Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack (1) Thread Tools Display Modes
  1 links from elsewhere to this Post. Click to view. #1 (permalink)  
Old 10-09-2006, 08:25 AM
Junior Member
 
Posts: 5
Default Blacklisted after testdriving Zimbra.

Hello all.

First of all, excuse me if im posting this to wrong forum but here's my scenario:

I have a fully patched FC5 server running in the office - all unnecessery services removed/stoped and only ssh listening to remote connections. I installed zimbra to a this server last week, added suitable MX record (IP only) to a valid dns (hostname does not have reverse name) and installed zimbra.

Everything was working fine, i sent out few test emails, used abuse.net's relay testing and it reported the host to be fine (also checked relaying manually using telnet - just to be sure) . I also checked postfix configuration files manually as i have experience on running/maintaining it myself and all things looked nice.

I gave my ok and passed the box to the company that is checking out zimbra and some days later they sent me email that they got email from their ISP saying that a another isp has blacklisted the ip for sending out spam.

I checked the postfix logfiles and found this:

Quote:
Oct 4 15:19:59 localhost postfix/smtp[2804]: 06B7251C610: to=<xxx.yyy@xyz.fi>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=27780-02, from MTA([127.0.0.1]:10025): 250 Ok: queued as D546451C611)
Oct 4 15:19:59 localhost postfix/qmgr[27718]: 06B7251C610: removed
Oct 4 15:20:00 localhost postfix/smtp[2831]: D546451C611: to=<xxx.yyy@xyz.fi>, relay=mta.inet.fi[81.228.11.141], delay=1, status=bounced (host mta.inet.fi[81.228.11.141] said: 550 mail not accepted from blacklisted IP address [X.Y.Z.D] (in reply to MAIL FROM command))
Oct 4 15:20:00 localhost postfix/cleanup[2803]: 6D9C851C613: message-id=<20061004122000.6D9C851C613@localhost.localdoma in>
Oct 4 15:20:00 localhost postfix/qmgr[27718]: 6D9C851C613: from=<>, size=3321, nrcpt=1 (queue active)
Oct 4 15:20:00 localhost postfix/qmgr[27718]: D546451C611: removed
So, the first email set to this Finnish/Swedish ip was bounced due to company ip being blacklisted.

Im sure that this machine aint hacked. I've installed it some 30 minutes before installing zimbra - did the installation behind the firewall and upgraded the machine via apt-get from Funet (gpg key checks enabled ofcourse)..

Now these two isp's are treatning the company with possible police investigation and arent cooperative when asking for information about the aclaimed spam batch.

After receiving their threatmail, i shutdown zimbra (last saturday) - and our main isp is still not willing to give out any information. Weird. Since then i've been sniffing traffic, done checks on the machine, read the logs and alot of different things to find out why they where blacklisting that ip but found out nothing that would be considered as "spam flood"

Allthou, there are few issues that might be the reason. The box had "localhost.localdomain" still as its hostname and zimbra installation was broadcasting that as its hostname in smtp sessions. Also, some smtp servers might check if the mta sending the message is in the zonefile of the domain (might have not been there due to dns caching) and if the servername in smtp session matches the reverse of the sender's ip..

Anyone had similar problems ? Any suggestions ?

*EDIT*
Ps. People in the company have been sending emails to other isp's email boxes without getting blacklisted or banned.
Reply With Quote
  #2 (permalink)  
Old 10-09-2006, 10:22 AM
Member
 
Posts: 10
Default @localhost.localdomain

The problem is becuase zimbra is giving its name as @localhost.localdomain. I had exactly the same problem when testing with the VMware trial version of zimbra. I was immediatly blacklisted by http://www.us.sorbs.net/ Check the web site and have yourself un-blacklisted.
Reply With Quote
  #3 (permalink)  
Old 10-09-2006, 10:42 AM
Junior Member
 
Posts: 5
Default

I was suspecting that, thanks for verifying.
Reply With Quote
  #4 (permalink)  
Old 10-09-2006, 01:36 PM
Loyal Member
 
Posts: 91
Exclamation

I have a related question, my machine gives its name as machinename.machinename when the only domain in zimbra is not the same as the machine name, why would this be and where do I change it?
Reply With Quote
  #5 (permalink)  
Old 10-09-2006, 10:29 PM
Senior Member
 
Posts: 52
Default

how did you change this?

thanx christof
Reply With Quote
  #6 (permalink)  
Old 10-11-2006, 03:48 AM
Junior Member
 
Posts: 5
Default

If im not mistaken:

zmlocalconfig --edit zimbra_server_hostname=new.host.name

EDIT!

I was mistaken, check the FAQ in the wiki, there's few commands how to do it the right way.

Last edited by rasjani : 10-11-2006 at 04:15 AM.
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0