[Raw Msg Headers][Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SMTP Policy rejection frustration



> ZMailer version: 	zmailer-2.99.50-s5
> platform:		Linux x86 RedHat 5.1
> 
> recently we have had to tighten up on policy for spam, so I changed
> to the 2nd alternate policy:
> 
> # -- 2nd alternate: No MX target usage, DNS existence verify
> ..                 relaycustomer - relaytarget - senderokwithdns +
> [0.0.0.0]/0        relaycustomer - relaytarget - senderokwithdns +

  Double-dot ?  Oh, line-start dot duplication bug in BDAT processing
  was detected, and corrected in between s5 and s6.

> To my surprise, the result is that for many domains, including
> nic.funet.fi, I get rejection:

   I think I see what the problem is.

  You don't have   smtp-policy.relay  file, in which you should
  list all those networks from which you accept traffic for outbound
  relaying.  Here is an example sample from nic.funet.fi:

#vger.rutgers.edu
[128.6.190.2]/32 fulltrustnet +
#.funet.fi
#[127.0.0.0]/8
[128.214.0.0]/16
[193.166.5.0]/24
[193.166.1.0]/24
[130.230.1.0]/24


> mail from:<jmack@phys.ualberta.ca>
> 250 2.1.0 Sender syntax Ok
> rcpt to:<zmailer@nic.funet.fi>
> 553 5.7.1 Policy rejection on the target address
> 
> I certainly don't have funet listed in smtp-policy.src...
...
> So what gives? 
> 
> I've changed back to the old pattern (3rd alternate) to send this,
> but clearly it will not do.

  The third alternate does not exhibit the same symptoms ?

> Thanks,
> --
> James S. MacKinnon           Office: P-139 Avadh-Bhatia Physics Lab
> Team Physics                 Voice : (403) 492-8226
> University of Alberta        email : Jim.MacKinnon@Phys.UAlberta.CA
> Edmonton, Canada T6G 2N5     WWW   : http://www.phys.ualberta.ca/

/Matti Aarnio -- now traveling at Finnish Amateur Astronomers Summer Camp..
	My previous weekend:  http://galileo.ksp.fi/oh6vm/aprs/ilmari-e.shtml
	(now with english text)