[TriLUG] recent "Poor Reputation Sender" bounces

Joseph Mack NA3T via TriLUG trilug at trilug.org
Tue Jul 9 11:46:35 EDT 2019


On Tue, 9 Jul 2019, ac via TriLUG wrote:

> this thread makes no sense.

I'm not surprised.

The error messages didn't tell me whether the source or the recipient were the 
problem. With the reverse DNS identifying one of the machines as rootbsd.net, 
which wasn't a name I associated with the sender or the recipient, I was lost.

Thanks for stepping in to continue to help straighten out the problem.

> 550 is a "hard bounce" - it is more commonly or generally used to
> indicate that there exists no such recipient....
>
> And, 550 csi.mimecast.org Poor Reputation Sender. -
> https://community.mimecast.com/docs/DOC-1369#550

There is no "Poor Reputation Sender" error listed there. Here's the nearest 
thing

"550 Local CT IP Reputation - (reject) Ongoing reputation checks have resulted 
in the message being rejected due to poor IP reputation. This could be 
subsequent to a 4xx error. Create an Auto Allow or Permitted Senders policy. You 
can request a review of your source IP ranges by completing our online form. "

I assume someone NAT'ing behind the 208.79.82.66 address is doing something that 
mimecast doesn't like (spam?).

> Has nothing to do with the pvt NAT ip but everything to do with the reputation of the public IP.
>
> It also has nothing to do with no reverse of the public IP (That has its own "code")

.
.

> Even setting a reverse or a different reverse should not change the current bounce.

That's good to know. I thought that for quite a while now, if you were going to 
send e-mail, your reverse DNS had to match your forward DNS.


BTW my mails sent directly to you get this error.

"
                    The mail system

<ac at main.me>: host mail.main.me[148.251.184.134] said: 550 Administrative
     prohibition (in reply to RCPT TO command)
"

Looking this up I find

"550 Administrative prohibition - envelope blocked The sender's email address or 
domain has triggered a Blocked Senders Policy, or there's a SPF hard rejection. 
Delete or modify the Block Sender Policy to exclude the sender address."

I don't have any control over the e-mail at wm7d.net, so you won't be getting 
any e-mails from me directly.

Are you really in Montenegro (your .me address)?

the main.me website doesn't tell me much about itself.

Joe

-- 
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant
map generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!


More information about the TriLUG mailing list