Astaro User Bulletin Board

Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Mail Security: SMTP, POP3, Antispam and Antivirus

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-14-2008, 12:12 AM
Junior Member
 
Join Date: Nov 2002
Posts: 14
Default Sender verification error (recepient) for <...>

Hi,
When using the smtp proxy, some destinations are not reachable and I get the following bounce:

This is the mail system at host mymailhost.mydomain.tld.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The mail system

<other@mydomain.tld>: host mx1.otherIspDomain.tld[***.yyy.zzz.146] said:
550-Verification failed for <me@mydomain.tld> 550-Previous (cached) callout
verification failure 550 Sender verification error (recipient) for
me@mydomain.tld (in reply to MAIL FROM command)


Mails do arrive great when disabling the smtp proxy and delivering mail through Astaro to my server with P/DNAT

Is this a bug? I need all the fine features of Astaro to filter incoming mail traffic but do not like to fail on targets.

How can this problem be solved?

Rgd. Adrie
Reply With Quote
  #2 (permalink)  
Old 11-14-2008, 02:00 PM
BAlfson's Avatar
Senior Member
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 562
Default

Have you checked to make sure that your domain has the correct reverse DNS entry?

I have to admit that I'm confused. The first half of your post indicates that emails you send get bounced back to you. The second half talks about how you force the Astaro to deliver emails that would be blocked by the spam filter. Rather than disable the SMTP Proxy, why not whitelist the improperly-configured domain for RDNS/HELO?

Cheers- Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #3 (permalink)  
Old 11-14-2008, 02:23 PM
Junior Member
 
Join Date: Nov 2002
Posts: 14
Default

I have the forward and reverse dns records. The domain is <rcan_dot_nl>

The problem is indeed about bounced emails. However the receiving ispmailserver validates the mailsender by verifying the sender, in this case me_at_rcan_dot_nl, BY querying the Astaro, being the smtpproxy. The smtpproxy does not know about me_at_rcan_dot_nl and the message is then rejected. I think the Astaro should query the inside mailserver.

As you can see white-listing will not do.
Reply With Quote
  #4 (permalink)  
Old 11-14-2008, 04:39 PM
BAlfson's Avatar
Senior Member
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 562
Default

Sorry, I obviously didn't read your original post closely enough. I guess that the other company needs to either whitelist your domain or they need to upgrade/patch their mailserver.

Whether you want to allow Sender Verify requests is another story, and I don't know if Astaro can be configured to pass those requests. We stopped using it for reasons you can find in these Forums by searching on Sender Verify.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #5 (permalink)  
Old 11-18-2008, 10:32 PM
Junior Member
 
Join Date: Nov 2002
Posts: 14
Default

Bob,
Solved the issue. By disabling BATV in the "Advanced anti-spam features" at the bottom of the ant-spam tab the mails get to the proper destination. Without the option the isp-mailserver allows the mail in.

Thx for the support.
Reply With Quote
  #6 (permalink)  
Old 11-19-2008, 07:05 PM
BAlfson's Avatar
Senior Member
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 562
Default

I don't think you should have to do that, but if you don't mind losing that functionality and you don't want to ask the other people to whitelist your domain.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #7 (permalink)  
Old 11-20-2008, 02:30 PM
tom's Avatar
tom tom is offline
Super Moderator
 
Join Date: Nov 2000
Location: Heidelberg, Germany
Posts: 1,164
Default

The problem is that that the "other side" does sender address verification using the header sender ("From:" header). This is incompatible with BATV, and also with some mailing list implementations and some "robot" email. They should use the envelope sender instead.

You should be able to create an exception for BATV using a *@theirdomain.com mask entry, instead of turning it off entirely.
__________________
Tom Kistner
Product Development & Administrator
Astaro AG
Reply With Quote
  #8 (permalink)  
Old 11-20-2008, 08:34 PM
BAlfson's Avatar
Senior Member
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 562
Default

So, Tom, you're saying that if he leaves BATV enabled, but adds an exception for '*@theirdomain.com' for BATV, then the Astaro will send the verification his correspondant is requesting?

Cool - Thanks!

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
Reply

Tags
proxy, sender, smtp, verification

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 03:08 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.