最近公司郵件總是被yahoo、hotmail、gmx.com、 web.de 等退信,退信中原因說明如:
demon@gmx.net
Remote server replied: 554 For explanation visit http://postmaster.gmx.com/en/error-messages?ip=96.68.237.219&c=bl
demon@hotmail.com:
Remote server replied: 550 OU-002 (SNT0-MC3-F25) Unfortunately, messages from 96.47.234.219 weren't sent. Please contact your Internet service provider since part of their network is on our block list. You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors.
demon@yahoo.de
Remote server replied: 553 Mail from 96.54.217.214 not allowed - 5.7.1 [BL23] Connections not accepted from IP addresses on Spamhaus XBL; see http://postmaster.yahoo.com/errors/550-bl23.html [550]
demon@rocketmail.com :
Remote server replied: 421 4.7.1 [TS03] All messages from 96.54.217.214 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
錯誤碼不同,卻都是因為進了反垃圾郵件組織的黑名單,這樣的組織有很多, 最著名的莫過於 spamhaus 和 CBL 。 如果遇到了屢次被退信的情況,可以在以下幾個常用的地址查一下 IP 或 域名屏蔽狀況:
http://www.dnsbl.info/dnsbl-database-check.php
引起屏蔽的原因:
根據我的經驗:
1. HELO name 不正確。 即 HELO server.domain.com —— 這是用於反向解析判斷的,解析的ip應與郵件服務器ip相符合。許多歐洲的開放郵箱網站會拒絕不正確的HELO name, 國內的 qq、163郵箱不會因此退信
2. 無TXT記錄。給域名添加 TXT 記錄, 限制合法的IP。 如 IN "v=spf1 a mx ~all" (語法有很多) 設置好可以用nslook 檢查域名的txt記錄,godaddy的txt記錄不會立即生效
nslook -type=txt
domain.com
3. 沒有PTR記錄。PTR很有必要,用於郵件的反向地址解析。使反向查找 x.x.x.x.in-addr.arpa 時能找到 應答服務器的響應。
4. 開啟了郵箱中繼。這個功能基本不用了。
5. 發送垃圾郵件和病毒郵件。
6. 如果是用的共享IP,或你服務器所在的域(這種情況極少)的用戶違規, 你可能會承受他人違規帶來的后果。
此時應該盡快檢查域名的 txt 記錄,郵件服務服務器名等, 至於DKIM,對進黑名單影響尚未看到。 接下來向屏蔽你IP的 spam 網站提交 Removal 申請。
下面引用 CBL (即 cbl.abuseat.org ) 的審核回信中得原因說明:
- The email server at this IP address contains a virus and has been sending out spam
- The email server at this IP address may be configured incorrectly
- The PC at this IP address may be infected with a virus or botnet software program
- An individual in the organization at this IP address may have a PC infected with a virus or botnet program
- This IP address may be a dynamic IP address which was previously utilized by a known spammer
- The marketing department of a company at this IP address may be sending out bulk emails that do not comply with the CAN-SPAM Act
- This IP address may have a insecure wireless network attached to it which could allow unknown users to use it's network connection to send out bulk email
- In some rare cases, your recipients' Barracuda Spam Firewall may be misconfigured
申請解除黑名單屏蔽,並不意味着你安全了,應該找出潛在的原因。 出獄一樣,你不改,可能很快又進去