Community Discussions and Support
Help with tracing mail delivery

Hey, Rolf, thanks a lot for answering.

I did not realise that the MX record order could be ignored.

We had locked down Mercury so that SMTP connections were only accepted from MessageLabs' IP addresses. However, because our staff use IMAP and they have dynamic addresses assigned by their ISP's for their home machines I opened it up again so they could authenticate and send mail. I'm going to lock it down again and update their IP addresses in Mercury as required.

This is the first email that has been delivered directly to our IP address. I guess we've been lucky that no more arrived.

Thanks again for the help.

<P>Hey, Rolf, thanks a lot for answering.</P> <P>I did not realise that the MX record order could be ignored.</P> <P>We had locked down Mercury so that SMTP connections were only accepted from MessageLabs' IP addresses. However, because our staff use IMAP and they have dynamic addresses assigned by their ISP's for their home machines I opened it up again so they could authenticate and send mail. I'm going to lock it down again and update their IP addresses in Mercury as required.</P> <P>This is the first email that has been delivered directly to our IP address. I guess we've been lucky that no more arrived.</P> <P>Thanks again for the help.</P>

Hi, folks

I have an issue that I don't understand and hope someone here can help me.

Our setup is as follows - we use Pegasus Mail and Mercury/32. All mail is filtered by MessageLabs.

MX records are set as follows:

MX10 MessageLabs

MX20 MessageLabs

MX30 mail.ourdomain.co.uk


Yesterday, a message was delivered directly to our mail server. As I understand it, this should only happen if MX10 and MX20 fail. We received many messages at the same time that were routed through MessageLabs. All mail received via MessageLabs has a banner appended to it, the offending message did not contain the banner or the usual MessageLab server information in the headers:

X-SPAMWALL: Passed through antiSPAM test by SpamHalter 4.4.0 on apsarchaeology.co.uk (1425)

X-SPAMWALL: probability - 0.0%

Return-path: <update@facebookmail.com>

Received: from facebookmail.com (213.122.160.98) by apsarchaeology.co.uk (Mercury/32 v4.62) with ESMTP ID MG000657;

   5 Aug 2010 13:46:36 +0100

From: update@facebookmail.com

To: greenman@apsarchaeology.co.uk

Subject: You have got a new message on Facebook!

Date: Thu, 5 Aug 2010 13:47:36 +0100

MIME-Version: 1.0

Content-Type: multipart/mixed;

boundary="----=_NextPart_000_0004_739DBACD.54AA3719"

X-Priority: 3

X-MSMail-Priority: Normal


 

Does anyone know how this can happen?

I thought that mail addressed to our domain would be subject to the MX records.

Thanks

&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium Arial; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-text-size-adjust: auto; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt; &lt;DIV style=&quot;PADDING-BOTTOM: 8px; BACKGROUND-COLOR: rgb(255,255,255); PADDING-LEFT: 8px; PADDING-RIGHT: 8px; FONT-FAMILY: Arial, Helvetica, sans-serif; FONT-SIZE: 10pt; PADDING-TOP: 8px&quot;&gt; &lt;P&gt;Hi, folks&lt;/P&gt; &lt;P&gt;I have an issue that I don&#039;t understand and hope someone here can help me.&lt;/P&gt; &lt;P&gt;Our setup is as follows - we use Pegasus Mail and Mercury/32. All mail is filtered by MessageLabs.&lt;/P&gt; &lt;P&gt;MX records are set as follows:&lt;/P&gt; &lt;P&gt;MX10 MessageLabs&lt;/P&gt; &lt;P&gt;MX20 MessageLabs&lt;/P&gt; &lt;P&gt;MX30 mail.ourdomain.co.uk&lt;/P&gt; &lt;P&gt; &lt;/P&gt; &lt;P&gt;Yesterday, a message was delivered directly to our mail server. As I understand it, this should only happen if MX10 and MX20 fail. We received many messages at the same time that were routed through MessageLabs. All mail received via MessageLabs has a banner appended to it, the offending message did not contain the banner or the usual MessageLab server information in the headers:&lt;/P&gt; &lt;P&gt;X-SPAMWALL: Passed through antiSPAM test by SpamHalter 4.4.0 on apsarchaeology.co.uk (1425)&lt;/P&gt; &lt;P&gt;X-SPAMWALL: probability - 0.0%&lt;/P&gt; &lt;P&gt;Return-path: &amp;lt;update@facebookmail.com&amp;gt;&lt;/P&gt; &lt;P&gt;Received: from facebookmail.com (213.122.160.98) by apsarchaeology.co.uk (Mercury/32 v4.62) with ESMTP ID MG000657;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&amp;nbsp; 5 Aug 2010 13:46:36 +0100&lt;/P&gt; &lt;P&gt;From: update@facebookmail.com&lt;/P&gt; &lt;P&gt;To: greenman@apsarchaeology.co.uk&lt;/P&gt; &lt;P&gt;Subject: You have got a new message on Facebook!&lt;/P&gt; &lt;P&gt;Date: Thu, 5 Aug 2010 13:47:36 +0100&lt;/P&gt; &lt;P&gt;MIME-Version: 1.0&lt;/P&gt; &lt;P&gt;Content-Type: multipart/mixed;&lt;/P&gt; &lt;P&gt;&lt;SPAN style=&quot;WHITE-SPACE: pre&quot; class=Apple-tab-span&gt;&lt;/SPAN&gt;boundary=&quot;----=_NextPart_000_0004_739DBACD.54AA3719&quot;&lt;/P&gt; &lt;P&gt;X-Priority: 3&lt;/P&gt; &lt;P&gt;X-MSMail-Priority: Normal&lt;/P&gt; &lt;DIV&gt; &lt;/DIV&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Does anyone know how this can happen?&lt;/P&gt; &lt;P&gt;I thought that&amp;nbsp;mail&amp;nbsp;addressed to our domain would be subject to the MX records.&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt;&lt;/DIV&gt;&lt;/SPAN&gt;

The MX priority is supposed to be respected by the sender but it's entirely up to them to do it or not. Some spam bots always connect to the lowest priority MX server, as they hope a backup server will have less effective antispam measures.

/Rolf 

&lt;p&gt;The MX priority is supposed to be respected by the sender but it&#039;s entirely up to them to do it or not. Some spam bots always connect to the lowest priority MX server, as they hope a backup server will have less effective antispam measures.&lt;/p&gt;&lt;p&gt;/Rolf&amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft