Hello,
last few days we've had 2 diferent IP addresses listed in SpamHaus ZEN
1. monitoring server which rarely sends e-mail
- to single address in our internal network
- single address of our customer (outside our network)
- got listed after 4 e-mails within one day.
2. nextcloud server which sends only a few mails in a time
- mostly to our internal network
- one single gmail address on 2024/02/29
- also got listed after 4 e-mails within one day
The only common denominator except our AS is our internal network as
destination, running Fortimail, admins told me it's very unlikely to report
to SpamHaus.
I have tcpdump running on the latter for over a month because this happened
about 3rd time within a few months - no other port 25 connection was made
nearly two weeks before listing.
We have delisted both addresses without any feedback but I am really curious
what happens here and/or how to avoid it.
Are there any other checks or measures I can do?
Is there anyone from SpamHaus who could help me to solve this?
Thanks for any ideas.
--
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Spam is for losers who can't get business any other way.
_______________________________________________
mailop mailing list
mailop@mailop.org
https://list.mailop.org/listinfo/mailop