Topic: SMTPAuthenticationError(535, '5.7.8 Error: authentication failed: Conn
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.3.1 OPENLDAP edition
- Deployed with iRedMail Easy or the downloadable installer? downloadable installer
- Linux/BSD distribution name and version: CentOS 7
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx):Nginx
- Manage mail accounts with iRedAdmin-Pro? 4.5 (LDAP)
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
# messages
Oct 21 02:26:11 mail journal: iredadmin + << ERROR >> Error while sending notification email to user@mydomain.com: SMTPAuthenticationError(535, '5.7.8 Error: authentication failed: Connection lost to authentication server') (/opt/www/iredadmin/tools/notify_quarantined_recipients.py, line 360)
# crontab
26 */2 * * * python /opt/www/iredadmin/tools/notify_quarantined_recipients.py --force-all >/dev/null
# maillog
Oct 21 02:26:01 mail postfix/submission/smtpd[18571]: connect from mail.mydomain.com[127.0.0.1]
Oct 21 02:26:11 mail postfix/submission/smtpd[18571]: warning: mail.mydomain.com[127.0.0.1]: SASL PLAIN authentication failed: Connection lost to authentication server
Oct 21 02:26:11 mail postfix/submission/smtpd[18571]: lost connection after AUTH from mail.mydomain.com[127.0.0.1]
Oct 21 02:26:11 mail postfix/submission/smtpd[18571]: disconnect from mail.mydomain.com[127.0.0.1]
Oct 21 02:26:11 mail postfix/cleanup[18578]: 4CG2BW4BjvzBsdZcH: message-id=<4CG2BW4BjvzBsdZcH@mail.mydomain.com>
Oct 21 02:26:11 mail clamd[4401]: SelfCheck: Database status OK.
Oct 21 02:26:13 mail postfix/10025/smtpd[18593]: 4CG2BY4Qt3zBsdZcV: client=mail.mydomain.com[127.0.0.1]
Oct 21 02:26:13 mail postfix/cleanup[18578]: 4CG2BY4Qt3zBsdZcV: message-id=<4CG2BW4BjvzBsdZcH@mail.mydomain.com>
Oct 21 02:26:13 mail postfix/10025/smtpd[18593]: disconnect from mail.mydomain.com[127.0.0.1]
Oct 21 02:26:13 mail amavis[11438]: (11438-04) Passed CLEAN {RelayedInternal}, ORIGINATING LOCAL [127.0.0.1] <root@mail.mydomain.com> -> <root@mail.mydomain.com>, Message-ID: <4CG2BW4BjvzBsdZcH@mail.mydomain.com>, mail_id: Wd4aAJ561Blc, Hits: -98.501, size: 1972, queued_as: 4CG2BY4Qt3zBsdZcV, dkim_new=dkim:mydomain.com, 1991 ms, Tests: [KAM_DMARC_STATUS=0.01,KAM_MXURI=1.5,NO_RELAYS=-0.001,USER_IN_WELCOMELIST=-0.01,USER_IN_WHITELIST=-100], helo=
Oct 21 02:26:13 mail amavis[11438]: (11438-04) Passed CLEAN, <root@mail.mydomain.com> -> <root@mail.mydomain.com>, Hits: -98.501, tag=-999, tag2=6.2, kill=6.9, queued_as: 4CG2BY4Qt3zBsdZcV, L/Y/0/0
Oct 21 02:26:13 mail postfix/cleanup[18578]: 4CG2BY4fvTzBsdZcY: message-id=<4CG2BW4BjvzBsdZcH@mail.mydomain.com>
Oct 21 02:26:13 mail postfix/qmgr[2772]: 4CG2BW4BjvzBsdZcH: removed
Oct 21 02:26:13 mail postfix/qmgr[2772]: 4CG2BY4Qt3zBsdZcV: removed
Oct 21 02:26:13 mail postfix/pipe[18596]: 4CG2BY4fvTzBsdZcY: to=<rootbcc@mydomain.com>, relay=dovecot, delay=0.17, delays=0.05/0.01/0/0.12, dsn=2.0.0, status=sent (delivered via dovecot service)
Oct 21 02:26:13 mail postfix/qmgr[2772]: 4CG2BY4fvTzBsdZcY: removed
# rootbcc@ 收到的mail
send: 'ehlo mail.mydomain.com\r\n'
reply: '250-mail.mydomain.com\r\n'
reply: '250-PIPELINING\r\n'
reply: '250-SIZE 215482368\r\n'
reply: '250-ETRN\r\n'
reply: '250-STARTTLS\r\n'
reply: '250-ENHANCEDSTATUSCODES\r\n'
reply: '250-8BITMIME\r\n'
reply: '250 DSN\r\n'
reply: retcode (250); Msg: mail.mydomain.com
PIPELINING
SIZE 215482368
ETRN
STARTTLS
ENHANCEDSTATUSCODES
8BITMIME
DSN
send: 'STARTTLS\r\n'
reply: '220 2.0.0 Ready to start TLS\r\n'
reply: retcode (220); Msg: 2.0.0 Ready to start TLS
send: 'ehlo mail.mydomain.com\r\n'
reply: '250-mail.mydomain.com\r\n'
reply: '250-PIPELINING\r\n'
reply: '250-SIZE 215482368\r\n'
reply: '250-ETRN\r\n'
reply: '250-AUTH PLAIN LOGIN\r\n'
reply: '250-ENHANCEDSTATUSCODES\r\n'
reply: '250-8BITMIME\r\n'
reply: '250 DSN\r\n'
reply: retcode (250); Msg: mail.mydomain.com
PIPELINING
SIZE 215482368
ETRN
AUTH PLAIN LOGIN
ENHANCEDSTATUSCODES
8BITMIME
DSN
send: 'AUTH PLAIN AHRlY2hsaW5zc3BhbUB0ZWNobGlucy5jb20AdGVjaGxpbnNzcGFtMzIzNDAxODgxMQ==\r\n'
reply: '535 5.7.8 Error: authentication failed: Connection lost to authentication server\r\n'
reply: retcode (535); Msg: 5.7.8 Error: authentication failed: Connection lost to authentication server
## dovecot
Oct 21 02:26:01 mail dovecot: auth: ldap(rootbcc@mydomain.com,127.0.0.1): invalid credentials
## mariadb
201021 2:26:01 3531 Connect fail2ban@localhost as anonymous on fail2ban
後台:隔離訊息
Subject
[WEBINAR] Web Application Security Essentials
Sender
srs0=uxhl=d3=bounce.s11.exacttarget.com=bounce-63185_html-140022032-68829-514005493-6171@mail.mydomain.com
Recipient
user@mydomain.com
Kind
Spam
Size
18 KB
Score
0.0
Date
2020-10-21 02:13:24
請問版主:
1).為何給 user@ 時, 出現 authentication failed ,此帳號為domain 裡的帳號
2). 後台 Spam 隔離信件, 其分數為 0.0 , 怎會被隔離?
在黑名單(White/Blacklist)已有:
srs0=rogl=dw=bounce.s11.exacttarget.com=bounce-63185_html-140022032-68829-514005493-5703@mail.mydomain.com
但在 Spam 隔離的sender 為:
srs0=uxhl=d3=bounce.s11.exacttarget.com=bounce-63185_html-140022032-68829-514005493-6171@mail.mydomain.com
正確黑名單建立的格式要如何建立?
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.