邮件服务器-邮件系统-邮件技术论坛(BBS)

标题: IP地址被列为黑名单 [打印本页]

作者: xiangrui    时间: 2009-3-2 19:22
标题: IP地址被列为黑名单
今天我们公司的邮件忽然发不出去了,我查看了一下原因,是因为我们的IP地址被www.spamhaus.org 列为黑名单了。被列为黑名单的IP地址是路由器的IP地址,不是邮件服务器的IP地址。然后我再网上申请从黑名单中移除了,另外还更换了一个把路由器的IP地址换了一个新的。换之前查看还没有被列为黑名单。谁知一个小时后新IP地址也被列为黑名单了。发出去的邮件退信的内容如下:
“Your message did not reach some or all of the intended recipients.
Subject:    20090302 Aggregated Event Crawl
Sent: 2009-3-2 18:48
The following recipient(s) cannot be reached:

david@mutualart.com on 2009-3-2 18:48

You do not have permission to send to this recipient.  For assistance, contact your system administrator.

            <×××.com #5.7.1 SMTP; 554 5.7.1 Service unavailable; Client host [211.160.170.245] blocked using cbl.abuseat.org; Blocked - see http://cbl.abuseat.org/lookup.cgi?ip=211.160.170.245&gt;”

其中211.160.170.245就是我新换的路由器的IP地址。

各位兄弟这是怎么回事啊?怎么解决啊?
作者: jhonlone    时间: 2009-3-2 20:56
刚看了下,已经不在这个黑名单里了,如下:

IP Address 211.160.170.245 is not currently listed in the CBL.

It was previously listed, but was removed at 2009-03-02 10:28 GMT

ATTENTION: At the time of detection, this IP was infected with, or NATting for a computer infected with a high volume spam sending trojan - it is participating or facilitating a botnet sending spam or spreading virus/spam trojans.

ATTENTION: if you simply repeatedly remove this IP address from the CBL without correcting the problem, the CBL WILL eventually stop letting you delist it and you will have to contact us directly.

This is the Waledac spamBOT

You MUST patch your system and then fix/remove the trojan. Do this before delisting, or you're most likely to be listed again almost immediately.

If this IP is a NAT firewall/gateway, you MUST configure the NAT to prevent outbound port 25 connections to the Internet except from your real mail servers. Please see our recommendations on NAT firewalls

If you are running a Barracuda anti-spam appliance, turn off the "bounce spam" feature before delisting. Barracuda appliances with the "bounce spam or virus" feature turned on are showering innocent third parties with bounces of email that they didn't send. This is called "backscatter", and can get you listed in quite a number of DNSBLs (including SpamCop). The CBL doesn't deliberately list for backscatter, but in the case of Barracuda's "bounced spam or viruses", sometimes the CBL is unable to distinguish between a BOT and a Barracuda sending it. This seems most common with Warezov detections.

The Microsoft MSRT (Malicious Software Removal Tool) stands a good chance of being able to find/remove the malicious software. If you can find which machine the malware is on.
作者: jhonlone    时间: 2009-3-2 20:59
建议先检查一下路由器以及邮件服务器的配置,并对服务器及客户端查毒,以防类似问题再发生
作者: 钉子    时间: 2009-3-2 22:49
如果对向只有一个公网IP或是以路由器为网关,就有可能把路由器的IP当成是邮件服务器IP。

www.spamhaus.org XBL(Exploits Block List):它是针对因为安全问题被劫持(比如僵尸机)或是蠕虫/病毒,带有内置式垃圾邮件引擎和其他类型的木马来发垃圾邮机器的实时黑名单IP列表。它的数据主要来源于两个合作组织:cbl.abuseat.org及www.njabl.org.因为被列入XBL的服务器大多为被第三方劫持利用,所以有可能导致误判断。
作者: xiangrui    时间: 2009-3-3 09:18
原帖由 钉子 于 2009-3-2 22:49 发表
如果对向只有一个公网IP或是以路由器为网关,就有可能把路由器的IP当成是邮件服务器IP。

www.spamhaus.org XBL(Exploits Block List):它是针对因为安全问题被劫持(比如僵尸机)或是蠕虫/病毒,带有内置式垃圾邮 ...

钉子大哥,那我现在应该怎么做才能解决这个问题呢?我是否需要把公司的所有机器都断网杀毒啊?
我们公司前段时间员工使用http://www.myspace.com帮助客户向其他客户发送了一些广告类似的邮件,他们不是使用我们公司自己的邮箱,是使用Myspace的邮箱发的。这样做是不是有影响啊?
作者: 钉子    时间: 2009-3-3 10:04
我们公司前段时间员工使用http://www.myspace.com帮助客户向其他客户发送了一些广告类似的邮件,他们不是使用我们公司自己的邮箱,是使用Myspace的邮箱发的。这样做是不是有影响啊?
--这个应该没影响。

那我现在应该怎么做才能解决这个问题呢?我是否需要把公司的所有机器都断网杀毒啊?
--如果有可能,先排查服务器,再排查客户端。
作者: xiangrui    时间: 2009-3-3 11:18
谢谢钉子大哥,我先杀毒试试。
作者: xiangrui    时间: 2009-3-17 18:11
我把所有的机器都使用卡巴斯基和360安全卫士查毒了,没有查到。
前段时间,我们公司新建了一个邮箱叫production.sales邮箱,使用这个邮箱对外面发送了一些会议邀请和公司的简介。大概有400多封,这会不会有影响啊?
另外,有哪些敏感字会被当成垃圾邮件啊?sales是不是其中之一啊?

[ 本帖最后由 xiangrui 于 2009-3-17 18:13 编辑 ]
作者: 钉子    时间: 2009-3-18 00:56
这样就未能完全确认了,
作者: xiangrui    时间: 2009-3-19 09:54
原帖由 钉子 于 2009-3-18 00:56 发表
这样就未能完全确认了,

钉子大哥,有没有什么办法确认啊?我需要知道什么原因造成的,然后想办法解决这个问题。等你什么时候有空我们上线(QQ或者飞信)聊吧!非常感谢!
作者: xiangrui    时间: 2009-3-20 11:22
钉子大哥,我刚才使用http://member.dnsstuff.com/pages/dnsreport.php查过了,DNS Report有6个警告,还提示说我们的邮件服务器被列入了黑名单。如下图:但是我没有找到被哪个网站列为黑名单了,也没有找到怎么移除?你能帮帮我吗?谢谢!

dnsstuff.GIF (30.78 KB, 下载次数: 0)

dnsstuff.GIF

作者: 钉子    时间: 2009-3-20 14:50
把你的域名和IP发给我,我帮你查一下看目的地。
作者: xiangrui    时间: 2009-3-20 15:15
钉子大哥,我已经把我们的域名和IP发给你了。谢谢!
作者: 钉子    时间: 2009-3-20 16:35
你的域名没做SPF记录。但这应该不影响发送。

两个IP都只是被列到了five-ten-sg.com,而这个组织是把所有中国的IP段都列入的,所以不用担心,只有确认不接收中国邮件的客户才会使用。

Listed in blackholes.five-ten-sg.com, www.five-ten-sg.com : 127.0.0.2 : added 2001-04-19; china does not seem to care about spam - (ttl:465629) [0.0087 sec]
Listed in blackholes.five-ten-sg.com, www.five-ten-sg.com : 127.0.0.2 : added 2001-04-20; we do not accept mail from china - (ttl:465629) [0.0088 sec]
作者: 钉子    时间: 2009-3-20 16:44
因为你对外的IP还是用的是路由器IP,所以我建议你在防火墙上实现所有242外出的数据依然是242的公网IP。

如果路由器实现不了这个功能,我建议新建一个A记录(比如smtp.abc.com)并指向245的IP,然后把Mx记录指向Smtp.abc.com这个A记录,再为245的IP建一个反向解释指向到Smtp.abc.com。

在路由器上做端口转发,将25端口转发到内部的Exchange服务器。

并且Exhcnage的HELO信息改为你Mx所指向的A记录。修改HELO信息方法:

Exchange 2003:服务器-主机名-协议-SMTP---默认虚拟SMTP服务器---属性--传递-高级-完全限制的域名,如下图:



PS:Mail.abc.com的A记录不需要修改,主要是考虑现有用户出差或是在外连接时,可以直接连接Exchange。
作者: xiangrui    时间: 2009-3-23 10:47
谢谢钉子大哥,我会按照你的方法试试的。非常感谢!
作者: xiangrui    时间: 2009-3-25 10:36
钉子大哥,我今天已经向我们的ISP申请245的反向域名解析smtp.abc.com了。但是我有个疑问:
“然后把Mx记录指向Smtp.abc.com这个A记录”,就是把以前的MX记录修改指向smtp.abc.com吗?还需要新建一个MX记录指向mail.abc.com吗?如果不需要,之前242的反向解析至mail.abc.com还有作用吗?
作者: 钉子    时间: 2009-3-26 00:59
标题: 回复 17楼 xiangrui 的帖子
“然后把Mx记录指向Smtp.abc.com这个A记录”,就是把以前的MX记录修改指向smtp.abc.com吗?
---YES。

还需要新建一个MX记录指向mail.abc.com吗?
---不需要。

如果不需要,之前242的反向解析至mail.abc.com还有作用吗?
---有,这是我考虑建新的SMTP.abc.com来指向MX的原因。15楼我已经写了PS:Mail.abc.com的A记录不需要修改,主要是考虑现有用户出差或是在外连接时,可以直接连接Exchange。
作者: xiangrui    时间: 2009-3-31 16:50
钉子大哥,我现在正在做SPF,这样设置好后我在建SPF时,需要把245和smtp.abc.com都加进去对吧?那还需要把242和mail.abc.com加进去吗?
作者: xiangrui    时间: 2009-3-31 16:51
另外Sender ID和SPF是不是只要做一个就可以了啊?




欢迎光临 邮件服务器-邮件系统-邮件技术论坛(BBS) (http://bbs.5dmail.cn/) Powered by Discuz! X3.2