Hello,
I've been having spam come in lately from just IP addresses (not reporting any hostname and no reverse lookup entries).
The zimbra.log shows entries such as this:
I've replaced the email address with just email@domainname. I left the incoming IP as it is.Code:Feb 2 18:05:57 mail postfix/smtpd[2716]: connect from unknown[109.94.16.70] Feb 2 18:06:00 mail amavis[7072]: (07072-18) Checking: NqysLox9Q3J2 [109.94.16.70] <email@domainname> -> <email@domainname> Feb 2 18:06:00 mail amavis[7072]: (07072-18) Passed BAD-HEADER, [109.94.16.70][109.94.16.70] <email@domainname> -> <email@domainname>, quarantine: badh-NqysLox9Q3J2, mail_id: NqysLox9Q3J2, Hits: -, size: 697, queued_as: 658EE685401A, 628 ms
Zimbra is configured so it requires a FQDN and reverse DNS lookup. It doesn't seem to be taking that into account as it allows the email attempt to go through.
Any hints of what I would need to change to prevent these from going through?
Thanks.


LinkBack URL
About LinkBacks


