POP2Exchange = Zombie? (Full Version)

All Forums >> [Content Security] >> GFI MailEssentials for Exchange/SMTP



Message


wehrlim -> POP2Exchange = Zombie? (17.Jun.2008 9:23:07 AM)

Hi everyone


I've a strange problem by a costumer since 5 days: We've got multiple Mailaccounts we're pulling via POP2Exchange to the local Mailserver. It worked very well - but now the most Mails (i suppose, those witch aren't shown in the whitelists) are marked as SPAM (DNSBL) by MailEssentials12 (Newest Build).

I tried most everething and found some helpful entries in this forum. So I analysed the problem down to one point (Names replaced by <--->):

2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","INFO: Mime From display name: <--->"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","INFO: Message recipients: 1"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Recipient <---> belongs to a local domain (<--->)"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL",">> CHeaderChecking"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Processing Message : DNS-Blacklist"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","GFI_MTAMSGPROPS_CONNECTION_SERVER_IP_ADDRESS is 127.0.0.1"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Performing Zombie Check on the following IP: 127.0.0.1"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL",">> CheckOpenRelay"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Cache size: 3010"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Checking: 127.0.0.1"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","IP 127.0.0.1 was found in cache: 'open-relay'"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","<< CheckOpenRelay (returning spam)"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","SPAM DETECTED: Open Relay detected"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Report: Sendender Mail-Server gefunden auf bl.spamcop.net "
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Writing SpamFlag: -1"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Spam email is blocked"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","Action config is <log: 1 block: 1 type: 4 NDR: 0 Tag: 0 Exchange: SPAM>"
2008-06-17,12:06:22,765,3,"#00000a00","#000022f8","info   ","DNSRBL","[CIMessage::MIMESenders]"

Yes, the local Server (POP2Exchange) is marked as a Zombie - the funny part is; The Zombie-Test by SOPS.net is disabled in ME - and in all Logs spamcop.net (witch is the first in the DNSBL-List) is the bad-guy. Of course none of the servers belonged to the mails are listed on any known BL-Server (checked more then once).

I also restarted IIS-Admin and GFI-Services multiple times now to clear the cache - no result :(

Any good idea?

Greetings, Mike




John Letourneau -> RE: POP2Exchange = Zombie? (17.Jun.2008 10:56:37 AM)

Mike,

Can you open a command prompt and run iisreset?  This should clear that cache for you.  Let me know how it goes.




wehrlim -> RE: POP2Exchange = Zombie? (17.Jun.2008 11:40:31 AM)

Hi John, thnx for the answer!

I can't belive it: now it works :) I tried this (IISRESET) multiple times in the last few days, no chance - and now... Everething seems OK again.

This must been your positiv aura ;)

I'le still keep an eye on it and would repost if it is back tomorrow...

Greetings, Mike




John Letourneau -> RE: POP2Exchange = Zombie? (17.Jun.2008 11:47:13 AM)

Mike,

Good to hear, let me know how it goes.




Page: [1]