Thanks for your advice Viktor I have done a capture and loaded into WireShark.
1,"0.000000","1.2.3.4","192.168.1.239","TCP","66","19524 > smtp [SYN] Seq=0 Win=8192 Len=0 MSS=1380 WS=256 SACK_PERM=1" 2,"0.000022","192.168.1.239","1.2.3.4","TCP","66","smtp > 19524 [SYN, ACK] Seq=0 Ack=1 Win=5840 Len=0 MSS=1460 SACK_PERM=1 WS=128" 3,"0.043797","1.2.3.4","192.168.1.239","TCP","60","19524 > smtp [ACK] Seq=1 Ack=1 Win=131072 Len=0" 4,"0.047331","192.168.1.239","1.2.3.4","SMTP","96","S: 220 spambox.co.nz ESMTP Postfix" 5,"0.093672","1.2.3.4","192.168.1.239","SMTP","90","C: EHLO remote.sender.com" 6,"0.093699","192.168.1.239","1.2.3.4","TCP","54","smtp > 19524 [ACK] Seq=43 Ack=37 Win=5888 Len=0" 7,"0.095070","192.168.1.239","1.2.3.4","SMTP","261","S: 250-spambox.co.nz | 250-PIPELINING | 250-SIZE 20728640 | 250-VRFY | 250-ETRN | 250-STARTTLS | 250-AUTH PLAIN LOGIN CRAM-MD5 | 250-AUTH=PLAIN LOGIN CRAM-MD5 | 250-ENHANCEDSTATUSCODES | 250-8BITMIME | 250 DSN" 8,"0.140698","1.2.3.4","192.168.1.239","SMTP","115","C: MAIL FROM:<jono.sm...@sender.com> SIZE=221190" 9,"0.146588","192.168.1.239","1.2.3.4","SMTP","68","S: 250 2.1.0 Ok" 10,"0.190450","1.2.3.4","192.168.1.239","SMTP","89","C: RCPT TO:<recipi...@domain.com>" 11,"0.230190","192.168.1.239","1.2.3.4","TCP","54","smtp > 19524 [ACK] Seq=264 Ack=133 Win=5888 Len=0" 12,"3.625029","192.168.1.239","1.2.3.4","SMTP","68","S: 250 2.1.5 Ok" 13,"3.668700","1.2.3.4","192.168.1.239","SMTP","60","C: DATA" Which follows on for a while transmitting then this occurs 66,"4.267143","192.168.1.239","1.2.3.4","TCP","54","smtp > 19524 [ACK] Seq=315 Ack=47059 Win=64128 Len=0" 67,"4.272844","1.2.3.4","192.168.1.239","SMTP","1434","C: DATA fragment, 1380 bytes" 68,"4.278587","1.2.3.4","192.168.1.239","SMTP","1434","C: DATA fragment, 1380 bytes" 69,"4.278597","192.168.1.239","1.2.3.4","TCP","54","smtp > 19524 [ACK] Seq=315 Ack=49819 Win=64128 Len=0" 70,"4.284366","1.2.3.4","192.168.1.239","SMTP","1434","C: DATA fragment, 1380 bytes" 71,"4.290093","1.2.3.4","192.168.1.239","SMTP","1434","[TCP Previous segment not captured] C: DATA fragment, 1380 bytes" 72,"4.290104","192.168.1.239","1.2.3.4","TCP","66","smtp > 19524 [ACK] Seq=315 Ack=51199 Win=64128 Len=0 SLE=53959 SRE=55339" 73,"4.295853","1.2.3.4","192.168.1.239","SMTP","1434","C: DATA fragment, 1380 bytes" 74,"4.295859","192.168.1.239","1.2.3.4","TCP","66","[TCP Dup ACK 72#1] smtp > 19524 [ACK] Seq=315 Ack=51199 Win=64128 Len=0 SLE=53959 SRE=56719" 75,"4.301731","1.2.3.4","192.168.1.239","SMTP","1434","C: DATA fragment, 1380 bytes" 76,"4.301738","192.168.1.239","1.2.3.4","TCP","66","[TCP Dup ACK 72#2] smtp > 19524 [ACK] Seq=315 Ack=51199 Win=64128 Len=0 SLE=53959 SRE=58099" 77,"4.307588","1.2.3.4","192.168.1.239","SMTP","1434","[TCP Previous segment not captured] C: DATA fragment, 1380 bytes" -- View this message in context: http://postfix.1071664.n5.nabble.com/Postfix-lost-connection-issue-tp57670p57788.html Sent from the Postfix Users mailing list archive at Nabble.com.