Good day one and all.
Once again I have to turn to the forum to see if there is somebody that
can tell me as to what I am doing wrong.
Since my last post, I have been checking the logs and
overall I am a happy chappy. Things are
being processed as I have wanted and expect.
With the Exception being the
Content Control blacklist. I have just
one entry in there, at the present time, but it is not being caught by my
blacklist. It is being caught by
SpamHouse , dropped and blocked. This is
a snippet from the SMTP log:
T 20161108 054127 582058f1 Connection from 198.148.80.98
T 20161108 054128 582058f1 EHLO 192.168.0.171
T 20161108 054128 582058f1 MAIL FROM: xo@ore.net
E 20161108 054128 582058f1 Host 198.148.80.98 blocked by
SpamHaus-2-8 - dropped and blocked.
T 20161108 054128 582058f1 Connection closed with
198.148.80.98, 1 sec. elapsed.
E 20161108 054129 0 Connection from 198.148.80.98 refused
because of short-term restriction.
T 20161108 054223 582058f2 Connection from 186.218.212.56
Session log shows
05:41:27.376: --- 8 Nov 2016, 5:41:27.376 ---
05:41:27.376: Accepted connection from '198.148.80.98',
timeout 30 seconds.
05:41:27.376: Connection from 198.148.80.98, Tue Nov 08
05:41:27 2016<lf>
05:41:27.376: << 220 xxxx.xxx ESMTP server ready.<cr><lf>
05:41:28.016: >> EHLO
192.168.0.171<cr><lf>
05:41:28.016: << 250-xxxxxx.xxx Hello
192.168.0.171; ESMTPs are:<cr><lf>250-TIME<cr><lf>
05:41:28.016: << 250-SIZE<cr><lf>
05:41:28.016: << 250 HELP<cr><lf>
05:41:28.657: >> MAIL FROM:
xo@ore.net<cr><lf>
05:41:28.891: << 551 BARRED: 198.148.80.98 -
Blocked by SpamHaus.org See http://spamhaus.org for removal
instructions<cr><lf>
05:41:28.891: --- Connection closed normally at 8 Nov
2016, 5:41:28.891. ---
05:41:28.891:
In my blacklist I have xo@ore.net. I have even tried different combinations
using the wild card placement.
The reason I have chosen this address is it has shown up numerous
times, all from different connection IP address. The Hello greeting just about
always has been 192.168.0.171, with a few variances.
The SMTP Server, Spam Control, Blacklist Definitions
order is:
Whitelist
BlackList
SpamHous 2-8
SpamCop
PSBL
SpamHouse Zen PBL
<p style="margin: 0cm 0cm 10pt;"><font face="Calibri" size="3">Good day one and all.&nbsp;&nbsp;
Once again I have to turn to the forum to see if there is somebody that
can tell me as to what I am doing wrong.</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">&nbsp;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">Since my last post, I have been checking the logs and
overall I am a happy chappy.&nbsp;&nbsp; Things are
being processed as I have wanted and expect.&nbsp;
With the Exception being &nbsp;the
Content Control blacklist.&nbsp; I have just
one entry in there, at the present time, but it is not being caught by my
blacklist.&nbsp; It is being caught by
SpamHouse , dropped and blocked.&nbsp; This is
a snippet from the SMTP log:</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">T 20161108 054127 582058f1 Connection from 198.148.80.98</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">T 20161108 054128 582058f1 EHLO 192.168.0.171</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">T 20161108 054128 582058f1 MAIL FROM: xo@ore.net</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">E 20161108 054128 582058f1 Host 198.148.80.98 blocked by
SpamHaus-2-8 - dropped and blocked.</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">T 20161108 054128 582058f1 Connection closed with
198.148.80.98, 1 sec. elapsed.</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">E 20161108 054129 0 Connection from 198.148.80.98 refused
because of short-term restriction.</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">T 20161108 054223 582058f2 Connection from 186.218.212.56</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">&nbsp;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">Session log shows</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:27.376: --- 8 Nov 2016, 5:41:27.376 ---</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:27.376: Accepted connection from '198.148.80.98',
timeout 30 seconds.</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:27.376: Connection from 198.148.80.98, Tue Nov 08
05:41:27 2016&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:27.376: &lt;&lt; 220 xxxx.xxx ESMTP server ready.&lt;cr&gt;&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.016: &gt;&gt; EHLO
192.168.0.171&lt;cr&gt;&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.016: &lt;&lt; 250-xxxxxx.xxx Hello
192.168.0.171; ESMTPs are:&lt;cr&gt;&lt;lf&gt;250-TIME&lt;cr&gt;&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.016: &lt;&lt; 250-SIZE&lt;cr&gt;&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.016: &lt;&lt; 250 HELP&lt;cr&gt;&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.657: &gt;&gt; MAIL FROM:
xo@ore.net&lt;cr&gt;&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.891: &lt;&lt; 551 BARRED: 198.148.80.98 -
Blocked by SpamHaus.org See http://spamhaus.org for removal
instructions&lt;cr&gt;&lt;lf&gt;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.891: --- Connection closed normally at 8 Nov
2016, 5:41:28.891. ---</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">05:41:28.891:</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">&nbsp;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">In my blacklist I have </font><a><font face="Calibri" size="3">xo@ore.net</font></a><font face="Calibri" size="3">.&nbsp;&nbsp; I have even tried different combinations
using the wild card placement.&nbsp; </font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">&nbsp;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">The reason I have chosen this address is it has shown up numerous
times, all from different connection IP address. The Hello greeting just about
always has been 192.168.0.171, with a few variances.&nbsp; &nbsp;&nbsp;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">&nbsp;</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">The SMTP Server, Spam Control, Blacklist Definitions
order is:</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">Whitelist</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">BlackList</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">SpamHous 2-8</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">SpamCop</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">PSBL</font></p>
<p style="margin: 0cm 0cm 0pt;"><font face="Calibri" size="3">SpamHouse Zen PBL</font></p>