View Full Version : All mail SPAM according to bl.spamcop.net


anson
05-12-2004, 08:02 PM
I've found issues with the SPAM processing and wonder if anyone else is experiencing the same thing?

I set the blacklist server to bl.spamcop.net and likewise set 127.0.0.1 and the mail servers IP address. If the user selects Yes to use the blacklist server under Spam Options, then no matter where the mail comes from it is marked as spam and dropped in the spam mailbox. It doesn't seem to matter if there are keywords or not in the spam option configuration. I've used a number of valid domain emails to test, ie: prodigy.net, lycos.com, etc. All these test emails end up in the SPAM inbox. The only way to resolve the problem is to not use the blacklist server.

Any ideas?

Thanks!

Jafo
05-13-2004, 01:00 PM
Turn off the blacklisting, send yourself an email, and view the header of the email that arrives to messenger account. See if any of the IP's are offending SPAMCOP:

http://www.spamcop.net/w3m?action=checkblock&ip=127.0.0.1

If any of the IP's are blacklisted that are part of your mailservers or the routes they take, add them to the 127.0.0.1 variable in the change settings section.

anson
05-14-2004, 07:54 PM
Well, I followed your instructions and am still seeing the problem. I didn't see where any of the servers involved were blacklisted with spamcop. I have pasted below the header info from messenger. This header is from an email that arrived with "use blacklist server" set to Yes and was sent to the spam box. I don't see anything about Spamcop in the header? Should I? Again, same problem with three different email account domains, prodigy.net, yahoo.com and lycos.com. Further down I've pasted another email header from an email sent with "use blacklist server" set to No. Looks ~identical. Thanks for your time and assistance.

---- Use Blacklist Server = Yes --------
Return-path:
Envelope-to: anson@starlightmusic.com
Delivery-date: Fri, 14 May 2004 18:12:41 -0400
Received: from [216.136.226.107] (helo=web20725.mail.yahoo.com)
by alpha.sitelutions.com with smtp (Exim 4.24)
id 1BOkv1-0002Ko-BU
for anson@starlightmusic.com; Fri, 14 May 2004 18:12:39 -0400
Message-ID: <20040514221236.13234.qmail@web20725.mail.yahoo.com>
Received: from [4.158.54.142] by web20725.mail.yahoo.com via HTTP; Fri, 14 May 2004 15:12:36 PDT
Date: Fri, 14 May 2004 15:12:36 -0700 (PDT)
From: Test Account
Subject: Testing your settings
To: anson@starlightmusic.com
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1658167629-1084572756=:11992"

------ Use Blacklist Server = No ------
Return-path:
Envelope-to: anson@starlightmusic.com
Delivery-date: Fri, 14 May 2004 18:38:30 -0400
Received: from [216.136.226.118] (helo=web20728.mail.yahoo.com)
by alpha.sitelutions.com with smtp (Exim 4.24)
id 1BOlK1-0003fr-Nc
for anson@starlightmusic.com; Fri, 14 May 2004 18:38:30 -0400
Message-ID: <20040514223824.21645.qmail@web20728.mail.yahoo.com>
Received: from [4.158.54.142] by web20728.mail.yahoo.com via HTTP; Fri, 14 May 2004 15:38:24 PDT
Date: Fri, 14 May 2004 15:38:24 -0700 (PDT)
From: Test Account
Subject: Testing your settings - again and again
To: anson@starlightmusic.com
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1281711458-1084574304=:19641"

anson
05-14-2004, 08:42 PM
I just wanted to mention that I just found an email from worldwidecreations.com in my SPAM box. So it's all domains at this point. I'm stumped. Any ideas?

anson
05-14-2004, 08:52 PM
Oh, and here is the header for that message from WWC which ended up in the SPAM box.

----------
Return-path:
Envelope-to: starmail@starlightmusic.com
Delivery-date: Fri, 14 May 2004 11:51:46 -0400
Received: from herberos by alpha.sitelutions.com with local-bsmtp (Exim 4.24)
id 1BOeyO-0000xp-SS
for starmail@starlightmusic.com; Fri, 14 May 2004 11:51:46 -0400
Received: from [207.234.129.35] (helo=server1.worldwidecreations.com)
by alpha.sitelutions.com with esmtp (TLSv1:AES256-SHA:256)
(Exim 4.24)
id 1BOeyO-00051O-8f
for anson@starlightmusic.com; Fri, 14 May 2004 11:51:44 -0400
X-ClientAddr: 127.0.0.1
Received: from dedicated.worldwidecreations.com (localhost.localdomain [127.0.0.1])
by dedicated.worldwidecreations.com (8.12.10/8.12.10) with ESMTP id i4EFpxol030364
for ; Fri, 14 May 2004 08:51:59 -0700
Received: (from root@localhost)
by dedicated.worldwidecreations.com (8.12.10/8.12.10/Submit) id i4EFpxXl030362;
Fri, 14 May 2004 08:51:59 -0700
Date: Fri, 14 May 2004 08:51:59 -0700
Message-Id: <200405141551.i4EFpxXl030362@dedicated.worldwidecre ations.com>
To: anson@starlightmusic.com
From: "im@worldwidecreations.com"
Subject: Instant Messaging For Your Site!
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="------------A4A1A21301C64BCAEA67DF85"
X-WorldWideCreations-MailScanner-Information: Please contact the ISP for more information
X-WorldWideCreations-MailScanner: Found to be clean

Jafo
05-14-2004, 09:52 PM
Turn off the blacklisting feature, and then see if mail still goes to the SPAM folder, it should not. Otherwise, try a different blacklist provider such as spamhaus and see if you can replicate the problem.

anson
05-15-2004, 10:41 AM
When blacklisting is turned off at the Admin level, all mail is delivered to the inboxes. If blacklisting is turned on at the Admin level and Off at the user level all mail is delivered to inboxes. If blacklisting is on at the Admin level and On at the user level, all mail goes to the spam box without question.

I tried out Spamhaus and am having the same problem.

I used Spamhaus's test to verify and it states, "Uh-oh, your SBL block is not working!" when I sent a test email from messenger to the test account,
"nelson-sbl-test@crynwr.com". Not sure why or what that exactly means, but plain and simple, spam blocking is not working here.

Jafo
05-15-2004, 06:33 PM
I would like to take a look, probably tomorrow afternoon if you dont mind.

Go to our contact form on the site and send me FTP info and your messenger admin username and pass and I will see what's up.