最近公司邮件总是被yahoo、hotmail、gmx.com、 web.de 等退信,退信中原因说明如:
[email protected]
Remote server replied: 554 For explanation visit http://postmaster.gmx.com/en/error-messages?ip=96.68.237.219&c=bl
[email protected]:
Remote server replied: 550 OU-002 (SNT0-MC3-F25) Unfortunately, messages from 96.47.234.219 weren't sent. Please contact your Internet service provider since part of their network is on our block list. You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors.
Remote server replied: 553 Mail from 96.54.217.214 not allowed - 5.7.1 [BL23] Connections not accepted from IP addresses on Spamhaus XBL; see http://postmaster.yahoo.com/errors/550-bl23.html [550]
[email protected] :
Remote server replied: 421 4.7.1 [TS03] All messages from 96.54.217.214 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html
错误码不同,却都是因为进了反垃圾邮件组织的黑名单,这样的组织有很多, 最著名的莫过于 spamhaus 和 CBL 。 如果遇到了屡次被退信的情况,可以在以下几个常用的地址查一下 IP 或 域名屏蔽状况:
http://www.dnsbl.info/dnsbl-database-check.php
http://www.dnsstuff.com/tools
http://www.spamhaus.org/lookup/
引起屏蔽的原因:
根据我的经验:
1. HELO name 不正确。 即 HELO server.domain.com —— 这是用于反向解析判断的,解析的ip应与邮件服务器ip相符合。许多欧洲的开放邮箱网站会拒绝不正确的HELO name, 国内的 qq、163邮箱不会因此退信
2. 无TXT记录。给域名添加 TXT 记录, 限制合法的IP。 如 IN "v=spf1 a mx ~all" (语法有很多) 设置好可以用nslook 检查域名的txt记录,godaddy的txt记录不会立即生效
nslook -type=txt
domain.com
3. 没有PTR记录。PTR很有必要,用于邮件的反向地址解析。使反向查找 x.x.x.x.in-addr.arpa 时能找到 应答服务器的响应。
4. 开启了邮箱中继。这个功能基本不用了。
5. 发送垃圾邮件和病毒邮件。
6. 如果是用的共享IP,或你服务器所在的域(这种情况极少)的用户违规, 你可能会承受他人违规带来的后果。
此时应该尽快检查域名的 txt 记录,邮件服务服务器名等, 至于DKIM,对进黑名单影响尚未看到。 接下来向屏蔽你IP的 spam 网站提交 Removal 申请。
下面引用 CBL (即 cbl.abuseat.org ) 的审核回信中得原因说明:
-
- The email server at this IP address contains a virus and has been sending out spam
- The email server at this IP address may be configured incorrectly
- The PC at this IP address may be infected with a virus or botnet software program
- An individual in the organization at this IP address may have a PC infected with a virus or botnet program
- This IP address may be a dynamic IP address which was previously utilized by a known spammer
- The marketing department of a company at this IP address may be sending out bulk emails that do not comply with the CAN-SPAM Act
- This IP address may have a insecure wireless network attached to it which could allow unknown users to use it's network connection to send out bulk email
- In some rare cases, your recipients' Barracuda Spam Firewall may be misconfigured
申请解除黑名单屏蔽,并不意味着你安全了,应该找出潜在的原因。 出狱一样,你不改,可能很快又进去
(http://www.cnblogs.com/antarctican/p/3598820.html)