Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Lisiting of our IP Ranges - some guidance please

1 view
Skip to first unread message

eci...@gmail.com

unread,
Aug 29, 2008, 8:45:45 AM8/29/08
to
Hi there,

we recently got added with some IPs to Level 1 which has increased to
Level 2. I guess I understand your policy and the reason why we got
listed and I dont want to question that. I just would like to ask for
some help to actually isolate and identify the problem. We are an
Email-Service-Provider in Europe and have hundreds of clients, so
investigation is a rather time consuming job.

We checked the logfiles of our mailservers for 'Access denied and
blocklisted' and we found some entries. However, to me it seems that
this message appears in general after a blocking took place. Now I
have several users where we were told '571 Access denied and
blocklisted - Do we have that user or not? Who knows :-).'

Is there any other response from your servers we could look for to
identify the message which caused the hassle?


Any help would be appreciated

thanks

--
Comments posted to news.admin.net-abuse.blocklisting
are solely the responsibility of their author. Please
read the news.admin.net-abuse.blocklisting FAQ at
http://www.blocklisting.com/faq.html before posting.

E-Mail Sent to this address will be added to the BlackLists

unread,
Aug 29, 2008, 9:06:16 PM8/29/08
to
eci...@gmail.com wrote:
> we recently got added with some IPs to Level 1
> which has increased to Level 2.

Which DNSbl?


> I guess I understand your policy and the reason
> why we got listed and I dont want to question that.
> I just would like to ask for some help to actually
> isolate and identify the problem.
> We are an Email-Service-Provider in Europe and have
> hundreds of clients, so investigation is a rather
> time consuming job.
>
> We checked the logfiles of our mailservers for
> 'Access denied and blocklisted' and we found some
> entries. However, to me it seems that this message
> appears in general after a blocking took place.
> Now I have several users where we were told '571
> Access denied and blocklisted - Do we have that
> user or not? Who knows :-).'
>
> Is there any other response from your servers we
> could look for to identify the message which
> caused the hassle?

Which DNSbl?

What IPs / CIDR / ASN ?

Whom do you think you might be talking to?

With the information you provided, it seems kind of hard
to guess much of anything.


> Nntp-Posting-Host: 195.140.184.10
no rDNS , 195.140.184.0/22 , AS15960

Ahh, I see that IP listed in UCEprotect's DNSbl.

<http://www.uceprotect.net/rblcheck.php?ipr=195.140.184.10>
<http://www.uceprotect.net/en/rblcheck.php?asn=15960>


Have you searched your mail server logs for UCEPROTECT-Policy Server ?

Seems easy enough to find, when I look for it.

e.g. 550 UCEPROTECT-Policy Server decided: 550 (V#.#-EXPO-####)
...
You hit a Spamtrap.
Counter to blacklisting increase for your IP.
421 Service not available, closing transmission channel

...
We have no user with that account here.
No PTR (Reverse-DNS) is assigned to your IP.
Welcome to UCEPROTECT-Level 1.

...
We have no user with that account here.
Your IP was detected to be a Dialup.
Welcome to UCEPROTECT-Level 1.


--
E-Mail Sent to this address <Blac...@Anitech-Systems.com>
will be added to the BlackLists.

0 new messages