WCM Forum

WCM Forum (http://www.wcm.at/forum/index.php)
-   Internet (http://www.wcm.at/forum/forumdisplay.php?f=8)
-   -   Mail-Host gesucht... (http://www.wcm.at/forum/showthread.php?t=195831)

Wientanz 23.07.2006 19:18

Mail-Host gesucht...
 
Hallo liebe Leute!

Eine Frage: Wir haben das Problem, dass unser Webhoster kürzlich große Änderungen durchgeführt hat und dadurch manche Email-Adressen nicht erreichbar sind, zB @utanet.at, @univie.ac.at oder @wu-wien.ac.at
Kurz-Problem-Info für alle, die jetzt mit "Email-Setting im outlook checken" kommen: Zumindest diese Mailserver stellen eine Rückanfrage an unseren Mailserver, ob die Adresse existiert und erhalten aber aufgrund irgendeines DNS-Fehlers erreicht diese Anfrage nie uns, sondern geht ins Leere. fazit: es werden keine Mails von uns akzeptiert.

Wir wollen nun einfach einen guten Mail-Host finden und dessen IP in unsere DNS Daten eintragen. Ich hab schon in Google gesucht, fürchte aber, dass meine Suche viel zu spezifisch ist und ich unter den Suchergebnissen nix gescheites finde.

Bitte um kurze Hilfe, danke!

Genaue Fehlerbeschreibung des Techinikers:
Code:

Let us explain more about what's really happening in this instnace. Basically, the SMTP protocol lack sender authentication. Due to this spoofing or forging the sender and sending millions of junk emails to the world has become easy for spammers. To overcome this, there are several methods deployed by mail servers to verify authenticity of the senders. There are popular techniques like SPF, Greylisting, Domain Keys and some servers do their own method of checking if the sender addresss is valid which may or may not be RFC standard. Note that there is no worldwide accepted method which makes the mail routing and sender verification more complex if some servers decide to perform some new methods of sender verification technique.


In this case, all the mails sent from our servers to zidmx1.univie.ac.at [131.130.3.100] and a number of other hosts are being bounced with the error: 550 Sender verify failed. The original issue stated in the forum/ticket occured when your account was not yet migrated to the new platform (that's why it says
mail03.powweb.com) and hence this issue might be causing unmigrated customers too.


Normally when a mail server bounces mail for some reason, it does indication the proper reason as to why they are rejecting emails. We had a number of customers whose mails where being rejected by remote hosts due to the similar sender verification failure but with complete information on what exactly the sender servers were performing to check the sender address validity. Based on that, we found a bug on our mail implementation program and this was fixed by updating the mail program modules. Most of such issues were solved with this fix.


Moreover, mail servers normally verify the sender with a popular technique called null sender verification and we do not allow this by default (since it sends 80 million junk per day). Since we don't have any idea on why utanet.at set of mail servers are bouncing mails with non-descripitive error message "550 Sender verify failed" we believed that they might be performing null sender verification and added your domains to a list that allows such verification. Unfortuantely, this doesn't seem to be the case and the remote servers are still bouncing the mails from our servers. We created a new mailbox test@unisport.at and sent test message to a0002102@univie.ac.at and the email was bounced with this line in logs:
2006-07-03 22:35:06 1Fxakg-00056q-0x ** a0002102@univie.ac.at F=<test@unisport.at>
P=<SRS0=wH_tXG=AV=unisport.at=test@yourhostingaccount.com> R=lookuphost T=remote_smtp: SMTP error from remote
mail server after RCPT TO:<a0002102@univie.ac.at>: host zidmx1.univie.ac.at [131.130.3.100]: 550 Sender verify failed


While we understand that this is causing considerable issues for your mail routing, we simply do not have any idea on why their mail servers are rejecting mails. We had tried to contact them several times based on the contact information given from some other customers but there were no responses from their side or the contact address was probably invalid. However, since we have added your domains to this null sender allow list, any remote mail server that performs null sender check (while sending or receiving), will passthrough.


We did see the original note provided by their mail server admins in one of the earlier mails you had sent to us, but it seems that they were indicating that about legacy mail servers and it seems they are still caching the old DNS records somehow. Here is the explanation given from univie.ac.at's admins:
-------------------------------------------------
Jun 22 01:36:09 H=mail03.powweb.com (mail03.powweb.com)
[66.152.97.36] sender verify fail for <info@unisport.at>:
all relevant MX records point to non-existent hosts


The message "all relevant MX records point to non-existent hosts" =
relates to the MX (mail exchanger, the server that receives mail for your domain) =
of unisport.at, that is being able to be resolved right now:


$ dig -t MX unisport.at +short=20
10 mx.unisport.at.
$ telnet mx.unisport.at. 25
Trying 65.254.254.53...
Connected to mx.unisport.at.
Escape character is '^]'.
220 ESMTP Mon, 26 Jun 2006 10:46:04 -0400: UCE strictly prohibited
quit
221 mailinc17.yourhostingaccount.com closing connection
-------------------------------------------------
Please note that mail03.powweb.com (66.152.97.36) is no longer valid mail server for unisport.at domain on DNS. The unisport.at MX is mx.unisport.at which points back to 3 IPs 65.254.254.50, 65.254.254.51 and 65.254.254.52. The domain "unisport.at" MX records are valid on DNS and setup correctly.


We think, their mail servers seems to be connecting back to 66.152.97.36 (legacy mail server) due to bad DNS cache for sender verification. Though this explanation is from June 22 when your account was not migrated. We've disabled SMTP for unisport.at (to prevent legacy mail servers accepting mails) on legacy but that did not do any trick.


harry1983 24.07.2006 07:29

Wurde auf eurer IP schon ein PTR Eintrag (Reverse Lookup Eintrag) gesetzt?
Sollte dieser fehlen wundert es mich nicht warum euch die anderen Server ablehnen.

Wientanz 24.07.2006 17:17

Schreib mir mal mehr darüber. Wie gesagt, das sollte eigentlich die Aufgabe des Providers sein. Aber wenn Du mehr weisst, dann schick ich das dem leider nicht allwissenden Support. Wenn der alte Service wieder funktionieren würde, wäre das die bessere Lösung.

LG
Stefan

harry1983 24.07.2006 17:44

Da muss ich gleich den Provider verteidigen, ein PTR ist kein Pflichteintrag, und vom Provider aus wird der sicher nicht gesetzt.
Erst nach Wunsch.
geh mal auf www.dnsgoodies.com und teste dort mal deine IP ob diese einen Reverse Lookup Eintrag besitzt. Wenn nicht, schreib deinem Provider dass du einen benötigst und gib deine externe IP und den Alias Namen des Mailservers an (z.B: mail.domain.at)

Wientanz 24.07.2006 18:20

Hmm... hat keinen PTR Eintrag.
Kurzfassung der Situation:
Domain von nic.at geholt.
Provider ist powweb.com. Der aktuelle Mailserver hat eine eigene Adresse.

Hmm..., sorry, ich muss gestehen dass ich mich mit DNS nicht so gut auskenne. Muss ich mich jetzt bei nic.at melden, oder bei powweb.com?:confused:

harry1983 24.07.2006 19:23

Bei den Provider der IP Adresse.
Also Powweb

Wientanz 24.07.2006 20:37

Code:

Hello Steve,


PTR is a reverse IP lookup for a domain. This is actually something we do not support on our servers. The reason we cannot support this on our servers is because currently we have shared IP addresses. Generally everyone is attached to the same shared IP address.


I certainly apologize for any inconvenience this causes.


Thanks for your time,
Chris
Technical Specialist

So, das war vor der Umstellung aber auch der Fall und es ging... Also kann es ja damit nix zu tun haben, oder?

harry1983 24.07.2006 21:45

Welche Fehlermeldung bekommst du wenn du ein Mail schickst bzw. wenn dir jemand eines schickt?
Und um welche Domain geht es?

Wientanz 24.07.2006 22:44

"505 - Sender verify failed". Betrifft aber nur das Schicken von Mails an Domains, deren mailserver eine Anti-Spamfunktion besitzt, die beim Server nachfragt, ob die Adresse existiert.

Und es betrifft mehrere Domains von mir und Kunden von mir. Eben alle, die auf Powweb.com liegen.

harry1983 24.07.2006 23:34

Ich rate dir wechsel den Provider.
Da stimmt eindeutig etwas nicht mit deren Mailserver.


Alle Zeitangaben in WEZ +2. Es ist jetzt 08:35 Uhr.

Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© 2009 FSL Verlag