This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unusual number of Bounced email with error "Rejected: RBL (cbl.abuseat.org)"

All of the sudden, I'm seeing a high percentage of emails, mostly legitimate, with the error message "Rejected: RBL (cbl.abuseat.org)".

Can anyone tell me what's going on?



This thread was automatically locked due to age.
  • Check 2 or more blocked IP to cbl.abuseat.org and post the results for us

  • how come? 

    In Rejected RBL there are no IP's or the corresponding isnt blacklisted?

  • Sorry, I thought you meant that my address was on a block list.

    Meanwhile, I turned off the RBL check and the problem seems to have gone away.  Thanks for helping.

  • The RBL check is almost "free" in that it's the very first line of defense.   A single packet is received.  If the IP is listed in the cached black.rbl.ctipd.astaro.local, no request even goes out to an RBL service and the email is rejected before another packet is received.  If it is not, the list of configured RBLs is queried until one responds that the IP is blacklisted or until all configured RBLs have been queried.

    I would urge you to check to see whether there's a problem with a specific address or two or if you might need to just reboot your UTM.  If this problem began after an Up2Date, I would try restoring the backup made just prior to that.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks Bob for answering.  t wasn't one or two addresses that were bouncing, it was about 75% of all incoming email.  The only change I made right before this happened was changing my DNS forwarders.  I changed them back at the same time I shut off the RBL check.  I also rebooted.  The problem seems to have gone away but I'm too scared of checking the RBL box again!

  • Enough time has elapsed, Steve, that I think you can try it again.  You can open the SMTP Live Log before you do this and watch to see if you're getting too many rejections.  Just put rbl in the 'Filter' box and touch return.

    Also, you might want to consider DNS best practice.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA