<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
		<link>https://forum.iredmail.org/topic14387-smtp-auth-is-required-for-users-under-this-sender-domain-mailing-list.html</link>
		<atom:link href="https://forum.iredmail.org/feed-rss-topic14387.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in SMTP AUTH is required for users under this sender domain (Mailing list.]]></description>
		<lastBuildDate>Thu, 21 Jun 2018 07:33:38 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63904.html#p63904</link>
			<description><![CDATA[<p>This *did* work. Thanks.</p>]]></description>
			<author><![CDATA[null@example.com (craig)]]></author>
			<pubDate>Thu, 21 Jun 2018 07:33:38 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63904.html#p63904</guid>
		</item>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63804.html#p63804</link>
			<description><![CDATA[<p>Thanks. I&#039;ve made the change and will wait for user to advise whether or not it&#039;s working. If it&#039;s <strong>not</strong> working, I&#039;ll be back. <img src="https://forum.iredmail.org/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[null@example.com (craig)]]></author>
			<pubDate>Fri, 15 Jun 2018 15:14:49 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63804.html#p63804</guid>
		</item>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63778.html#p63778</link>
			<description><![CDATA[<p>Aha, my mistake, i forgot to mention that you need to add a setting in /opt/iredapd/settings.py and restart iredapd service:<br /></p><div class="codebox"><pre><code>CHECK_SPF_IF_LOGIN_MISMATCH = True</code></pre></div><p>If it still doesn&#039;t work, please turn on debug mode in iRedAPD and trigger this issue again. i need detailed debug log for troubleshooting.</p><p>I will enable this option by default in next release.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Fri, 15 Jun 2018 12:08:34 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63778.html#p63778</guid>
		</item>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63769.html#p63769</link>
			<description><![CDATA[<p>To save some looking up, the IP address that was denied was 94.100.133.204. The antispameurope.com SPF record is as follows:</p><p>v=spf1 a mx ip4:83.246.65.0/24 ip4:185.140.204.0/22 ip4:94.100.128.0/20 ip4:81.20.94.0/24 ip4:173.45.18.0/24 ~all</p><p>Breaking that down:</p><p>81.20.94.0/24<br />83.246.65.0/24<br />94.100.128.0/20<br />173.45.18.0/24<br />185.140.204.0/22</p><p>The blocked IP address is within the 94.100.128.0/20 range, so it should have been allowed by iRedAPD, according to your earlier post.</p><br /><p>Craig</p>]]></description>
			<author><![CDATA[null@example.com (craig)]]></author>
			<pubDate>Fri, 15 Jun 2018 04:16:21 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63769.html#p63769</guid>
		</item>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63756.html#p63756</link>
			<description><![CDATA[<div class="quotebox"><cite>craig wrote:</cite><blockquote><div class="quotebox"><cite>ZhangHuangbin wrote:</cite><blockquote><p>This one is well handled by iRedAPD, email sent from servers listed in SPF will not be rejected.</p></blockquote></div><p>Cool, that&#039;s good news. I will test.</p></blockquote></div><p>This is *not* working.</p><p>My user&#039;s domain is example.COM, and their parent company has what I assume is an alias on their domain example.NET. They use Hornet Security, a third-party, to process their email. So my user sends an email to list@example.NET, and the message is then distributed to a number of addresses on both example.COM and example.NET.</p><p>At <a href="https://www.hornetsecurity.com/en/onboarding-information">https://www.hornetsecurity.com/en/onboa … nformation</a> Hornet Security states, under the &quot;Setting the SPF record&quot; heading:</p><div class="quotebox"><blockquote><p>Another DNS setting you can configure in addition to the MX record is the SPF record. This is saved as a domain TXT record and specifies which systems are allowed to send e-mail on behalf of the domain. It is analyzed in certain circumstances by external recipients, but also by the Hornetsecurity spam filter service, for purposes that include detecting fraud attempts such as spoofing. It is therefore very useful to modify or expand the TXT entry. The following setting is recommended:&nbsp; &nbsp;“v=spf1 include:antispameurope.com ~all”</p></blockquote></div><p>So I added that to the SPF record of example.COM. This is the output of dig run on my iRedMail server:</p><div class="codebox"><pre><code>[06:18:26 root@server log]# dig +short example.COM txt @localhost
&quot;v=spf1 a mx include:example.NET include:antispameurope.com ~all&quot;
[06:28:37 root@server log]#</code></pre></div><p>However, messages still bounce:</p><div class="codebox"><pre><code>Jun 14 05:35:11 server postfix/smtpd[3158]: NOQUEUE: reject: RCPT from mx-relay28-hz1.antispameurope.com[94.100.133.204]: 554 5.7.1 &lt;user2@example.COM&gt;: Recipient address rejected: SMTP AUTH is required for users under this sender domain; from=&lt;user1@example.COM&gt; to=&lt;user2@example.COM&gt; proto=ESMTP helo=&lt;mx-relay28-hz1.antispameurope.com&gt;</code></pre></div><p>So is my logic broken, or is iRedAPD not taking into account the SPF record as you say it should?</p>]]></description>
			<author><![CDATA[null@example.com (craig)]]></author>
			<pubDate>Thu, 14 Jun 2018 06:39:47 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63756.html#p63756</guid>
		</item>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63746.html#p63746</link>
			<description><![CDATA[<div class="quotebox"><cite>ZhangHuangbin wrote:</cite><blockquote><p>Do you mean the mailing list address is also &quot;&lt;something&gt;@domain1.COM? If yes, then it will be rejected due to it&#039;s considered as forged spam (all emails with sender address &#039;&lt;someone&gt;@domain1.com&#039; must be sent from your server).</p></blockquote></div><p>No, I believe that whatever is happening the &quot;from&quot; field of the sender is just being preserved. I am still waiting for this user to send me a sample of a mailing list email and tell me what MLM is being used.</p><div class="quotebox"><cite>ZhangHuangbin wrote:</cite><blockquote><p>This one is well handled by iRedAPD, email sent from servers listed in SPF will not be rejected.</p></blockquote></div><p>Cool, that&#039;s good news. I will test.</p>]]></description>
			<author><![CDATA[null@example.com (craig)]]></author>
			<pubDate>Wed, 13 Jun 2018 10:50:18 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63746.html#p63746</guid>
		</item>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63707.html#p63707</link>
			<description><![CDATA[<div class="quotebox"><cite>craig wrote:</cite><blockquote><p>If I host domain1.COM and a user on that domain sends a message though my server to a discussion list on domain2.NET hosted elsewhere, and that list distributes it to users back on domain1.COM, the email will be bounced.</p></blockquote></div><p>Do you mean the mailing list address is also &quot;&lt;something&gt;@domain1.COM? If yes, then it will be rejected due to it&#039;s considered as forged spam (all emails with sender address &#039;&lt;someone&gt;@domain1.com&#039; must be sent from your server).<br /></p><div class="quotebox"><cite>craig wrote:</cite><blockquote><p>Another legitimate situation in which emails will bounce is when a third party sends emails from an address on my domain to my users if my domain is also hosted on the same server. I have the necessary SPF record identifying their mail server as a legitimate source of email for my domain.</p><p>Is such an SPF record taken into consideration by this feature?</p></blockquote></div><p>This one is well handled by iRedAPD, email sent from servers listed in SPF will not be rejected.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 12 Jun 2018 18:45:45 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63707.html#p63707</guid>
		</item>
		<item>
			<title><![CDATA[Re: SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63701.html#p63701</link>
			<description><![CDATA[<p>Another legitimate situation in which emails will bounce is when a third party sends emails from an address on my domain to my users if my domain is also hosted on the same server. I have the necessary SPF record identifying their mail server as a legitimate source of email for my domain.</p><p>Is such an SPF record taken into consideration by this feature?</p><p>Is it possible for me to turn this feature off, but only for situations like these legitimate examples?</p>]]></description>
			<author><![CDATA[null@example.com (craig)]]></author>
			<pubDate>Tue, 12 Jun 2018 06:14:32 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63701.html#p63701</guid>
		</item>
		<item>
			<title><![CDATA[SMTP AUTH is required for users under this sender domain (Mailing list]]></title>
			<link>https://forum.iredmail.org/post63694.html#p63694</link>
			<description><![CDATA[<p>==== Required information ====<br />- iRedMail version (check /etc/iredmail-release): 0.9.8<br />- Linux/BSD distribution name and version: CentOS 7.5<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL<br />- Web server (Apache or Nginx): Nginx<br />- Manage mail accounts with iRedAdmin-Pro?: Yes<br />- [IMPORTANT] Related original log or error message is required if you&#039;re experiencing an issue.<br />====</p><p>I&#039;ve read the information at <a href="https://docs.iredmail.org/errors.html#recipient-address-rejected-smtp-auth-is-required-for-users-under-this-sender-domain">https://docs.iredmail.org/errors.html#r … der-domain</a> , but unless I&#039;m misunderstanding something I see a third (and legitimate) reason that email could get caught by this: discussion/mailing lists. If I host domain1.COM and a user on that domain sends a message though my server to a discussion list on domain2.NET hosted elsewhere, and that list distributes it to users back on domain1.COM, the email will be bounced.</p><p>Am I right? How can I allow these emails without having to manually keep track of a whitelist in &quot;MYNETWORKS&quot;? One of my users wants me to whitelist 5500 IP addresses for a big European company!</p>]]></description>
			<author><![CDATA[null@example.com (craig)]]></author>
			<pubDate>Mon, 11 Jun 2018 14:56:28 +0000</pubDate>
			<guid>https://forum.iredmail.org/post63694.html#p63694</guid>
		</item>
	</channel>
</rss>
