請教一下各位先進
這幾天公司外包廠商EIP IP被SPAMHAUS 黑單
我跟廠商溝通了好幾天 他們還是找不到問題也不知道怎麼處理
有甚麼辦法可以幫我解決嗎
現在公司很多MAIL都因此寄不出去 或者寄出去對方沒收到
以下是 SPAMHAUS 這邊的回覆
08 MAR 2024
08:59:05
Thank you for contacting Spamhaus XBL Removals,
Please use https://translate.google.com/ for language, if needed.
IF THIS HAS ALREADY BEEN FIXED PLEASE...
REPLY TO THIS MESSAGE IMMEDIATELY - AND - INCLUDE THE DETAILS OF WHAT WAS FIXED AND HOW.
This issue can be caused by multiple things: please read the whole reponse, especially if you have a Sophos appliance!
--
122.116.21.46 has been classified as part of a proxy network. There is a type of malware using this IP that installs a third-party proxy that could be used for nearly anything, including sending spam or stealing customer data. This should be of more concern than a Spamhaus listing, which is a symptom and not the problem.
It is NOT your mail server:
(IP, UTC timestamp, HELO value)
122.116.21.46 2024-03-08 05:55:00 122-116-21-46.hinet-ip.hinet.net
122.116.21.46 2024-03-04 12:55:00 83.8.244.229.ipv4.supernova.orange.pl
122.116.21.46 2024-03-02 13:30:00 122-116-21-46.hinet-ip.hinet.net
122.116.21.46 2024-03-02 05:30:00 122-116-21-46.hinet-ip.hinet.net
122.116.21.46 2024-03-01 15:55:00 122-116-21-46.hinet-ip.hinet.net
The proxy is installed on a device - usually an Android mobile, firestick, smart doorbell, etc, but can be anything that has software on it - that is using your IP to send spam DIRECTLY to the internet via port 25: This is very often the result of third party "free" apps like VPNs, channel unlockers, streaming, etc being installed on someone's personal device, usually a phone.
This is a simple explanation of how this works: https://www.spamhaus.com/resource-center/when-doorbells-go-rogue/
Any devices with "free" VPNs, TV streaming, channel unlocking, or 3rd-party apps installed are the first things to check.
How to solve this problem depends on whether this IP is static and assigned for business use with an internal mail server or dynamic, for home use. If you are not sure, call your ISP and ask them.
HOME USER: Dynamic Single IP for non-commercial use. There are a number of possibilities:
Please call your ISP or IT department for assistance with configuring your router or firewall correctly. You can also find most router configuration manuals online.
If the IP is static, the network has a malware problem. It is very unlikely to be the actual mail server, but it is something that is able to share the same public IP.
Consider the implications of a proxy that is under someone else's control being active on your network: malicious operators control a device that is within your network. To them, spamming is an extra. Your business is their business.
We very strongly recommend securing your firewall to not allow any packets outbound on port 25, except those coming from any email server(s) on your local network. Remote sending of email to servers via the Internet should still work if web-based, or configured properly to use port 587 using SMTP-AUTH. We also suggest securing any guest networks the same way.
IMPORTANT: Limiting port 25 stops the connections from leaving your network but does NOT neutralize the proxy. It needs to be found and removed.
Since we are unable to see through NAT or the Firewall, finding the problem is entirely the responsibility of the IT manager. Logging at the router or firewall to see what is trying to use port 25 should lead to the compromised device(s).
The easier thing to do would be to limit outbound port 25 to mail servers and thus secure your network and stop the listings. You can look for the device(s) afterward.
NOTE: there may be more than one affected device. There also may be more than one issue. Please check all your technical settings, including DNS (forward and reverse) and HELO values. Guest networks also need to be secured.
Our FAQ might be helpful: https://www.spamhaus.org/faq/section/Hacked...%20Here's%20help
--SOPHOS:
If you are using a Sophos device please check the following:
Go to Protect-> Email | go to the Tab "general settings" | below this menu SMTP settings -> look at the "SMTP Hostname".
If that is "SMTP" or "Sophos" then you will need to configure it properly using a fully qualified domain name. Correct configuration is site dependent and we are unable to recommend anything specific.
You can test a server's HELO configuration by visiting https://aboutmy.email. From there, send an email from the machine in question to the provided email address, and then examine the results. This tool will give a lot of detail about the email. To check HELO/EHLO, navigate to "Delivery" -> "SMTP" and look for the EHLO line.
The Sophos appliance re-writes the HELO that the proxy is using. Fixing the HELO is important, but not nearly as critical as finding and removing that third party proxy. Changing the HELO will NOT neutralize the proxy.
Regards,
Marvin Adams
主要是這個吧
對方回報的反解第二條
122.116.21.46 2024-03-04 12:55:00 83.8.244.229.ipv4.supernova.orange.pl
怎麼會解出一條波蘭網域
另外你們透過外包EIP寄信...?
還是他們也代管你們的信箱?
或者是這個外包直接在EIP實作信箱收發?
-------------回覆------------
因為你的網域有了,我們來看看
DNS Record found
SPF Record found
No DMARC Record found
DMARC Quarantine/Reject policy not enabled
No DKIM Record found
基本上你信箱安全只做了SPF,麻煩補上DMARC和DKIM
一些信箱會把沒做滿的網域辨別為可疑信件(Gmail還明說會列入垃圾信)
再來Outlook SPAM Mail的問題
微軟在管理中心有發公告,部分使用者遇到被列為SPAM的問題,處理中
2024年3月7日 上午4:48 [GMT+8]
Users' outbound Exchange Online email messages may be marked as spam and not delivered.
User impact: Users' outbound Exchange Online email messages may be marked as spam and not delivered.
More info: This isn’t connection method specific and thus occurs in all Exchange Online connection methods. Affected users receive a Non-Delivery Report (NDR) message that references the third-party anti-spam service name that has added the IP address to their block list.
Current status: We're working with the third-party anti-spam service to better identify the IP
address ranges affected by this problem, so that we can more quickly identify and manage sources of potentially malicious email messages. This will help reduce the frequency of spam and phishing email, which would also reduce the number of reported and blocked IP addresses, returning some mail flow as expected. In parallel, we're reviewing long-term solutions to prevent similar problems.
Scope of impact: The problem may impact some users sending outbound email messages if they're leveraging a specific third-party anti-spam service mentioned within the NDR.
Root cause: A third-party anti-spam service is blocking a portion of Microsoft’s email IP address ranges to protect organizations that use their services.
Next update by: Saturday, March 9, 2024 at 5:00 AM GMT+8
我們不是在EIP發信 我們SERVER 都在outlook exchange mailserver
所以才不曉得是不是連帶關係 只是懷疑
現在某些人寄信會出現退回
mtai11n.zprv.incnets.com rejected your message to the following email addresses:
cus@shuntenglogistics.com (cus@shuntenglogistics.com)
Your message couldn't be delivered because it's suspected of being spam. For best practices when sending email, refer to the guidelines found here: https://aka.ms/EmailingBestPractices.
mtai11n.zprv.incnets.com gave this error:
Decision Engine classified the mail item was rejected because of IP Block (from outbound normal IP pools) -> 554 5.7.1 Service unavailable; Client host [40.107.215.91] blocked using bl.spamcop.net; Blocked - see https://www.spamcop.net/bl.shtml?40.107.215.91
內容比較長,在上面回你