Solved

Domain Name listed in RBL

Posted on 2008-10-31
8
1,343 Views
Last Modified: 2013-11-15
Exchange 2003
Email is working however some emails are not being delievered to some domains and are being stuck in the queue

I did a check of our domain name on DNSstuff.com and it says 6 Blacklists Domain is listed on RBL

which is causing emails not to be delievered.  How do I fix this and prevent it?

We have antivirus/spam running on all computers and email servers so not sure what to do to get our emails flowing again
0
Comment
Question by:WestonGroup
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +1
8 Comments
 
LVL 9

Expert Comment

by:Housammuhanna
ID: 22850213
Hving AntiSPAM dont mean that you can not be a black list
Listen
You have to check your ANTISPAM update and make sure that its protecting your local net from sending SPAM Emails
Make sure that sending Email list with several dead Email account will be consider as a SPAM and your IP will be blacked again
Enter MXTOOLBOX.com
check your IP and Request Removal for your Black List it may take about 24 hour
0
 
LVL 13

Expert Comment

by:Rowley
ID: 22850410
Emm...

There are various reasons you might be on a blacklist, the main one being that your SMTP server is acting as an open relay. Connections may also be rejected by certain mail hosts if you do not have a reverse (PTR) address for your mail host.

For relay info, check out http://support.microsoft.com/kb/895853
For DNS ptr guidance check out http://support.microsoft.com/kb/300171

hth.
0
 

Author Comment

by:WestonGroup
ID: 22850645
Neither were the case

I checked our domain and it said CBL listed us
ATTENTION: At the time of detection, this IP was infected with, or NATting for a computer infected with a high volume spam sending trojan - it is participating or facilitating a botnet sending spam or spreading virus/spam trojans.

ATTENTION: if you simply repeatedly remove this IP address from the CBL without correcting the problem, the CBL WILL stop letting you delist it.

This is identified as the Cutwail spambot

I ran a removal tool which found a trojan which I removed and requested delisting 2 days ago but it's still being listed...

I can't see to find how to fix this

0
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 13

Expert Comment

by:Rowley
ID: 22850759
"or NATting for a computer infected"

- Ensure no system bar your mail gateways can make outbound smtp connections.
- Check your mail logs to see whether you might still be sending trashy mails, what internal clients are connecting etc.
- Make sure every host on your network has up to date AV and has run and the removal tool for this trojan.

"I can't see to find how to fix this"

Don't despair...
0
 
LVL 9

Expert Comment

by:Housammuhanna
ID: 22850918
Enable SMTP Logging and See how is using your SMTP Server to send Emails
or configure the Firewall to log all the SMTP Traffic
0
 
LVL 7

Expert Comment

by:celazkon
ID: 23400475
Hi,
I had exactly the same issue, it a NDR spam, solved it by disabling the NDR reports on Exchange. Don't forget to double-check Your server for any trojans/malware. If You don't find any,  block on Your firewall the outbound connection on port 25 for Your whole network, except the mailserver itself (this is best practise, regardless this issue). Then go to the Exchange Management console and select the Organization configuration-Hub transport. Select the Remote domains tab and doubleclick the default item (if You have any other in the list, repeat the next step for all required items). On the properties dialog box, select the Message format tab, and clear the checkbox at Allow non-delivery reports, then click okay. Also, if You use the exchange anti-spam features, disable the Reject messages option on the Anti-spam-Content filter-Actions tab.
Afterwards, go to CBL and delist Your server IP address.
It more a workaround than solution, since You should PREVENT the spam messages delivery to non-existent addresses in Your organization, but this is quite impossible without some CISCO, Sonicwall or similar hardware DPI device (or dedicated server for the email black-hole).

It about the following scenario:
Spammer sends out email to Your domain to non-existing user. Exchange recieves the email, since its anti-spam features doesn't interpret the message as spam. Once it gets through the spam-filter check, the server tries to deliver message to user mailbox. Since no such user (and no such email alias) exists in Your organization, Exchange generates the NDR report and send it out back to the address stated in the original spam message at the Sender header. Thus, Your Exchange sends out NDR report for every spam that passes through the anti-spam filter, even when its addressed to non-existent email. Therefore, it basically generates more spam, since it replies to spam email with another email. The CBL then correctly interprets this as a spam-bot and includes Your mailserver's IP address in the blacklist.

Hope this helps You.
Martin
0
 
LVL 7

Accepted Solution

by:
celazkon earned 500 total points
ID: 23400480
Oops, I just realised, I wrote You instructions for the Exchange 2007 server. For Exchange 2003, check:
http://support.microsoft.com/kb/294757
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A list of top three free exchange EDB viewers that helps the user to extract a mailbox from an unmounted .edb file and get a clear preview of all emails & other items with just a single click on mailboxes.
This article was originally published on Monitis Blog, you can check it here . If you have responsibility for software in production, I bet you’d like to know more about it. I don’t mean that you’d like an extra peek into the bowels of the sourc…
The viewer will learn how to successfully download and install the SARDU utility on Windows 8, without downloading adware.
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question