Community Discussions and Support
Black list

Thank you John,

 

I am not sure how many times I had read through the manual and missed that.  That line has been added to the Tranflt.mer file.  

 

 

<p>Thank you John,</p><p> </p><p>I am not sure how many times I had read through the manual and missed that.  That line has been added to the Tranflt.mer file.  </p><p> </p><p> </p>

Good day one and all.  

Once again I have to turn to the forum to see if there is somebody that

can tell me as to what I am doing wrong.

 

Since my last post, I have been checking the logs and

overall I am a happy chappy.   Things are

being processed as I have wanted and expect. 

With the Exception being  the

Content Control blacklist.  I have just

one entry in there, at the present time, but it is not being caught by my

blacklist.  It is being caught by

SpamHouse , dropped and blocked.  This is

a snippet from the SMTP log:

T 20161108 054127 582058f1 Connection from 198.148.80.98

T 20161108 054128 582058f1 EHLO 192.168.0.171

T 20161108 054128 582058f1 MAIL FROM: xo@ore.net

E 20161108 054128 582058f1 Host 198.148.80.98 blocked by

SpamHaus-2-8 - dropped and blocked.

T 20161108 054128 582058f1 Connection closed with

198.148.80.98, 1 sec. elapsed.

E 20161108 054129 0 Connection from 198.148.80.98 refused

because of short-term restriction.

T 20161108 054223 582058f2 Connection from 186.218.212.56

 

Session log shows

05:41:27.376: --- 8 Nov 2016, 5:41:27.376 ---

05:41:27.376: Accepted connection from '198.148.80.98',

timeout 30 seconds.

05:41:27.376: Connection from 198.148.80.98, Tue Nov 08

05:41:27 2016<lf>

05:41:27.376: << 220 xxxx.xxx ESMTP server ready.<cr><lf>

05:41:28.016: >> EHLO

192.168.0.171<cr><lf>

05:41:28.016: << 250-xxxxxx.xxx Hello

192.168.0.171; ESMTPs are:<cr><lf>250-TIME<cr><lf>

05:41:28.016: << 250-SIZE<cr><lf>

05:41:28.016: << 250 HELP<cr><lf>

05:41:28.657: >> MAIL FROM:

xo@ore.net<cr><lf>

05:41:28.891: << 551 BARRED: 198.148.80.98 -

Blocked by SpamHaus.org See http://spamhaus.org for removal

instructions<cr><lf>

05:41:28.891: --- Connection closed normally at 8 Nov

2016, 5:41:28.891. ---

05:41:28.891:

 

In my blacklist I have xo@ore.net.   I have even tried different combinations

using the wild card placement. 

 

The reason I have chosen this address is it has shown up numerous

times, all from different connection IP address. The Hello greeting just about

always has been 192.168.0.171, with a few variances.    

 

The SMTP Server, Spam Control, Blacklist Definitions

order is:

Whitelist

BlackList

SpamHous 2-8

SpamCop

PSBL

SpamHouse Zen PBL

&lt;p style=&quot;margin: 0cm 0cm 10pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;Good day one and all.&amp;nbsp;&amp;nbsp; Once again I have to turn to the forum to see if there is somebody that can tell me as to what I am doing wrong.&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;Since my last post, I have been checking the logs and overall I am a happy chappy.&amp;nbsp;&amp;nbsp; Things are being processed as I have wanted and expect.&amp;nbsp; With the Exception being &amp;nbsp;the Content Control blacklist.&amp;nbsp; I have just one entry in there, at the present time, but it is not being caught by my blacklist.&amp;nbsp; It is being caught by SpamHouse , dropped and blocked.&amp;nbsp; This is a snippet from the SMTP log:&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;T 20161108 054127 582058f1 Connection from 198.148.80.98&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;T 20161108 054128 582058f1 EHLO 192.168.0.171&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;T 20161108 054128 582058f1 MAIL FROM: xo@ore.net&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;E 20161108 054128 582058f1 Host 198.148.80.98 blocked by SpamHaus-2-8 - dropped and blocked.&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;T 20161108 054128 582058f1 Connection closed with 198.148.80.98, 1 sec. elapsed.&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;E 20161108 054129 0 Connection from 198.148.80.98 refused because of short-term restriction.&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;T 20161108 054223 582058f2 Connection from 186.218.212.56&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;Session log shows&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:27.376: --- 8 Nov 2016, 5:41:27.376 ---&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:27.376: Accepted connection from &#039;198.148.80.98&#039;, timeout 30 seconds.&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:27.376: Connection from 198.148.80.98, Tue Nov 08 05:41:27 2016&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:27.376: &amp;lt;&amp;lt; 220 xxxx.xxx ESMTP server ready.&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.016: &amp;gt;&amp;gt; EHLO 192.168.0.171&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.016: &amp;lt;&amp;lt; 250-xxxxxx.xxx Hello 192.168.0.171; ESMTPs are:&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;250-TIME&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.016: &amp;lt;&amp;lt; 250-SIZE&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.016: &amp;lt;&amp;lt; 250 HELP&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.657: &amp;gt;&amp;gt; MAIL FROM: xo@ore.net&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.891: &amp;lt;&amp;lt; 551 BARRED: 198.148.80.98 - Blocked by SpamHaus.org See http://spamhaus.org for removal instructions&amp;lt;cr&amp;gt;&amp;lt;lf&amp;gt;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.891: --- Connection closed normally at 8 Nov 2016, 5:41:28.891. ---&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;05:41:28.891:&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;In my blacklist I have &lt;/font&gt;&lt;a&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;xo@ore.net&lt;/font&gt;&lt;/a&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;.&amp;nbsp;&amp;nbsp; I have even tried different combinations using the wild card placement.&amp;nbsp; &lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;The reason I have chosen this address is it has shown up numerous times, all from different connection IP address. The Hello greeting just about always has been 192.168.0.171, with a few variances.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;The SMTP Server, Spam Control, Blacklist Definitions order is:&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;Whitelist&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;BlackList&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;SpamHous 2-8&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;SpamCop&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;PSBL&lt;/font&gt;&lt;/p&gt; &lt;p style=&quot;margin: 0cm 0cm 0pt;&quot;&gt;&lt;font face=&quot;Calibri&quot; size=&quot;3&quot;&gt;SpamHouse Zen PBL&lt;/font&gt;&lt;/p&gt;

Content control is applied to the message by Mercury core after it has been received by MercuryS or MercuryD. To prevent MercuryS from accepting all connections from 198.148.80.98 go to MercuryS configuration / Connection control and add a restriction for that IP address with attribute "Refuse connections".


&lt;p&gt;Content control is applied to the message by Mercury core after it has been received by MercuryS or MercuryD. To prevent MercuryS from accepting all connections from&amp;nbsp;198.148.80.98 go to MercuryS configuration / Connection control and add a restriction for that IP address with attribute &quot;Refuse connections&quot;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;

Since you say that the originating IP address changes but the mail address remains the same, you might be better off adding that address to the MercuryS killfile.

 

Your logs should then look similar to this:-

 

T 20161111 161712 5823bc3d Connection from 218.38.243.204

T 20161111 161713 5823bc3d EHLO mata.com

T 20161111 161713 5823bc3d MAIL FROM: <info@apple.com>

E 20161111 161713 5823bc3d Killfile: Mail from '<info@apple.com>' rejected, talking to 218.38.243.204 

T 20161111 161714 5823bc3d Connection closed with 218.38.243.204, 2 sec. elapsed.

 

John. 

&lt;p&gt;Since you say that the originating IP address changes but the mail address remains the same, you might be better off adding that address to the MercuryS killfile.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Your logs should then look similar to this:-&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;T 20161111 161712 5823bc3d Connection from 218.38.243.204&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;T 20161111 161713 5823bc3d EHLO mata.com&lt;/span&gt;&lt;/p&gt;&lt;p&gt;T 20161111 161713 5823bc3d MAIL FROM: &amp;lt;info@apple.com&amp;gt;&lt;/p&gt;&lt;p&gt;E 20161111 161713 5823bc3d Killfile: Mail from &#039;&amp;lt;info@apple.com&amp;gt;&#039; rejected, talking to 218.38.243.204&amp;nbsp;&lt;/p&gt;&lt;p&gt;T 20161111 161714 5823bc3d Connection closed with 218.38.243.204, 2 sec. elapsed.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;John.&amp;nbsp;&lt;/p&gt;

I am using that for other address and it does work just fine. As I stated mail from xo@ore.net comes from different IP address. So can not block it with IP restriction.

HELO is usually from 192.168.0.171, but have seen it from 175 and other address too. 

The only consistent is the marl from.  That is why I want it in the black list.    

&lt;p&gt;I am using that for other address and it does work just fine. As I stated mail from xo@ore.net comes from different IP address. So can not block it with IP restriction. &lt;/p&gt;&lt;p&gt;HELO is usually from 192.168.0.171, but have seen it from 175 and other address too.&amp;nbsp; &lt;/p&gt;&lt;p&gt;The only consistent is the marl from.&amp;nbsp;&amp;nbsp;That is why I want it in the&amp;nbsp;black list.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/p&gt;

Okay, this suggestion just might work. I did not have that checked as an option for MercuryS to use. Just set it up now. Will advise if this works.

 

Thanks

 

&lt;p&gt;Okay, this suggestion just might work. I did not have that checked as an option for MercuryS to use. Just set it up now. Will advise if this works.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Thanks&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

Sr. Grumpy Bear,

You could also do it using transaction filtering. Add a line to the TRANSFLT.MER file like:-

M, "xo@ore.net", BS, "554 XO@ORE.NET Not Welcome Here - connection dropped." 

and make sure you have transaction level filtering enabled under MercuryS Compliance.

John. 

&lt;p&gt;Sr. Grumpy Bear,&lt;/p&gt;&lt;p&gt;You could also do it using transaction filtering. Add a line to the TRANSFLT.MER file&lt;span style=&quot;font-size: 10pt;&quot;&gt;&amp;nbsp;like:-&lt;/span&gt;&lt;/p&gt;&lt;p&gt;M, &quot;&lt;span style=&quot;font-family: Tahoma, Arial, Helvetica; font-size: 12.096px;&quot;&gt;xo@ore.net&lt;/span&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;&quot;, BS, &quot;554 XO@ORE.NET Not Welcome Here - connection dropped.&quot;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;and make sure you have transaction level filtering enabled under MercuryS Compliance.&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;John.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft