iT邦幫忙

1

SPAM IP 被BLOCK 導致MAIL發送有問題

  • 分享至 

  • xImage

請教一下各位先進
這幾天公司外包廠商EIP IP被SPAMHAUS 黑單
我跟廠商溝通了好幾天 他們還是找不到問題也不知道怎麼處理
有甚麼辦法可以幫我解決嗎
現在公司很多MAIL都因此寄不出去 或者寄出去對方沒收到
以下是 SPAMHAUS 這邊的回覆

08 MAR 2024
08:59:05
Thank you for contacting Spamhaus XBL Removals,

Please use https://translate.google.com/ for language, if needed.

IF THIS HAS ALREADY BEEN FIXED PLEASE...
REPLY TO THIS MESSAGE IMMEDIATELY - AND - INCLUDE THE DETAILS OF WHAT WAS FIXED AND HOW.

This issue can be caused by multiple things: please read the whole reponse, especially if you have a Sophos appliance!

--

122.116.21.46 has been classified as part of a proxy network. There is a type of malware using this IP that installs a third-party proxy that could be used for nearly anything, including sending spam or stealing customer data. This should be of more concern than a Spamhaus listing, which is a symptom and not the problem.

It is NOT your mail server:

(IP, UTC timestamp, HELO value)
122.116.21.46 2024-03-08 05:55:00 122-116-21-46.hinet-ip.hinet.net
122.116.21.46 2024-03-04 12:55:00 83.8.244.229.ipv4.supernova.orange.pl
122.116.21.46 2024-03-02 13:30:00 122-116-21-46.hinet-ip.hinet.net
122.116.21.46 2024-03-02 05:30:00 122-116-21-46.hinet-ip.hinet.net
122.116.21.46 2024-03-01 15:55:00 122-116-21-46.hinet-ip.hinet.net

The proxy is installed on a device - usually an Android mobile, firestick, smart doorbell, etc, but can be anything that has software on it - that is using your IP to send spam DIRECTLY to the internet via port 25: This is very often the result of third party "free" apps like VPNs, channel unlockers, streaming, etc being installed on someone's personal device, usually a phone.

This is a simple explanation of how this works: https://www.spamhaus.com/resource-center/when-doorbells-go-rogue/

Any devices with "free" VPNs, TV streaming, channel unlocking, or 3rd-party apps installed are the first things to check.


How to solve this problem depends on whether this IP is static and assigned for business use with an internal mail server or dynamic, for home use. If you are not sure, call your ISP and ask them.

HOME USER: Dynamic Single IP for non-commercial use. There are a number of possibilities:

  • It is possible you may have inherited a problem from the IP's previous user. Please check the timestamps provided above. Was this IP yours during the most recent?
  • Dynamic IPs are not intended for running mail servers. If that is what you are doing, please find a work-around with your provider. Effective NAT/Firewall configuration will be required.
  • In the event that you do not operate your own mail server - which should be most people - then please configure your router to block all access to port 25, and use SMTP AUTH with your provider of choice. Your ISP can help with that, and most router user manuals are available online.

Please call your ISP or IT department for assistance with configuring your router or firewall correctly. You can also find most router configuration manuals online.


If the IP is static, the network has a malware problem. It is very unlikely to be the actual mail server, but it is something that is able to share the same public IP.

Consider the implications of a proxy that is under someone else's control being active on your network: malicious operators control a device that is within your network. To them, spamming is an extra. Your business is their business.

We very strongly recommend securing your firewall to not allow any packets outbound on port 25, except those coming from any email server(s) on your local network. Remote sending of email to servers via the Internet should still work if web-based, or configured properly to use port 587 using SMTP-AUTH. We also suggest securing any guest networks the same way.

IMPORTANT: Limiting port 25 stops the connections from leaving your network but does NOT neutralize the proxy. It needs to be found and removed.

Since we are unable to see through NAT or the Firewall, finding the problem is entirely the responsibility of the IT manager. Logging at the router or firewall to see what is trying to use port 25 should lead to the compromised device(s).

The easier thing to do would be to limit outbound port 25 to mail servers and thus secure your network and stop the listings. You can look for the device(s) afterward.

NOTE: there may be more than one affected device. There also may be more than one issue. Please check all your technical settings, including DNS (forward and reverse) and HELO values. Guest networks also need to be secured.

Our FAQ might be helpful: https://www.spamhaus.org/faq/section/Hacked...%20Here's%20help

--SOPHOS:

If you are using a Sophos device please check the following:
Go to Protect-> Email | go to the Tab "general settings" | below this menu SMTP settings -> look at the "SMTP Hostname".

If that is "SMTP" or "Sophos" then you will need to configure it properly using a fully qualified domain name. Correct configuration is site dependent and we are unable to recommend anything specific.

You can test a server's HELO configuration by visiting https://aboutmy.email. From there, send an email from the machine in question to the provided email address, and then examine the results. This tool will give a lot of detail about the email. To check HELO/EHLO, navigate to "Delivery" -> "SMTP" and look for the EHLO line.

The Sophos appliance re-writes the HELO that the proxy is using. Fixing the HELO is important, but not nearly as critical as finding and removing that third party proxy. Changing the HELO will NOT neutralize the proxy.

Regards,
Marvin Adams

看更多先前的討論...收起先前的討論...
PIZZ iT邦新手 1 級 ‧ 2024-03-08 17:10:42 檢舉
自架,換代管,上雲,改IP和DNS對應...

同仁先註冊免費Gmail用公司名+帳戶名當帳號,先用免費郵件的發送...之後在下載回來

如果你們和外包商有簽合約,你們的RTO是設定多久?違約怎處理?賠償怎麼算?

你們家沒法顧?
circusyu iT邦新手 5 級 ‧ 2024-03-08 17:27:08 檢舉
EIP廠商說第一次遇到這個問題他們也不知道也沒辦法解決
已查過 outlook exchange 信件發送都沒問題
估計是EIP的IP出現異常才導致信件問題
排除EIP的IP問題 有甚麼可以解決嗎 因為exchange mail server都確認沒問題
一切都是EIP在搞鬼 他們卻也不知道問題在哪..
甚至訪問某些網頁 也會因為EIP的IP被阻擋進入
122.116.21.46,是一台NAS,不是 Mail server
看了你的問題以及回覆,我想請教一個問題,你們的EIP廠商,提供你們什麼服務?
全包你們公司的上網嗎?exchange server是交給他們代管嗎?
sam0407 iT邦大師 1 級 ‧ 2024-03-11 14:04:12 檢舉
上週我們集團裡有幾家是用Microsoft 365的Outlook的郵件都被SPAM擋下來,請SPAM廠商查:是微軟的Server進了SPAM黑名單,IP開頭也是40.107.xxx.xxx
yXoXy iT邦新手 5 級 ‧ 2024-03-11 15:27:30 檢舉
用的是 exchange online ? 這問題已經有3個月了 SpamCop 把微軟納進黑名單而且大多 IP 都是 40.107.x.x 也正是微軟的 mail IP。
可以參考這個看看 https://www.softnext.com.tw/news_main.html?tag=t&nid=1108
圖片
  直播研討會
圖片
{{ item.channelVendor }} {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

1 個回答

0
mathewkl
iT邦高手 1 級 ‧ 2024-03-08 17:21:56

主要是這個吧
對方回報的反解第二條

122.116.21.46 2024-03-04 12:55:00 83.8.244.229.ipv4.supernova.orange.pl

怎麼會解出一條波蘭網域

另外你們透過外包EIP寄信...?
還是他們也代管你們的信箱?
或者是這個外包直接在EIP實作信箱收發?

-------------回覆------------

因為你的網域有了,我們來看看
DNS Record found
SPF Record found
No DMARC Record found
DMARC Quarantine/Reject policy not enabled
No DKIM Record found
基本上你信箱安全只做了SPF,麻煩補上DMARC和DKIM
一些信箱會把沒做滿的網域辨別為可疑信件(Gmail還明說會列入垃圾信)

再來Outlook SPAM Mail的問題
微軟在管理中心有發公告,部分使用者遇到被列為SPAM的問題,處理中

2024年3月7日 上午4:48 [GMT+8]
Users' outbound Exchange Online email messages may be marked as spam and not delivered.

User impact: Users' outbound Exchange Online email messages may be marked as spam and not delivered.

More info: This isn’t connection method specific and thus occurs in all Exchange Online connection methods. Affected users receive a Non-Delivery Report (NDR) message that references the third-party anti-spam service name that has added the IP address to their block list.

Current status: We're working with the third-party anti-spam service to better identify the IP
address ranges affected by this problem, so that we can more quickly identify and manage sources of potentially malicious email messages. This will help reduce the frequency of spam and phishing email, which would also reduce the number of reported and blocked IP addresses, returning some mail flow as expected. In parallel, we're reviewing long-term solutions to prevent similar problems.

Scope of impact: The problem may impact some users sending outbound email messages if they're leveraging a specific third-party anti-spam service mentioned within the NDR.

Root cause: A third-party anti-spam service is blocking a portion of Microsoft’s email IP address ranges to protect organizations that use their services.

Next update by: Saturday, March 9, 2024 at 5:00 AM GMT+8

circusyu iT邦新手 5 級 ‧ 2024-03-08 17:29:16 檢舉

我們不是在EIP發信 我們SERVER 都在outlook exchange mailserver
所以才不曉得是不是連帶關係 只是懷疑
現在某些人寄信會出現退回

mtai11n.zprv.incnets.com rejected your message to the following email addresses:
cus@shuntenglogistics.com (cus@shuntenglogistics.com)
Your message couldn't be delivered because it's suspected of being spam. For best practices when sending email, refer to the guidelines found here: https://aka.ms/EmailingBestPractices.
mtai11n.zprv.incnets.com gave this error:
Decision Engine classified the mail item was rejected because of IP Block (from outbound normal IP pools) -> 554 5.7.1 Service unavailable; Client host [40.107.215.91] blocked using bl.spamcop.net; Blocked - see https://www.spamcop.net/bl.shtml?40.107.215.91

mathewkl iT邦高手 1 級 ‧ 2024-03-08 17:52:19 檢舉

內容比較長,在上面回你

我要發表回答

立即登入回答