 0 spam and I am on day 12.

Previously I would get 7-10 a week - since Vamsoft - nothing.  It is extremely well priced at $239 per server so whatever you are paying for postfix - if it is more than $239 - you are wasting your money.  This software is excellent.

In terms of IP - please can I have your Internet facing IP.

 

by: vinodmorePosted on 2009-09-12 at 08:06:02ID: 25316739

Internet facing IP = 114.143.226.235(Firewall IP) 114.143.226.233(Gateway IP)

 

by: vinodmorePosted on 2009-09-12 at 08:11:54ID: 25316761

BTW which color you chose?

 

by: alanhardistyPosted on 2009-09-12 at 08:15:04ID: 25316771

Here is the response from uceprotect:

Who is responsible for this listing?
YOU ARE NOT!. Your IP 114.143.226.235 was NOT involved in a spamrun, but has a spammy neighborhood. Other customers within this range did not care about their security and got hacked and started spamming, while your provider has possibly not even noticed that there is a serious problem.

We are sorry for you, but you have chosen an provider not acting fast enough on spammers.

Therefore we recommend:
Please send a complaint to your provider and request them to fix this problem immediately.
Think about this: You pay them for, that you can use the Internet without problems.
If they are ignoring your complaint or claiming they can't do anything, you should consider to change your provider.

Can't you make an exception for me?
We never make exceptions. Requests to us are futile. Only your provider can fix this problem.
Our system respects IP's which are registered at ips.whitelisted.org, these are excluded from Level 2.

How can this netrange be removed from Level 2?
After your provider has fixed his problems, the UCEPROTECT-Level 2 listing will be removed automatically and free of charge as soon as the causal Level 1 listings will expire.
Every IP temporary listed at Level 1 expires 7 days after we have seen the last abusive action originating from it.
If your provider don't want to wait for free expiration, they can optionally do Expressdelisting, which is charged a total of 150 EUROs per Level 2 listed allocation.
It is necessary that all problems which have caused the Level 2 listing are fixed in first place, otherwise this netrange might end up in Level 2 again within a short timeframe.

Basically - you are not spamming - but IP's from your ISP close to your IP address are spamming, so you should be fine in terms of infections, but you need to talk to your ISP and complain to them and get the to deal with this.

 

by: alanhardistyPosted on 2009-09-12 at 08:16:04ID: 25316773

Painting plaster coving (white) and touching up the mess made when the coving was installed with Snowdrop!

 

by: vinodmorePosted on 2009-09-12 at 08:33:06ID: 25316826

But how can i prove them (ISP), that this problem is from there end.

They will say 114.143.226.235 belongs to your firewall which is getting blocked, that means there is spamming from your end. You need to Fix it.

I had this problem with my previous ISP also. So moved to this bigger ISP which is current one(TATA Teleservices).

 

by: alanhardistyPosted on 2009-09-12 at 08:38:23ID: 25316850

I got the above information from www.mxtoolbox.com running the blacklist check for your ip address.

Once you get the results, click on the link in the righ-hand column and you get taken to the uceprotect site.

Enter your ip and you will get the same info I did.

Get Tata to do the same and get them to sort out their problems.

Don't get fobbed off - insist they resolve the issue or move to another (cleaner) isp if there is one!

 

by: vinodmorePosted on 2009-09-12 at 09:38:33ID: 25317007

OK got it what i have to do. Fight with ISP. I'll do it.

But do i have to worry about UCEPROTECTL2 & UCEPROTECTL3 listings?

Actually i'm more worried about getting listed in Spamhaus-ZEN, This is site which causes a lots of problems to me. Need more info this site. See pic

IP got listed over there on last Thursday i made a request removed it. We were no able to send mails, mails were stuck outbox itself.

One more thing---
Now as you say its problem with ISP, then should i relax keep network as it is I mean shall I avoid go around install and scan all systems for Malwares??

 

by: alanhardistyPosted on 2009-09-12 at 09:43:07ID: 25317030

If you get listed - find out why and then let us know as we can give you specific advise to eliminate the problem.  Right now - you don't have the info so we can't give the advice.

Keep checking every couple of days to make sure you don't pop up again and if you do - raise a question on EE and get some more advice.

 

by: vinodmorePosted on 2009-09-14 at 21:30:53ID: 25331741

OK yesterday created rule on firewall allow host to communicate only to mailserver are remote location, and all other smtp traffic will be dropped.

I'll scan all systems with Symantec and Malwarebytes.

Hope i should not face any problems??

 

by: alanhardistyPosted on 2009-09-14 at 23:57:00ID: 25332371

MalwareBytes will mop up anything it finds and Symantec should also, so you should be fine.

 

by: vinodmorePosted on 2009-09-17 at 02:15:11ID: 31626991

Ok i'll follow instructions by expert.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...