Re: [mailop] Strange mail delivery from microsoft

2023-06-18 Thread Benny Pedersen via mailop
Klaus Ethgen via mailop skrev den 2023-06-18 18:53: I have tighten my firewall a bit and seen many attacks from Microsoft (40.92.0.0/16). They contact once from a IP and then never again. If I greylist them, the will try to deliver from a different address which gets greylisted again and so on.

Re: [mailop] [EXTERNAL] Re: Strange mail delivery from microsoft

2023-06-20 Thread Benny Pedersen via mailop
Jay Hennigan via mailop skrev den 2023-06-20 17:46: On 6/19/23 13:55, Michael Wise via mailop wrote: If you're using GreyListing, know that a given email will not be coming from the same IP address twice. The outgoing IP address is randomized for ... reasons. Because if you reuse the same IP

Re: [mailop] [EXT] - Dkim fails, success on same email?

2023-06-20 Thread Benny Pedersen via mailop
Mark Alley via mailop skrev den 2023-06-20 19:05: You'll need to add the DKIM selector (and key) Sophos generated for you to your external DNS provider so that other receivers can resolve the key, which enables them to validate messages signed by your email filter. if sophos like to change cust

Re: [mailop] Listed on Polspam.pl - how to delist?

2023-06-26 Thread Benny Pedersen via mailop
Sebastian Nielsen via mailop skrev den 2023-06-26 10:39: It seems I have got listed on polspam.pl for some reason. I cannot find why, if there is some email that I sent that triggered something, or if someone accidentially pressed "Spam" instead of "Delete" which happens regularly. Theres no con

Re: [mailop] SPF +all considered harmful

2023-07-11 Thread Benny Pedersen via mailop
Alessandro Vesely via mailop skrev den 2023-07-11 11:12: You need +all if you're after dmarc=pass. no not at all, direct to mx will have spf pass without +all, on next hub envelope sender changes, so new spf problem when next hub forwards mails, it does not need to be a maillist btw if dma

Re: [mailop] SPF +all considered harmful

2023-07-11 Thread Benny Pedersen via mailop
Brandon Long via mailop skrev den 2023-07-11 18:50: I assumed most people had already tuned their systems to ignore +all or overly broad IP ranges, spammers abused that like a decade ago. so why did gmail.com add 30+ ipv4 when it could be simple as +all ? :) i did not count ipv6 on gmail

Re: [mailop] SPF +all considered harmful

2023-07-11 Thread Benny Pedersen via mailop
Bill Cole via mailop skrev den 2023-07-11 19:01: On 2023-07-11 at 11:08:23 UTC-0400 (Tue, 11 Jul 2023 17:08:23 +0200) Benny Pedersen via mailop is rumored to have said: direct to mx will have spf pass without +all, on next hub envelope sender changes, so new spf problem when next hub forwards

Re: [mailop] authentication hacks, I Need someone from AOL and/or Yahoo to contact me

2023-07-26 Thread Benny Pedersen via mailop
John Levine via mailop skrev den 2023-07-26 06:44: This is a very old idea. See https://en.wikipedia.org/wiki/POP_before_SMTP It's not clear who originally invented it. It may have been me. maybe before ipv4 nat was implemented where a single ipv4 could have millions of users in just one t

Re: [mailop] hotmail.com SPF forgot IPv6

2023-08-19 Thread Benny Pedersen via mailop
John Levine via mailop skrev den 2023-08-18 23:37: Ah! Even better. We are pretty much on the same page then I expect. There's a whole lot of perfectly normal sending situations that SPF can't describe. (They mostly incude the words "relay" or "forward".) So if you reject on -all you'll aways l

Re: [mailop] hotmail.com SPF forgot IPv6

2023-08-19 Thread Benny Pedersen via mailop
Taavi Eomäe via mailop skrev den 2023-08-19 19:13: On 19/08/2023 13:16, Benny Pedersen via mailop wrote: if it was hardfails, lets not ignore domain owners, ever An SPF hardfail isn't sufficient for a reject or mark as spam either though. As previously mentioned, DKIM can be and shou

Re: [mailop] Can someone at ptd.net and rcn.com please contact me

2023-09-09 Thread Benny Pedersen via mailop
Ken Robinson via mailop skrev den 2023-09-09 19:37: There is no spam content in the messages. MxToolbox shows that my mail server is not on any blacklists. to be unfair, dnsbl is not content :) proff of content checks is after-data test /me hiddes ___

Re: [mailop] Noticeable increase of spam emanating from Colocrossing?

2023-10-02 Thread Benny Pedersen via mailop
Jarosław Rafa via mailop skrev den 2023-10-02 11:38: Nobody takes UCEProtect seriously. Actually, it takes only a few spamming IPs in a wide IP range to get listed there. Many ISPs that are absolutely OK are listed in UCEProtect level 3. just use dnswl and abusic welcome-list before block-list

Re: [mailop] fastmail and sender score snafu

2023-10-09 Thread Benny Pedersen via mailop
Bill Cole via mailop skrev den 2023-10-09 14:45: On 2023-10-09 at 03:46:08 UTC-0400 (Mon, 9 Oct 2023 07:46:08 +) Gellner, Oliver via mailop is rumored to have said: Postfix default of the maximum queue lifetime is 5 days: https://www.postfix.org/postconf.5.html#maximal_queue_lifetime One m

Re: [mailop] Reaching out to GMAIL

2023-11-21 Thread Benny Pedersen via mailop
Ralf Hildebrandt via mailop skrev den 2023-11-21 12:44: And since it's the postfix-users mailinglist, we're dead sure it's not spam we're sending! only one From: header now, so sure its sys4.de now back to cloud9 solves it, where dkim was not breaked /me hiddes ___

Re: [mailop] Orange ISP - New outbound IP ranges

2023-12-01 Thread Benny Pedersen via mailop
Jeremy Jarry via mailop skrev den 2023-12-01 09:48: Hello all, Just to inform that we will warm up these new outbound IP ranges starting next Monday: where nothing works :=) 80.12.242.64/27, 193.252.23.208, 193.252.23.209, 193.252.23.216, 193.252.23.217, 193.252.23.218, 193.252.23.219, 193.

Re: [mailop] Hotmail complains about their own mail

2023-12-16 Thread Benny Pedersen via mailop
Thomas Walter via mailop skrev den 2023-12-16 19:56: Dec 15 20:46:06 speedy postfix/smtpd[64567]: ACC2D1FF9B: client=mail-westus2azolkn19012032.outbound.protection.outlook.com[52.103.10.32] Dec 15 20:46:06 speedy postfix/cleanup[64616]: ACC2D1FF9B: message-id= Dec 15 20:46:08 speedy postfix/qmg

Re: [mailop] Merry Christmas from Google?

2023-12-17 Thread Benny Pedersen via mailop
Marco Moock via mailop skrev den 2023-12-17 09:00: Am 16.12.2023 um 16:07:19 Uhr schrieb Jarland Donnell via mailop: Obligatory: We don't intend to send any email their way that could be perceived as unsolicited, but our users do use forwarders and we'll never completely match their filters.

Re: [mailop] o365 outbound senders.. Strange Failures sending .. widespread reports

2023-12-18 Thread Benny Pedersen via mailop
Michael Peddemors via mailop skrev den 2023-12-18 22:45: Strange rewriting mechanism, but this kind of volume should be restricted from the o365 side, no? What about the usage of non-existant FQDN name in the MAIL FROM? what mta ? what port is used ? i use postfix with postscreen on port 25

Re: [mailop] o365 outbound senders.. Strange Failures sending .. widespread reports

2023-12-18 Thread Benny Pedersen via mailop
Michael Peddemors via mailop skrev den 2023-12-18 23:54: Maybe my original posting wasn't clear.. +1 You would see these in your inbound logs, coming from o365 via port 25/TLS... i have no logs of this here, so it can be differing on diff servers Just real strange widespread occurrence th

Re: [mailop] ECDSA DKIM validation?

2023-12-21 Thread Benny Pedersen via mailop
John R Levine via mailop skrev den 2023-12-21 11:44: As I've said several times, unless there is a cryptographic problem with RSA, there is no reason to *use* any other kind of signature. analogy to no need to have ipv6 when ipv4 works :) ___ mailop

Re: [mailop] BIMI boycott? Lookup tool, why we publish BIMI anyway, and intellectual property law considerations

2024-01-11 Thread Benny Pedersen via mailop
Randolf Richardson, Postmaster via mailop skrev den 2024-01-11 19:52: I might have missed something, but wouldn't that be a phisher's wet dream? Indeed, and because the BIMI record references a URI to load the logo from, so the scammers (spammers, phishers, malware/virus distributors, e

Re: [mailop] BIMI and multiple hops

2024-01-13 Thread Benny Pedersen via mailop
Andrew C Aitchison via mailop skrev den 2024-01-13 07:16: [ Wearing an MTA developer's hat. ] +1 I see that an MTA is supposed to remove existing Authentication-Results and BIMI-Indicator headers, and that generally an MUA may use these headers if present. where is this dokumented ? I pre

Re: [mailop] Spamhaus contact?

2024-01-19 Thread Benny Pedersen via mailop
Atro Tossavainen via mailop skrev den 2024-01-19 10:48: Since most RBLs exchange data, Source? sign up to dnswl.org, in that stage blacklists are checked, if accepted, blacklists is then ignored :) i dont know if others doing this, i really dont care __

Re: [mailop] DMARC on srs forwarding domains?

2024-02-02 Thread Benny Pedersen via mailop
Bill Cole via mailop skrev den 2024-02-03 02:01: Telling the next hops that they need to parse ARC and trust your system instead of just checking SPF is a choice that one can make, yes. there is nothing to tell, its trustness or not maillist arc trustness: yes direct to mx trustness: no in d

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-09 Thread Benny Pedersen via mailop
Philip Paeps via mailop skrev den 2024-02-09 10:56: You are not wrong. +1, maybe #metoo But you should treat ARC signatures in exactly the same way you treat DKIM signatures no not at all unless world like to step on own foots : as one signal. what ever this means Blindly trusting AR

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-10 Thread Benny Pedersen via mailop
Sebastian Nielsen via mailop skrev den 2024-02-10 05:11: And also as a side note, this list server (mailop) also does sender rewriting to From: mailop@mailop.org to prevent SPF and DMARC from tripping on list mail. So its obvious it’s the right way to do it. Same have the list "Exim-Users" begu

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-10 Thread Benny Pedersen via mailop
John Levine via mailop skrev den 2024-02-10 05:22: It appears that Sebastian Nielsen via mailop said: just because SPF and DMARC are so badly designed that they can't handle it doesnt make it "forging" anything. It isn't badly designed. Forwarding a email, is the equvalient of, when you recei

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-10 Thread Benny Pedersen via mailop
John Levine via mailop skrev den 2024-02-10 05:25: PS: Perhaps this list needs a FAQ of Well Known Bad Ideas so we can stop having this argument over and over. or make mailman patch that stops mailman from breaking dkim ___ mailop mailing list mai

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-11 Thread Benny Pedersen via mailop
Sebastian Nielsen via mailop skrev den 2024-02-11 18:33: It’s a matter of a simple configuration. checked spf for big domains: gmail.com 328,960 individual IPv4 addresses outlook.com 506,999 individual IPv4 addresses (65.55.238.128/26 listed twice in spf) hotmail.com 148,087 individual IPv4

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-12 Thread Benny Pedersen via mailop
Jaroslaw Rafa via mailop skrev den 2024-02-12 11:34: Dnia 12.02.2024 o godz. 01:36:09 Benny Pedersen via mailop pisze: if spf should be pr email addresses, thay could add ipv6 pr sender email :=) and have ipv4 with nullMX or simply remove ipv4 in mx, will it ever happen ? Yeah, use only IPv6

Re: [mailop] DMARC on srs forwarding domains?

2024-02-13 Thread Benny Pedersen via mailop
Matus UHLAR - fantomas via mailop skrev den 2024-02-13 16:00: I still think implementing SPF and SRS gives more value than ARC. oh dear, if you really need both spf and srs, your problem is more deep then linux begin trust maillists domains in arc, get better stable results on spf dkim arc

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-13 Thread Benny Pedersen via mailop
Byunghee HWANG via mailop skrev den 2024-02-14 01:00: I really strongly agree with this opinion. That's why I wish people in the world didn't use SPF. SPF is a serious obstacle when forwarding. spf is not designed for forwarding, stop forwarding, problem solved dmarc need spf to find aligned

Re: [mailop] Is forwarding to Gmail basically dead?

2024-02-14 Thread Benny Pedersen via mailop
Byunghee HWANG via mailop skrev den 2024-02-14 05:45: spf is not designed for forwarding, stop forwarding, problem solved Yes, you are right! good then :=) And if Google stops email service, i will also stop forwarding. https://wiki.debian.org/PostfixAndSASL see section SASL authenticat

Re: [mailop] Anybody having trouble with gmail not recognizing valid SPF records?

2024-02-15 Thread Benny Pedersen via mailop
Eric J Esslinger via mailop skrev den 2024-02-15 19:17: My SPF records have been valid for... oh 10 years or so, and haven't changed, but the last two days I'm getting intermittent bounces sending to gmail.com addresses from our customer domain. I've sent a couple of emails to postmas...@gmail.c

Re: [mailop] One click unsubscribe in mailing list messages

2024-02-25 Thread Benny Pedersen via mailop
Ken O'Driscoll via mailop skrev den 2024-02-25 21:38: Outlook has supported list-unsubscribe for at least a year, if not longer. But, it's an add-on you need to proactively install so... waiting for roundcube, since squirrelmail have had this as a plugin, just not roundcube, hmp :=)

Re: [mailop] Gmail.com SPF false negatives?

2024-02-28 Thread Benny Pedersen via mailop
Rob Nagler via mailop skrev den 2024-02-27 23:30: gmail.com [1] started failing messages from domains which are correctly setup for SPF (and have been for some years): 550-5.7.26 Gmail requires all senders to authenticate with either SPF or DKIM. 550-5.7.26 550-5.7.26 Authentication result

Re: [mailop] Gmail.com SPF false negatives?

2024-02-28 Thread Benny Pedersen via mailop
L. Mark Stone via mailop skrev den 2024-02-27 23:52: I believe you need a DMARC record... does this fix spf fails ? ___ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop

Re: [mailop] Gmail.com SPF false negatives?

2024-02-28 Thread Benny Pedersen via mailop
Jarland Donnell via mailop skrev den 2024-02-27 23:54: Is it plausible that Google had a temporary issue reaching your DNS servers? impossible is possible ? ___ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop

Re: [mailop] Gmail.com SPF false negatives?

2024-02-28 Thread Benny Pedersen via mailop
Matt Palmer via mailop skrev den 2024-02-27 23:59: Any chance of a transient/intermittent DNS failure on nagler.me? On occasion I've seen spurious SPF/DKIM failures when there's been a flaky DNS server in the mix. first fix spf to be valid for the sender domain in question, as it is now it

Re: [mailop] Gmail.com SPF false negatives?

2024-02-28 Thread Benny Pedersen via mailop
Kai Bojens via mailop skrev den 2024-02-28 08:35: Am 27.02.24 um 23:30 schrieb Rob Nagler via mailop: $ dig +short txt nagler.me "v=spf1 a mx ip4:139.177.203.52 include:_spf.google.com -all" A TTL of just 300 seconds is way too short IMHO. If anythi

Re: [mailop] tiscali.it/tiscalinet.it reject RFC821 FROM domain as a CNAME because "domain does not have neither a valid MX or A record"

2024-02-29 Thread Benny Pedersen via mailop
Stefano Bagnara via mailop skrev den 2024-02-29 11:09: I think I wrote here too early: from further investigation seems like the issue has gone and now those emails are not refused anymore. https://totaluptime.com/kb/cname-and-mx-for-the-same-host-name/ dont use cname for email or even mx an

Re: [mailop] PTR check mechanism / gmail

2024-03-03 Thread Benny Pedersen via mailop
Gareth Evans via mailop skrev den 2024-03-04 01:17: Received: from atlas.bondproducts.com (unknown [23.24.6.165]) by mx6.messagingengine.com (Postfix) with ESMTP id ... https://multirbl.valli.org/fcrdns-test/23.24.6.165.html one red means fails [...] Received: from users.shellworld

Re: [mailop] Love how people use SPF records.. Just for a chuckle..

2024-03-12 Thread Benny Pedersen via mailop
Michael Peddemors via mailop skrev den 2024-03-11 23:54: host -t TXT save.ca ... so.. basically hard block everything except 1/2 the internet.. the other half is "v=spf1 +all" ? :) if one likes no maintained ranges 225 netblocks are authorized 2,583,457 individual IPv4 addresses i did not

Re: [mailop] Google unsolicited mail rejected with 421

2024-03-16 Thread Benny Pedersen via mailop
Marco Moock via mailop skrev den 2024-03-16 12:46: Am 14.03.2024 um 10:28:13 Uhr schrieb Julian Bradfield via mailop: Their latest daftness (latest in my noticing it, anyway) is rate-limiting on the basis of too many recipients for a single message-id, where "too many" varies from 6 to 30. You'

Re: [mailop] Google unsolicited mail rejected with 421

2024-03-17 Thread Benny Pedersen via mailop
Jaroslaw Rafa via mailop skrev den 2024-03-17 13:38: Dnia 16.03.2024 o godz. 13:08:52 Benny Pedersen via mailop pisze: bingo its why its tempfailed, gmail should redesign how to handle maillists where message-id can come to inbound on gmail, should not count on message-id abuse counts Well

Re: [mailop] 172.245.92.88 (HostPapa / Colocrossing) phishing source - not correctly registered @ ARIN ?

2024-03-19 Thread Benny Pedersen via mailop
Benoit Panizzon via mailop skrev den 2024-03-19 09:03: In the meantime, it scores a decent number of spam points due to being in various blacklists: [172.245.92.88 listed in dnsrbl.swinog.ch] [172.245.92.88 ] [Bloc

Re: [mailop] Anyone from Google - Sudden Gmail bounces??

2024-03-31 Thread Benny Pedersen via mailop
Julian Bradfield via mailop skrev den 2024-03-31 17:35: It also thinks 41.212.32.14 has been very spammy in recent months. oh https://multirbl.valli.org/lookup/41.212.32.14.html dont send email from pbl listed ips OP should ask isp for a static ip __

Re: [mailop] Anyone from Google - Sudden Gmail bounces??

2024-03-31 Thread Benny Pedersen via mailop
Odhiambo Washington via mailop skrev den 2024-03-31 21:16: Not sure I understand you. but 41.212.32.14 is a static IP. I don't thing the /24 has any dynamic segment. https://hetrixtools.com/blacklist-check/41.212.32.14 ___ mailop mailing list mailop@

Re: [mailop] Are there other comparable services like spamcop.net / spamhaus.org?

2024-04-03 Thread Benny Pedersen via mailop
Aban Dokht via mailop skrev den 2024-04-03 10:41: Hi list, are there other comparable services like spamcop.net or spamhaus.org worth submitting SPAM samples to? Currently we are reporting SPAM samples semi automated to those to services and would like to know, if the are other ones worth to

Re: [mailop] [External] Re: Off-Topic - VMWare ESXI 7.0

2024-04-16 Thread Benny Pedersen via mailop
Kevin A. McGrail via mailop skrev den 2024-04-16 16:06: As the original poster, I wanted to say thanks.  Based on the dozen or so replies so far, I clearly struck a nerve.  I'm reading all the replies with great interest. you are welcome to use linode.com for wm like i do, do dns not serve we

Re: [mailop] Problems with invoices.premierinn.de and postmas...@premierinn.de

2024-04-25 Thread Benny Pedersen via mailop
John Levine via mailop skrev den 2024-04-25 18:33: It appears that Andrew C Aitchison via mailop said: because the return path would not work. $ host invoices.premierinn.de It has an SPF record. What's the problem? spf have no rules to be enforced, while rfc 7505 is in all mta, spf po

Re: [mailop] Problems with invoices.premierinn.de and postmas...@premierinn.de

2024-04-26 Thread Benny Pedersen via mailop
Jaroslaw Rafa via mailop skrev den 2024-04-26 11:25: Dnia 25.04.2024 o godz. 19:12:34 John Levine via mailop pisze: No, really it's not, and I should know. In any event, I can see how people might reject mail from a domain that has a TXT record but no A or MX, but it seems pretty marginal. I'

Re: [mailop] Gmail has a thing about dots

2024-05-02 Thread Benny Pedersen via mailop
John Levine via mailop skrev den 2024-05-02 21:02: Return-Path: <"a..b"@m.jl.ly> less spammy without " rfc or not but imho < and > is required in spamassassin From:addr "..." is spammy, while From:Name needs " i noted you use rblsmtpd. with does imho not support tls okay for testing :)

Re: [mailop] Doesn't ARC substitute DKIM at Gmail inbound?

2024-05-05 Thread Benny Pedersen via mailop
Andrew C Aitchison via mailop skrev den 2024-05-05 18:49: On Sat, 4 May 2024, Alessandro Vesely via mailop wrote: The last URL in the response says something about ARC: ARC checks the previous authentication status of forwarded messages. If a forwarded message passes SPF or DKIM authen

Re: [mailop] Doesn't ARC substitute DKIM at Gmail inbound?

2024-05-05 Thread Benny Pedersen via mailop
Dave Crocker via mailop skrev den 2024-05-05 19:21: But that certainly is a common misconception about DKIM. not even if users have there own dkim selector ? ___ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop

[mailop] eu tld have one ipv6 addr not listen to udp

2024-05-07 Thread Benny Pedersen via mailop
eu zone: The server(s) were not responsive to queries over UDP. (2001:978:2:1::93:2) why is it not resolved ? ___ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop

Re: [mailop] eu tld have one ipv6 addr not listen to udp

2024-05-07 Thread Benny Pedersen via mailop
Marco Moock via mailop skrev den 2024-05-07 20:24: Am 07.05.2024 um 20:12:24 Uhr schrieb Benny Pedersen via mailop: eu zone: The server(s) were not responsive to queries over UDP. (2001:978:2:1::93:2) why is it not resolved ? Works for me, via TCP and UDP. Maybe was a temporary issue. ah

Re: [mailop] (Mis)use of DKIMs length tag and its impact on DMARC and BIMI

2024-05-18 Thread Benny Pedersen via mailop
Sebastian Nielsen via mailop skrev den 2024-05-18 20:14: Yeah, for mailing lists the rewrite + resign method is better, like this mailing list does, rewrites everything to mailop@mailop.org And then resigns the mail with their own SPF and DKIM. with this maillist does not do Authentication-Res

Re: [mailop] TLS inbound to comcast.net

2024-05-20 Thread Benny Pedersen via mailop
Brotman, Alex via mailop skrev den 2024-05-20 15:09: Hey folks, Over the next few weeks, we're going to be disabling TLSv1/v1.1 inbound to our platform. Most senders are already using TLSv1.2/v1.3, so I don't think this will be an issue. However, keep in mind that if you're not already usin

Re: [mailop] TLS inbound to comcast.net

2024-05-21 Thread Benny Pedersen via mailop
Serhii via mailop skrev den 2024-05-21 14:59: https://datatracker.ietf.org/doc/rfc8996/ yet its still possible to enable sslv2, sslv3 on openssl :) i dont think openssl will remove support for any tls versions yet ___ mailop mailing list mailop@ma

Re: [mailop] TLS inbound to comcast.net

2024-05-21 Thread Benny Pedersen via mailop
Suresh Ramasubramanian via mailop skrev den 2024-05-21 15:18: Yeah Benny – if you’re running 16 year old code and certificates that you’re still on TLS v1 or 1.1, it is time to upgrade, asap. What you have is not much better or worse than sending it en clair anyway. tls is self adaptive, so no

Re: [mailop] [External] Does Google not accept bounce emails anymore?

2024-06-01 Thread Benny Pedersen via mailop
Brandon Long via mailop skrev den 2024-06-01 03:22: There's also nothing to prevent you from DKIM signing your bounce messages. null sender is no domain, so it can't be dkim signed but header from is not null sender for bounces so this can be dkim signed just funny since its local mail anywa

[mailop] t-online.de spam

2024-06-18 Thread Benny Pedersen via mailop
Received: from mailout11.t-online.de (mailout11.t-online.de [194.25.134.85]) by mx.junc.eu (Postfix) with ESMTPS id 22CFA83FCF for ; Tue, 18 Jun 2024 00:45:39 +0200 (CEST) Received: from fwd80.aul.t-online.de (fwd80.aul.t-online.de [10.223.144.106]) by mailout11.t-online

Re: [mailop] how to stop this spam

2024-06-20 Thread Benny Pedersen via mailop
Jeff Pang via mailop skrev den 2024-06-20 04:13: Hello Recently i got a lot of spams like this one: https://cloud.hostcache.com/spam.eml They have two features: 1. arabic language 2. from google groups (though i never joined those groups) how can i stop them effectively? (block arabic and goog

Re: [mailop] how to stop this spam

2024-06-20 Thread Benny Pedersen via mailop
Jeff Pang via mailop skrev den 2024-06-20 04:13: Recently i got a lot of spams like this one: https://cloud.hostcache.com/spam.eml Content Domains: gmail.com google.com googlegroups.com Content analysis details: (13.6 points, 5.0 required) pts rule name description

Re: [mailop] too many bad IP blocked

2024-06-21 Thread Benny Pedersen via mailop
Matus UHLAR - fantomas via mailop skrev den 2024-06-21 17:27: But I feel like this discussion has been resolved already. unless :) i have solve to just know my custummers asn's, and only let there isp asn be allowed, this saves much more lines in shorewall then if i did shorewall blacklisti

mailop@mailop.org

2024-06-24 Thread Benny Pedersen via mailop
Umut Alemdar via mailop skrev den 2024-06-24 15:40: Since the beginning of June, we have been experiencing delivery issues with AT&T. Despite our attempts to resolve this by contacting support, we have not received any feedback or resolution. Could anyone from AT&T contact me off list, please?

mailop@mailop.org

2024-06-24 Thread Benny Pedersen via mailop
Marco Moock via mailop skrev den 2024-06-24 16:46: Am 24.06.2024 um 16:06:32 Uhr schrieb Benny Pedersen via mailop: that sayed We can’t connect to the server at list.mailop.org. Works for me. Please use traceroute to find out if that is a problem at your side. it was my slow unifi router

Re: [mailop] Why an SPF hard bounce on ~all ?

2024-06-27 Thread Benny Pedersen via mailop
Paul Smith via mailop skrev den 2024-06-27 18:17: That would be an SPF fail, but the sender domains are ~all Why the hard bounce? It's entirely up to the receiver what they do with a message. If they've decided to hard fail messages with soft SPF fails, that's their choice... permfails is n

Re: [mailop] Request: UTF-8 email address?

2024-06-27 Thread Benny Pedersen via mailop
Christine Borgia via mailop skrev den 2024-06-27 21:55: Does anyone here have a UTF-8 email address you'd let me send some test messages to? so you know any dns servers that support utf-8 ? dns servers that set the glue record must support utf-8, not just idn, what will happend if both idn an

Re: [mailop] envelope or header address?

2024-07-05 Thread Benny Pedersen via mailop
Jeff Pang via mailop skrev den 2024-07-05 13:45: When an user requests to join mailing list, which address should we take? envelope The envelope address, or the header From address? from is not smtp In the mailop life, I saw many sender addresses in header are different than the envelope

Re: [mailop] safe-mail.net

2024-07-12 Thread Benny Pedersen via mailop
Bill Cole via mailop skrev den 2024-07-12 16:13: Any SMTP client which does not fall back to the A record when no MX records exists is fundamentally broken. and here its more fun when domain is nullMX it would be fail to failback to A/ :) sendmail -f yourmailaddrhere -bv f...@example.or

Re: [mailop] [EXTERNAL] Re: (Mis)use of DKIM's length tag and it's impact on DMARC and BIMI

2024-08-11 Thread Benny Pedersen via mailop
Michael Orlitzky via mailop skrev den 2024-08-10 16:03: (the other, simpler sample config files don't mention the body length option at all). same problem here https://certitude.consulting/blog/en/o365-anti-phishing-measures/ include another origin content into users browser, then all conte

Re: [mailop] query for black listed domains

2024-09-08 Thread Benny Pedersen via mailop
On 8. september 2024 14.09.51 Corey H via mailop https://blacklistalert.org/ Only ipv4 and domain name, reload fails if client ip is ipv6 ___ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop

Re: [mailop] mailop Digest, Vol 27, Issue 21

2022-10-19 Thread Benny Pedersen via mailop
mailop-requ...@mailop.org skrev den 2022-10-19 05:11: Including the resent-* headers is interesting to me, seeing as how they aren't included in the message. I don't know if this was an intentional over-sign or over zealous configuration. imho same problem as i reported here https://gitlab

Re: [mailop] mailop Digest, Vol 27, Issue 27

2022-10-19 Thread Benny Pedersen via mailop
mailop-requ...@mailop.org skrev den 2022-10-19 18:56: They clearly have a default 'block' policy. The reject message is presented immediately upon connection. $ telnet mx00.t-online.de 25 Trying 194.25.134.8... Connected to mx00.t-online.de. Escape character is '^]'. 554 IP=66.254.66.70 - A pro

Re: [mailop] Industry standards

2022-10-20 Thread Benny Pedersen via mailop
Kai 'wusel' Siering via mailop skrev den 2022-10-21 05:23: Am 21.10.22 um 04:59 schrieb Hal Murray via mailop: That's the industry standard: block after abuse. Instead, t-online.de uses block-and-maybe-unblock-after-contact. This is not how email is supposed to work. I thought the standard wa

Re: [mailop] Anyone else seeing email backed up to Microsoft -- only IPv6

2022-10-25 Thread Benny Pedersen via mailop
Frank Bulk via mailop skrev den 2022-10-25 16:40: They're all IPv6 hosts, though it's possibly our MTA prefers that when communicating to Microsoft. https://support.xbox.com/en-US/help/hardware-network/connect-network/ipv6-on-xbox-one :-) glibc have ipv6 preferelble /etc/gai.conf can change

Re: [mailop] [EXTERNAL] Re: Anyone else seeing email backed up to Microsoft -- only IPv6

2022-10-28 Thread Benny Pedersen via mailop
Brotman, Alex via mailop skrev den 2022-10-28 17:22: These are attempts from our logs (we use IPv6 for inbound/outbound) 2a01:111:f400:7d00::33 2a01:111:f400:7e1a::33 2a01:111:f400:7e1b::33 2a01:111:f400:7e88::33 2a01:111:f400:7e89::33 2a01:111:f400:7e8a::33 2a01:111:f400:7e8b::33 2a01:111

Re: [mailop] [EXTERNAL] Recommendations for host with good IP reputation or use external SMTP?

2022-10-30 Thread Benny Pedersen via mailop
Ian Evans via mailop skrev den 2022-10-31 01:51: But going back to my original question: are there far better places to host a postfix server than Digitalocean? https://www.irccloud.com/pastebin/f9H1aoy5/pregreet%20bots ask custommer support at DO to help there custommer not abuse a ip that

Re: [mailop] [Admin] Changes to list behaviour, members spam filters etc

2022-11-22 Thread Benny Pedersen via mailop
Alessandro Vesely via mailop skrev den 2022-11-22 10:54: On Tue 22/Nov/2022 09:55:17 +0100 Sebastian Nielsen via mailop wrote: The message you wrote had: Return-Path: Authentication-Results: wmail.tana.it; spf=pass smtp.mailfrom=mailop.org; dkim=fail (signature verification failed) heade

Re: [mailop] Giant Yahoo thread headers

2022-11-29 Thread Benny Pedersen via mailop
WIlliam Fisher via mailop skrev den 2022-11-29 23:11: What are other folks doing with the massive thread headers from yahoo? masive in what way ? long lines ? or many long lines ? fixing it would break threads imho ___ mailop mailing list mailop@

Re: [mailop] verizon email-to-text gateway mail deferred evening and night

2023-01-08 Thread Benny Pedersen via mailop
Brandon Applegate via mailop skrev den 2023-01-06 22:16: I’ve just hit this recently too. There are a bunch of threads on the official VZW forums. Of course with all due respect to the VZW employees that actually try and reply in there - they have 0 clue what this even is… oh dear, lets proxy

Re: [mailop] new exploit?

2023-01-14 Thread Benny Pedersen via mailop
Mary via mailop skrev den 2023-01-14 16:33: Thank you, I'll take a closer look, because Shellshock implies that somehow the SMTPD executes a bash script, which I find highly unlikely. That is why I thought they are trying to exploit something further down the pipeline (Logstash, Prometheus, etc).

Re: [mailop] gmail putting most messages into Spam

2023-01-18 Thread Benny Pedersen via mailop
Laura Atkins via mailop skrev den 2023-01-18 11:49: Your SPF record is invalid. ccs.covici.com [4]. 180 IN TXT "v=spf1ainclude:covici-com.spf-a.smtp25.com [5] include:covici-com.spf-b.smtp25.com [6] include:covici-com.spf-c.smtp25.com [7] include: ccs.covici.com [4] include: debian-2.covici.com

Re: [mailop] gmail putting most messages into Spam

2023-01-18 Thread Benny Pedersen via mailop
Slavko via mailop skrev den 2023-01-18 17:57: Dňa 18. januára 2023 16:44:50 UTC používateľ John Covici via mailop napísal: So, what can I use to begin and end the record? Do I need any delimiter character like Mark gave me? I will suggest you to start to learn SPF record syntax, either readi

Re: [mailop] gmail putting most messages into Spam

2023-01-18 Thread Benny Pedersen via mailop
John Levine via mailop skrev den 2023-01-18 23:00: It appears that Jaroslaw Rafa via mailop said: Dnia 18.01.2023 o godz. 07:39:48 Mark Alley via mailop pisze: Woops, sorry, wrong link pasted. That's the sender guidelines - while still helpful, was not what I was trying to send. The eu.org d

Re: [mailop] Anyone from Spamhaus?

2023-01-19 Thread Benny Pedersen via mailop
Mark Fletcher via mailop skrev den 2023-01-20 05:20: Hi All, Over the past couple of days, the two servers that send email for groups.io [1], 66.175.222.12 and 66.175.222.108, have been listed on the Spamhaus CSS blacklist a couple times each. We're an email groups hosting service, like Google G

Re: [mailop] Anyone from Spamhaus?

2023-01-19 Thread Benny Pedersen via mailop
Simon Wilson via mailop skrev den 2023-01-20 05:53: X-Spam-Status: Yes, score=102.999 tagged_above=-999 required=6.2 tests=[RCVD_IN_HOSTKARMA_W=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_LASTEXTERNAL=8, SHORTCIRCUIT=100] autolearn=disabled turn of shortcircuit or change the score of it __

Re: [mailop] Question of SPF record

2023-02-05 Thread Benny Pedersen via mailop
H via mailop skrev den 2023-02-06 01:13: I have a domain with multiple email addresses hosted by Ionos. I have found that outgoing emails can come from a range of Ionos email IPs. I have created a TXT record for my domain containing one IP4 address but outgoing emails seem to be sent from differ

Re: [mailop] [External] Re: Question of SPF record

2023-02-05 Thread Benny Pedersen via mailop
Kevin A. McGrail via mailop skrev den 2023-02-06 02:34: To add onto this, rarely will you want to divine the IP addresses of your service providers. Contact them for their include record. From searching the interweb, it seems these are likely what you want: _ _include:_spf.perfora.net include:

Re: [mailop] DKIM record IONOS

2023-02-10 Thread Benny Pedersen via mailop
H via mailop skrev den 2023-02-10 01:41: If anyone could set me straight, it would be greatly appreciated. never use cname for content that is to be dnssec, even if your domain is not dnssec yet, it should not be used, opendkim use dnssec, but many testers seem to not do the validate dnssec,

Re: [mailop] How to get Google to set a null MX for gmail.co ?

2023-02-16 Thread Benny Pedersen via mailop
Matthew Pounsett via mailop skrev den 2023-02-16 20:03: On Thu, Feb 16, 2023 at 12:03 PM Tom Perrine via mailop wrote: Any idea who/how to suggest to Google that a null MX would be appreciated? I spoke to someone who may be able to get it done at the DNS-OARC workshop, which is going on toda

Re: [mailop] How to get Google to set a null MX for gmail.co ?

2023-02-16 Thread Benny Pedersen via mailop
Tom Perrine via mailop skrev den 2023-02-16 20:21: Perfect, thanks! I bet they have an entire slew of those sorts of domains. I guess I’m not the only person who thinks it’s a good idea and I’m not a complete moron today (as opposed to other days!) https://dmarcian.com/spf-survey/?domain=gmai

Re: [mailop] How to get Google to set a null MX for gmail.co ?

2023-02-16 Thread Benny Pedersen via mailop
Alex Irimia via mailop skrev den 2023-02-16 21:05: If your MTA allows you to, maybe you could overwrite gmail.co [2] to gmail.com [1] and actually reach the intended recipient of the fat-fingered sender? small fingers can do errors aswell please dont suggest this _

Re: [mailop] Should mailing list messages be DKIM signed? (ARC / DKIM)

2023-02-17 Thread Benny Pedersen via mailop
Patrick Ben Koetter via mailop skrev den 2023-02-17 17:07: Greetings, I'm about to setup a new mailing list server. It will use Mailman 3, which is able to add ARC signatures to incoming messages. The lists will also rewrite the From:-header and to match the lists name and domain. I'm unsure

Re: [mailop] Should mailing list messages be DKIM signed? (ARC / DKIM)

2023-02-17 Thread Benny Pedersen via mailop
Tobias Herkula via mailop skrev den 2023-02-17 17:56: Only adding ARC without your own DKIM will make it harder for a lot of people, that are not yet ready to process ARC signatures. in ARC terms it always ORIGINATE on nexthub, but this rule is not for nexthub with DKIM sadly so many mailli

Re: [mailop] Should mailing list messages be DKIM signed? (ARC / DKIM)

2023-02-18 Thread Benny Pedersen via mailop
Alessandro Vesely via mailop skrev den 2023-02-18 13:49: Mailman cannot verify SPF. envelope sender changes on nexthop, no ? so why is it important ? if you meant not to accept spf fail posters, this is still in mta stage to be enforced if wanted not to accept it ___

Re: [mailop] Should mailing list messages be DKIM signed? (ARC / DKIM)

2023-02-20 Thread Benny Pedersen via mailop
Alessandro Vesely via mailop skrev den 2023-02-20 08:47: The point of ARC is to report authentication results. A post having only spf=pass becomes unauthenticated after the first hop. inccorect, nexthop can use spf aswell, or not Right. Ditto for DMARC rejects/ quarantine, which I don't th

Re: [mailop] Gmail blocking of good customer

2023-02-24 Thread Benny Pedersen via mailop
Christine Borgia via mailop skrev den 2023-02-24 17:17: 421 4.7.0 [149.72.90.158 15] Our system has detected that this If someone could reach out to me, I'd greatly appreciate it. I'm not sure what to advise this customer except to say that email may not work for their business model. note

  1   2   >