Hi jeff and all DA community...
I have a problem which could be a potential bug i do not explain...
I have a client, which is experiencing system error return messages due to users unknown or to defer due to policy infringement at yahoo and nate.com
let me show you logs :
Here is log for yahoo...
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE Completed
2008-02-13 10:35:18 1JPE1O-0007Fu-PB <= <> R=1JNluV-0006K2-UE U=mail P=local S=6893 T="Mail delivery failed: returning message to sender" from <> for [email protected]
2008-02-13 10:35:18 1JPE1O-0007Fu-PB => admin <[email protected]> F=<> R=virtual_user T=virtual_localdelivery S=6993
2008-02-13 10:35:18 1JPE1O-0007Fu-PB Completed
and nate.com
2008-02-13 10:27:48 1JPDu8-000717-Io <= [email protected] H=(nlueuph.net) [211.208.187.130] P=smtp S=1067 T="¢º±ÝÀ¶±Ç´ë~Ãâ(³â7.5~12%)49595" from <[email protected]> for [email protected]
2008-02-13 10:27:50 1JPDu8-000717-Io ** [email protected] F=<[email protected]> R=lookuphost T=remote_smtp: SMTP error from remote mail server after end of data: host smtp.nate.com [203.226.255.61]: 541 5.6.0 Your message was rejected by PATTERN FILTER
2008-02-13 10:27:50 1JPDuA-00071I-RI <= <> R=1JPDu8-000717-Io U=mail P=local S=2005 T="Mail delivery failed: returning message to sender" from <> for [email protected]
2008-02-13 10:27:50 1JPDu8-000717-Io Completed
2008-02-13 10:27:50 1JPDuA-00071I-RI => info <[email protected]> F=<> R=virtual_user T=virtual_localdelivery S=2104
2008-02-13 10:27:50 1JPDuA-00071I-RI Completed
Problem is following :
Account [email protected] doesn't exist on our servers.... But apparently there seems to be activity on this email...
Account [email protected] exists but has passwords changed every 2 days... latest set this morning is 13 caracteres long alpha-numerical... It is technically impossible this password could get hacked in less than 5 minutes...
Where is the problem...
What acl should i use to block these mail sendings from our servers ???
(i've check rbl status, and server ip seems still to be clean... Only considered as problem on yahoo filtering system)
Edit : I've tested adding domains and sender email [email protected] in blacklist senders, and this doesn't solve anything...
User has experienced 549 system error messages that he shouldn't have to receive...
This is very weird...
Thks for urgent response
Tdldp
I have a problem which could be a potential bug i do not explain...
I have a client, which is experiencing system error return messages due to users unknown or to defer due to policy infringement at yahoo and nate.com
let me show you logs :
Here is log for yahoo...
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3b.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE == [email protected] R=lookuphost T=remote_smtp defer (0): SMTP error from remote mail server after initial connection: host mx3a.mail.yahoo.co.kr [202.165.108.248]: 421 4.7.0 [TS01] Messages from 87.252.2.45 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE ** [email protected]: retry timeout exceeded
2008-02-13 10:35:18 1JNluV-0006K2-UE Completed
2008-02-13 10:35:18 1JPE1O-0007Fu-PB <= <> R=1JNluV-0006K2-UE U=mail P=local S=6893 T="Mail delivery failed: returning message to sender" from <> for [email protected]
2008-02-13 10:35:18 1JPE1O-0007Fu-PB => admin <[email protected]> F=<> R=virtual_user T=virtual_localdelivery S=6993
2008-02-13 10:35:18 1JPE1O-0007Fu-PB Completed
and nate.com
2008-02-13 10:27:48 1JPDu8-000717-Io <= [email protected] H=(nlueuph.net) [211.208.187.130] P=smtp S=1067 T="¢º±ÝÀ¶±Ç´ë~Ãâ(³â7.5~12%)49595" from <[email protected]> for [email protected]
2008-02-13 10:27:50 1JPDu8-000717-Io ** [email protected] F=<[email protected]> R=lookuphost T=remote_smtp: SMTP error from remote mail server after end of data: host smtp.nate.com [203.226.255.61]: 541 5.6.0 Your message was rejected by PATTERN FILTER
2008-02-13 10:27:50 1JPDuA-00071I-RI <= <> R=1JPDu8-000717-Io U=mail P=local S=2005 T="Mail delivery failed: returning message to sender" from <> for [email protected]
2008-02-13 10:27:50 1JPDu8-000717-Io Completed
2008-02-13 10:27:50 1JPDuA-00071I-RI => info <[email protected]> F=<> R=virtual_user T=virtual_localdelivery S=2104
2008-02-13 10:27:50 1JPDuA-00071I-RI Completed
Problem is following :
Account [email protected] doesn't exist on our servers.... But apparently there seems to be activity on this email...
Account [email protected] exists but has passwords changed every 2 days... latest set this morning is 13 caracteres long alpha-numerical... It is technically impossible this password could get hacked in less than 5 minutes...
Where is the problem...
What acl should i use to block these mail sendings from our servers ???
(i've check rbl status, and server ip seems still to be clean... Only considered as problem on yahoo filtering system)
Edit : I've tested adding domains and sender email [email protected] in blacklist senders, and this doesn't solve anything...
User has experienced 549 system error messages that he shouldn't have to receive...
This is very weird...
Thks for urgent response
Tdldp
Last edited: