Solved

RBL and Exchange 2007

Posted on 2011-09-30
19
515 Views
Last Modified: 2012-05-12
I have a hand full of users that have outside reciepents that bounce back emails sent to them and the error details note 'Message rejected because of RBL policy'

We are running Exchange 2007 and using Vipre (from GFI) for spam filtering. When I run our mail server IP on the blacklist check found at http://www.mxtoolbox.com it comes back clean.

My question is two fold...

(1) Could it be that we are listed someplace else that http://www.mxtoolbox.com does not scan again and if so is there another tool I should be using other than http://www.mxtoolbox.com?

(2) I am under the assumption that I am only relying only on GFI's software for RBL purposes but is it possible that I have it also setup in Exchange? If so how would I check?

Not sure if it matters any but the bounce backs all seem to come from users that have Google for email
0
Comment
Question by:bnrtech
  • 11
  • 8
19 Comments
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36892120
What is the FQDN on your SEND Connector and what is your Reverse DNS Record on your fixed IP Address set as?

Do they match?  Do they both resolve in DNS back to the IP Address you are sending from?

If you are not sure - send me a test message to alan @ it-eye.co.uk and I'll see what you are sending as, what IP you are coming from and I'll see if I can see any issues with your setup that might be causing you problems.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36892124
FYI - Vipre is Anti-Virus not Anti-Spam.  Are you using GFI Mail Essentials for Spam Filtering?
0
 

Author Comment

by:bnrtech
ID: 36892302

Thanks for this input. I will send you a test email right now from the admin account. I did update the FQDN in E2007 a couple of moments ago. I thought I already did this but it looks like I was wrong in that assumption.

The Vipre product we use is both for anti-spam and anti-virus.

Thanks for this helpful input.
0
 

Author Comment

by:bnrtech
ID: 36892321

FYI - Here is the Vipre product that we use...

http://www.gfi.com/mes

0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36892322
Ooh - sorry about the Vipre - didn't know they did a combined product.  We use a Vipre based solution from them and wrongly assumed it was only AV!  You live and you learn :)
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36892343
Okay - test email received.  Checking your config to see if anything stands out as being wrong.
0
 

Author Comment

by:bnrtech
ID: 36892367

All good. Standing by. Thanks :)
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 500 total points
ID: 36892403
Okay - your FQDN = exchange.domain.org.  Your Reverse DNS on the IP you are sending from is mail.domain.org.

Performing an nslookup on exchange.domain.org fails, so you would be better off changing the FQDN on your SEND connector to mail.domain.org then you will be RFC compliant.

Separate note - you have two MX records pointing to the same IP Address, which is completely pointless.  If you only have 1 server - having two MX's is not going to help if your 1 server goes down.  Best to remove the MX record with the 300 priority.

You don't have an SPF record and would be advised to get one setup.

Other than that - you are clean!
0
 

Author Comment

by:bnrtech
ID: 36892596
On the FQDN, maybe I need to restart the connector before the change takes effect (?). I will do that later and send you another test. I see your point in making certain both are mail.domain.org

Understood on the MX record.

Any recommendation on setting up a SPF record?

Thanks for all of the support
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 500 total points
ID: 36892612
Make the change and restart the Exchange Transport Service.

You can visit http://www.microsoft.com/mscorp/safety/content/technologies/senderid/wizard/ to figure out what you need for SPF.

You are welcome :)
0
 

Author Comment

by:bnrtech
ID: 36892717

All good. I will restart the transport now and send you one more test message.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36892740
Okey dokey.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36892805
Still seeing exchange.domain.org as FQDN.
0
 

Author Comment

by:bnrtech
ID: 36893635

Maybe I need to reboot the server (which I can do tonight)?

and/or

Maybe I am not doing the right thing to setup the FQDN? Here are screenshots of the connectors with what I think is the right FQDN setup, Is there something I am missed? connector 1 connector 1connector2.JPG
connector3.JPG
0
 
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 500 total points
ID: 36893701
You don't need to adjust your Receive connector - you need to adjust you Send Connector under Org Config> Hub Transport
0
 

Author Comment

by:bnrtech
ID: 36893755

Got it. My mistake. I just updated (hopefully the right way this time) and resent another test.

Thanks for all the good tips.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36893800
That's better.  Seeing mail.domain.org now.

Try sending emails to the recipients that failed before.
0
 

Author Closing Comment

by:bnrtech
ID: 36893913
Thanks for all the help info!
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 36893966
Thanks for the points :)

Have a good weekend.

Alan
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now