Results 1 to 6 of 6

Thread: RBL log message?

  1. #1
    vshah is offline Loyal Member
    Join Date
    Mar 2006
    Posts
    86
    Rep Power
    9

    Default RBL log message?

    We've setup RBLs in Zimbra and have for over a day now but I can't figure out what to look for in the /var/log/zimbra.log to see if the RBLs are working.

    [zimbra@mrmailman ~]$ zmprov -l gacf | grep zimbraMtaRestriction
    zimbraMtaRestriction: reject_invalid_hostname
    zimbraMtaRestriction: reject_non_fqdn_sender
    zimbraMtaRestriction: reject_rbl_client sbl.spamhaus.org
    zimbraMtaRestriction: reject_rbl_client bl.spamcop.net

    [zimbra@mrmailman ~]$ grep -i reject /var/log/zimbra.log

    gets no results. What's the default message logged for RBLS? Any other ideas?

  2. #2
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,569
    Rep Power
    57

    Default

    I don't use RBL lists but shouldn't it say something like "blocked using"?
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  3. #3
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,569
    Rep Power
    57

    Default

    You could use this (from a news group post):

    the following one-liner searches the log file for RBL rejections, then prints
    out the hostname[IP ADDR], From address, To address, and HELO hostname,
    separated by spaces:

    grep "reject:.*blocked using" /var/log/mail.log |
    perl -n -e 's/.*RCPT from ([^:]+):.*from=<([^>]+)> to=<([^>]+)> .*helo=<([^>]+)>/$1 $2 $3 $4/ && print'
    or this utility: dnsblcount
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  4. #4
    vshah is offline Loyal Member
    Join Date
    Mar 2006
    Posts
    86
    Rep Power
    9

    Default

    Thanks, Bill!

    I tried the regexp (actually tried some broader regexps too) and again got no results, which doesn't seem likely if the RBLs are working. I'll wait a few days and if there's no results again then I'll put in a support case for this, I guess.

  5. #5
    phoenix is online now Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,569
    Rep Power
    57

    Default

    Maybe there's just no hits on the RBL list or were you getting some spam that might have been blocked by the RBL before you activated them?
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  6. #6
    vshah is offline Loyal Member
    Join Date
    Mar 2006
    Posts
    86
    Rep Power
    9

    Default

    It's possible that we aren't getting connects from any sites on the RBL lists -- that's why I want to wait a few days before making this a support case. Currently we are in pilot group testing with around a dozen people getting mail on the zimbra box. That's only about 2500 msgs/day with about 40-50% of those being blocked or tagged as spam.
    We were thinking of waiting for 4.5 before going into full production but if 4.5's not out till mid-Jan that's not going to be possible. Either way, we wanted the RBLs working before going into production.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 3
    Last Post: 07-19-2007, 02:00 AM
  2. Curious log message in zmmtaconfig.log
    By emx in forum Administrators
    Replies: 1
    Last Post: 07-16-2007, 11:21 AM
  3. Network Service Error with MIME encoded message
    By Glenham in forum Administrators
    Replies: 2
    Last Post: 10-17-2006, 09:37 AM
  4. Replies: 4
    Last Post: 08-10-2006, 10:55 PM
  5. Recover single message from redo log?
    By shanson in forum Administrators
    Replies: 1
    Last Post: 06-06-2006, 08:07 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •