Question

Sendmail 451 4.4.1 reply: read error from Deferred: Connection timed out with

Asked by: scopeortho

I am getting the following error with some outside connections:

220 Ready
>>> EHLO mail.scop.net
250-ESMTP Server Ready
250-SIZE 104857600
250-DSN
250-STARTTLS
250 TLS
>>> STARTTLS
220 Server ready Ready to start TLS
>>> EHLO mail.scop.net
250-ESMTP Server Ready
250-SIZE 104857600
250 DSN
>>> MAIL From:<dmartinez@scop.net> SIZE=22877
250 +OK Sender OK
>>> RCPT To:<JARoberts@ironmountain.com> NOTIFY=SUCCESS,FAILURE,DELAY
250 +OK Recipient OK
>>> DATA
354 Start mail input, end with "<CR><LF>.<CR><LF>"  
>>> .
<JARoberts@ironmountain.com>... Connecting to colsmtp02.ironmtn.com. via esmtp...
<JARoberts@ironmountain.com>... Closing connection to nussmtp01.ironmtn.com.
220 Ready
>>> EHLO mail.scop.net
250-ESMTP Server Ready
250-SIZE 104857600
250-DSN
250-STARTTLS
250 TLS
>>> STARTTLS
220 Server ready Ready to start TLS
>>> EHLO mail.scop.net
250-ESMTP Server Ready
250-SIZE 104857600
250 DSN
>>> MAIL From:<dmartinez@scop.net> SIZE=22877
250 +OK Sender OK
>>> RCPT To:<JARoberts@ironmountain.com> NOTIFY=SUCCESS,FAILURE,DELAY
250 +OK Recipient OK
>>> DATA
354 Start mail input, end with "<CR><LF>.<CR><LF>"  
>>> .
<JARoberts@ironmountain.com>... Deferred
Closing connection to colsmtp02.ironmtn.com.

Not all users are experiencing this issue and only seems to affect some outside SMTP connections.  I had to rebuild our Mail Server because of hardware problems so I did a fresh build on new hardware.  We are on Linux RH 8.0.  I can send mail to other SMTP's and here is a weird twist to the problem.  I have  a user with email address of first name.last name with an alias of first initial.lastname.  She cannot send to a specific e-mail she gets the same error stating deferred connection timed out.  But I can successfully send to that address with no problems.  What seems to be the issue.  I have looked at the MTU, but if some emails are being sent out I figured that could not be the issue.  Also, we are receiving fine with no problems.  

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2006-06-06 at 13:03:59ID21876883
Tags

error

,

451

,

read

,

from

Topic

SendMail Email Server

Participating Experts
1
Points
0
Comments
8

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. postfix and deferred status
    I realize this is probably a dumb question but here it is any way. My question deals with using postfix to send email from a Linux server. I am new at this so please bear with me. I have inherited an internal bug tracking system for our software development. This system was...
  2. How to solve "Deferred: Invalid argument" problems in s…
    I have a constant large number of items in my sendmail queue, most of them containing "Deferred: Invalid argument" in the "q" file. I know most of these should be deliverable, but it seems sendmail is somehow sending something stupid to the receiving serv...
  3. Deferred: Connection refused by conservus.ca
    Hello I have a mail server that we call Discovery 192.168.1.30. Our MX record point to mail.montrealinfo.com 192.168.1.30. We don't have an MX record for conciergeinfo.com and conservus.ca even though we own these domains. Then we have a faxserver that we call FAXSERVER 192...
  4. sendmail - stat=Deferred: Connection refused by [12…
    We have recently started seeing messages like the following in our /var/log/maillog. Sep 27 10:48:25 www3 sendmail[823]: k8RHmOvL000823: to=Doug <XXXXXXXXXXXXX@mobile.mycingular.com>, ctladdr=xamine (501/501), delay=00:00:01, xdelay=00:00:00, mailer=relay, pri=30482, ...
  5. Deferred Emails
    Hi: I have a Linux CENTOS Server running PostFix. It has no mailboxes, but is a kind of gateway, because it receives all the MX load for several Domains which have mailboxes in another destination Server, which is a Linux CENTOS running Sendmail. So, after checking the email...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: scopeorthoPosted on 2006-06-07 at 16:05:55ID: 16857527

This problem only seems to be to outside connections utilizing ESMTP and trying to establish a TLS connection.  Of course we will not be able to establish a TLS connection to outside SMTP servers since we will not have each others Certificates.  But during the connection the outside SMTP server states to start sending data but the data will not be transferred.  Now, I had about 6 messages this morning in the queue that were stuck in there.  I flushed them out in the afternoon and they all got delivered.  Any ideas as to why this connection is having diffuculties is it on my end?  Is there a way to have sendmail not to establish a TTL connection?  I see that there are available entries that are commented our in the sendmail.cf about TTL, if they are commented out that should mean that my mail server will not use TTL.  Can this even be the problem?  This is the only common variable of the messages getting stuck in my queue.  These are some SMTP's that I have some diffuculties with: UCSD.EDU;TMAIL.COM;IRONMOUNTAIN.COM;HANGER.COM.

 

by: scopeorthoPosted on 2006-06-12 at 16:28:37ID: 16890394

I have not been able to resolve this issue.  We send mail to Hanger.com frequently and this is now begining to affect work flow.  I do not beleive it is a network problem since we recieve from this SMTP's just fine.  It is sending out to them that is the problem.  Here is my Sendmail.cf:

divert(-1)
dnl This is the sendmail macro config file. If you make changes to this file,
dnl you need the sendmail-cf rpm installed and then have to generate a
dnl new /etc/mail/sendmail.cf by running the following command:
dnl
dnl        m4 /etc/mail/sendmail.mc > /etc/mail/sendmail.cf
dnl
include(`/usr/share/sendmail-cf/m4/cf.m4')
VERSIONID(`linux setup for Red Hat Linux')dnl
OSTYPE(`linux')
dnl Uncomment and edit the following line if your mail needs to be sent out
dnl through an external mail server:
dnl define(`SMART_HOST',`smtp.your.provider')
define(`confDEF_USER_ID',``8:12'')dnl
undefine(`UUCP_RELAY')dnl
undefine(`BITNET_RELAY')dnl
dnl define(`confAUTO_REBUILD')dnl
define(`confTO_CONNECT', `1m')dnl
define(`confTRY_NULL_MX_LIST',true)dnl
define(`confDONT_PROBE_INTERFACES',true)dnl
define(`PROCMAIL_MAILER_PATH',`/usr/bin/procmail')dnl
define(`ALIAS_FILE', `/etc/aliases')dnl
dnl define(`STATUS_FILE', `/etc/mail/statistics')dnl
define(`UUCP_MAILER_MAX', `2000000')dnl
define(`confUSERDB_SPEC', `/etc/mail/userdb.db')dnl
define(`confPRIVACY_FLAGS', `authwarnings,novrfy,noexpn,restrictqrun')dnl
define(`confAUTH_OPTIONS', `A')dnl
dnl TRUST_AUTH_MECH(`EXTERNAL DIGEST-MD5 CRAM-MD5 LOGIN PLAIN')dnl
dnl define(`confAUTH_MECHANISMS', `EXTERNAL GSSAPI DIGEST-MD5 CRAM-MD5 LOGIN PLAIN')dnl
dnl define(`confCACERT_PATH',`/usr/share/ssl/certs')
dnl define(`confCACERT',`/usr/share/ssl/certs/ca-bundle.crt')
dnl define(`confSERVER_CERT',`/usr/share/ssl/certs/sendmail.pem')
dnl define(`confSERVER_KEY',`/usr/share/ssl/certs/sendmail.pem')
dnl define(`confTO_QUEUEWARN', `4h')dnl
dnl define(`confTO_QUEUERETURN', `5d')dnl
dnl define(`confQUEUE_LA', `12')dnl
dnl define(`confREFUSE_LA', `18')dnl
define(`confTO_IDENT', `0')dnl
dnl FEATURE(delay_checks)dnl
FEATURE(`no_default_msa',`dnl')dnl
FEATURE(`smrsh',`/usr/sbin/smrsh')dnl
FEATURE(`mailertable',`hash -o /etc/mail/mailertable.db')dnl
FEATURE(`virtusertable',`hash -o /etc/mail/virtusertable.db')dnl
FEATURE(redirect)dnl
FEATURE(always_add_domain)dnl
FEATURE(use_cw_file)dnl
FEATURE(use_ct_file)dnl
dnl The '-t' option will retry delivery if e.g. the user runs over his quota.
FEATURE(local_procmail,`',`procmail -t -Y -a $h -d $u')dnl
FEATURE(`access_db',`hash -T<TMPF> -o /etc/mail/access.db')dnl
FEATURE(`blacklist_recipients')dnl
EXPOSED_USER(`root')dnl
dnl This changes sendmail to only listen on the loopback device 127.0.0.1
dnl and not on any other network devices. Comment this out if you want
dnl to accept email over the network.
dnl DAEMON_OPTIONS(`Port=smtp,Addr=192.168.0.6, Name=MTA')
dnl NOTE: binding both IPv4 and IPv6 daemon to the same port requires
dnl       a kernel patch
dnl DAEMON_OPTIONS(`port=smtp,Addr=::1, Name=MTA-v6, Family=inet6')
dnl We strongly recommend to comment this one out if you want to protect
dnl yourself from spam. However, the laptop and users on computers that do
dnl not have 24x7 DNS do need this.
dnl FEATURE(`accept_unresolvable_domains')dnl
dnl FEATURE(`relay_based_on_MX')dnl
MAILER(smtp)dnl
MAILER(procmail)dnl
Cwlocalhost.localdomain


I am not too strong in Linux.  So I really need some help on this one!  I am not even sure if I am troubleshooting the right thing here.  Is it the fact that my server is trying to establish a TLS connection or is it totally something else?

 

by: scopeorthoPosted on 2006-06-12 at 16:41:08ID: 16890454

Also when reconciling the maillog I see the TLS connection, but with "verify=FAIL"

 

by: scopeorthoPosted on 2006-06-14 at 11:45:26ID: 16905428

Well I have made one determining factor after troubleshooting all last night.  That these emails are not transferring because they have attachments.  Now, I can send a regular email with no attachment, and to throw another twist I can send an email with a 5KB attachment with no problem.  But I tried a 17KB attachment and it received the deferred connection in the mqueue.  I have sendmail configured to maximum mail size to 10MB.  I really don't understand this problem.  I am now seeing more smtp having issues: UPS.com and ADP.com.  This is really going to hurt us if I cannot resolve this problem.  Before I rebuild the mail server I had in place a Microsoft Windows 2003 SMTP server for temporary and I had no issues with that.  According to sendmail.org there are two issues that maybe causing these types of problems:

Q3.10 -- How do I solve "collect: I/O error on connection" or "reply: read error from host.name" errors?
Date: April 8, 1997
Updated: May 9, 2000
Updated: June 8, 2002
Updated: March 2, 2003

If you are just getting occasional such messages, they're probably due to a temporary network problem, or the remote host crashing or otherwise abruptly terminating the connection. If you are getting a lot of these from a single host, there is probably some incompatibility between 8.x and that host (see Q3.12 and Q3.20). If you get a lot of them in general, you may have network problems that are causing connections to get reset.

Note that this problem is sometimes caused by incompatible values of the MTU (Maximum Transmission Unit) size on a SLIP or PPP connection. Be sure that your MTU size is configured to be the same value as what your ISP has configured for your connection. If you are still having problems, then have your ISP configure your MTU size for 1500 (the maximum value), and you configure your MTU size similarly.

Another possibility is that you have a router/firewall filtering out all incoming ICMP messages, while your OS is doing "Path MTU discovery" (e.g. modern TCP/IP stacks do this by default). Path MTU discovery relies on certain ICMP messages being allowed through back to the host originating the traffic - see our tip on Path MTU Discovery and RFC 1191 for the details.

I have looked at my MTU on my external router and it is set to 1500 just as my sendmail server is too!  I really need some help here it is causing some work stoppage at points.

Dennis

 

by: scopeorthoPosted on 2006-06-14 at 16:48:09ID: 16907967

I tried a temporary install of sendmail on another box and I get the same result.  Now I am just thinking that either I am not configuring sendmail correctly or I have bad installation disk.

 

by: scopeorthoPosted on 2006-06-19 at 12:36:07ID: 16937030

Here is more to add to my problem.  An smtp that I was having trouble with @hanger.com is now OK.  I have just sent two e-mails with large attachments and they were received.  But now I am getting more smtps stuck in the queue.  I have now been tasked to look at MS exchange and offsite mail hosting I have posted a request for recommendations on offsite hosting  here in EE: http://www.experts-exchange.com/Networking/Email_Groupware/Q_21889657.html .  I come from an Exchange background and that is what I prefer.  But in the mean time before we get this new service or server, I need to have functional email and I am downloading 9.0 as we speak and see if this helps me some.  No one has commented am not sure if I am being over looked or if no one has any answers, at this time I am beginning to get desperate here!

 

by: scopeorthoPosted on 2006-06-28 at 11:42:52ID: 17003773

The problem was resolved when we updated our Firewall to the latest build.

 

by: EE_AutoDeleterPosted on 2006-06-28 at 21:05:45ID: 17006790

scopeortho,
Because you have presented a solution to your own problem which may be helpful to future searches, this question is now PAQed and your points have been refunded.

EE_AutoDeleter

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...