Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-28-2009, 07:30 AM
Junior Member
 
Posts: 7
Default Mail rejections

Hi


We are using Zimbra open soure 4.0.4 server with RBL 's like CBL and spahouse, it was working fine all these days , recently SSL certificates got expired , then the zimbra mail server started rejecting each and every external mails from yaho , google .... ( not from internal local users mails) because of RBL sites like cbl and spamhouse , though all those domains or IPs were not present in RBL sites , then I removed all RBL MTA restriction and recreated the SSL certificates , Now we are able to receive all mails ,


But If I update RBL restrictions in postfix/main.cf or through zmprov command it will start rejecting all external mails even if the mail IDs , domains ,and IP's are valid and clean .


Please let me know how to fix this.
thanks in advance .

Harish
__________________
Harish K R
Reply With Quote
  #2 (permalink)  
Old 05-29-2009, 01:18 AM
Moderator
 
Posts: 5,806
Default

Welcome to the forums

Would you post a extract from /var/log/zimbra.log so we can see what Postfix and Amavis is doing please.

You should really plan a upgrade going by your version number
__________________
SplatNIX IT Services :: Innovation through Collaboration™


http://www.messagefortress.com
Reply With Quote
  #3 (permalink)  
Old 06-08-2009, 03:07 AM
Junior Member
 
Posts: 7
Red face

Sorry for the late replay I was not keeping well

Hi

I get below error pasted from my zimbra.log file .



Jun 8 13:00:34 mydomain postfix/smtpd[3028]: NOQUEUE: reject: RCPT from web51510.mail.re2.yahoo.com[206.190.38.202]: 554 Service unavailable; Client host [206.190.38.202] blocked using dnsbl.njabl.org; from=<hari_future@yahoo.com> to=<harishkr@mydomain.com> proto=SMTP helo=<web51510.mail.re2.yahoo.com>
Jun 8 13:00:35 s7solutions postfix/smtpd[3028]: disconnect from web51510.mail.re2.yahoo. .com[206.190.38.202]
__________________
Harish K R
Reply With Quote
  #4 (permalink)  
Old 06-08-2009, 03:19 AM
Moderator
 
Posts: 5,806
Default

Well that Y! server has got itself blacklist in dnsbl.njabl.org. Personally I would drop using that RBL.
__________________
SplatNIX IT Services :: Innovation through Collaboration™


http://www.messagefortress.com
Reply With Quote
  #5 (permalink)  
Old 06-08-2009, 06:52 AM
Junior Member
 
Posts: 7
Default

HI
Though this IP is not present in dnsbl.njabl.org, still it is rejecting
njabl.org

This behavior started after ssl certification expiry , we were unable to use zmprov command then , once we recreated ssl certificates we were able to use zmprov command but this mail rejection problem continued because of RBL’s ,IF RBL reference is there mail server is rejecting all external mails, even though physically IP’s are not present in any RBL database’s .
But zimbra log says blocked using dnsbl.njabl.org strange .


Please help me on this

Harish
__________________
Harish K R
Reply With Quote
  #6 (permalink)  
Old 06-08-2009, 12:59 PM
Elite Member
 
Posts: 369
Default

RBL 's like dnsbl.njabl.org , i doubt are updated on regular basis. I would recommand not using many RBL's and one which is globally adopted is zen.spamhaus.org.
Reply With Quote
  #7 (permalink)  
Old 06-08-2009, 01:04 PM
Moderator
 
Posts: 5,806
Default

Or add it into SA and use scoring instead.
__________________
SplatNIX IT Services :: Innovation through Collaboration™


http://www.messagefortress.com
Reply With Quote
  #8 (permalink)  
Old 06-09-2009, 02:41 AM
Junior Member
 
Posts: 7
Default

How can I do this plase let men know .

adding into SA

harish
__________________
Harish K R
Reply With Quote
  #9 (permalink)  
Old 06-09-2009, 02:44 AM
Moderator
 
Posts: 5,806
Default

A number of RBLs are already checked in SA ... Go into /opt/zimbra/conf/spamassassin and check the rules. I think it is something like 20_rblchecks.cf ... You could always grep for the domain name eg. spamhaus.
__________________
SplatNIX IT Services :: Innovation through Collaboration™


http://www.messagefortress.com
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0