Topic: Grey Listing appears to not work for some emails
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.6.0 MARIADB edition.
- Deployed with iRedMail Easy or the downloadable installer? N
- Linux/BSD distribution name and version: CentOS Linux release 7.9.2009 (Core)
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Apache
- Manage mail accounts with iRedAdmin-Pro? N
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
I have an email coming via salesforce.com (so the original from address is mangled), that is not passing the Grey Listing from iRedAPD.
Below is 5 occurrences (3 lines each) from the log file that are essentially the same, the source IP is the same.
It should pass Grey Listing, but it's not.
The date/times are:
Jun 29 15:08:19
Jun 29 15:18:21
Jun 29 15:38:26
Jun 29 16:18:36
Jun 29 17:38:53
So well within the 5 minutes defined in the config
GREYLISTING_BLOCK_EXPIRE = 5
/var/log/iredapd/iredapd.log
Jun 29 15:08:19 nebula journal: iredapd [13.238.11.116] Client has not been seen before, greylisted (ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com).
Jun 29 15:08:19 nebula journal: iredapd [13.238.11.116] RCPT, camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> camp@todomain.org.au, 451 4.7.1 Intentional policy rejection, please try again later [sasl_username=, sender=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com, client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, reverse_client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, helo=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, encryption_protocol=TLSv1.2, encryption_cipher=ECDHE-RSA-AES256-GCM-SHA384, server_port=, process_time=0.1058s]
Jun 29 15:08:24 nebula journal: iredapd [srs][sender] rewrote: camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> SRS0=8Q/+=XE=ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@mydomain.com.au
Jun 29 15:18:21 nebula journal: iredapd [13.238.11.116] Client has not been seen before, greylisted (ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com).
Jun 29 15:18:21 nebula journal: iredapd [13.238.11.116] RCPT, camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> camp@todomain.org.au, 451 4.7.1 Intentional policy rejection, please try again later [sasl_username=, sender=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com, client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, reverse_client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, helo=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, encryption_protocol=TLSv1.2, encryption_cipher=ECDHE-RSA-AES256-GCM-SHA384, server_port=, process_time=0.1216s]
Jun 29 15:18:26 nebula journal: iredapd [srs][sender] rewrote: camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> SRS0=8Q/+=XE=ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@mydomain.com.au
Jun 29 15:38:26 nebula journal: iredapd [13.238.11.116] Client has not been seen before, greylisted (ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com).
Jun 29 15:38:26 nebula journal: iredapd [13.238.11.116] RCPT, camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> camp@todomain.org.au, 451 4.7.1 Intentional policy rejection, please try again later [sasl_username=, sender=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com, client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, reverse_client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, helo=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, encryption_protocol=TLSv1.2, encryption_cipher=ECDHE-RSA-AES256-GCM-SHA384, server_port=, process_time=0.1082s]
Jun 29 15:38:31 nebula journal: iredapd [srs][sender] rewrote: camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> SRS0=8Q/+=XE=ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@mydomain.com.au
Jun 29 16:18:36 nebula journal: iredapd [13.238.11.116] Client has not been seen before, greylisted (ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com).
Jun 29 16:18:36 nebula journal: iredapd [13.238.11.116] RCPT, camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> camp@todomain.org.au, 451 4.7.1 Intentional policy rejection, please try again later [sasl_username=, sender=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com, client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, reverse_client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, helo=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, encryption_protocol=TLSv1.2, encryption_cipher=ECDHE-RSA-AES256-GCM-SHA384, server_port=, process_time=0.1036s]
Jun 29 16:18:41 nebula journal: iredapd [srs][sender] rewrote: camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> SRS0=8Q/+=XE=ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@mydomain.com.au
Jun 29 17:38:53 nebula journal: iredapd [13.238.11.116] Client has not been seen before, greylisted (ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com).
Jun 29 17:38:53 nebula journal: iredapd [13.238.11.116] RCPT, camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> camp@todomain.org.au, 451 4.7.1 Intentional policy rejection, please try again later [sasl_username=, sender=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com, client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, reverse_client_name=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, helo=smtp-0fed340ad1cf7c796.core1.sfdc-vwfla6.mta.salesforce.com, encryption_protocol=TLSv1.2, encryption_cipher=ECDHE-RSA-AES256-GCM-SHA384, server_port=, process_time=0.1122s]
Jun 29 17:38:58 nebula journal: iredapd [srs][sender] rewrote: camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com -> SRS0=8Q/+=XE=ykfd48fzszkzwdvb.5num7zm.28-1deyqeai.aus25.bnc.salesforce.com=camping=fromdomain.asn.au__0-3w7nw7sjuglkyw.66zbr51vqp349v0a@mydomain.com.au
I have turned on iRedAPD debug mode and will check tomorrow when the next email comes.
I can't use spf_to_whitelist_domains.py because salesforce.com uses
_spf.salesforce.com. TXT "v=spf1 exists:%{i}._spf.mta.salesforce.com -all"
Any ideas?
Thanks, Rob
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.