This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM 9 cannot send mail to gmail mail accounts

Hi, 

i am not able to send mail with the UTM 9.701 to any gmail account.

 

any hints ? thank you !

 
2020:01:25-16:04:07 hostname exim-out[6797]: 2020-01-25 16:04:07 1ivMU0-000269-2K gmail.de [216.58.207.37]:25 Connection timed out
2020:01:25-16:04:07 hostname exim-out[6796]: 2020-01-25 16:04:07 1ivMU0-000269-2K == user@gmail.de R=dnslookup T=remote_smtp defer (110): Connection timed out
2020:01:25-16:04:07 hostname exim-out[7134]: 2020-01-25 16:04:07 1ivLvK-0004JP-Fh == user@gmail.de R=dnslookup T=remote_smtp defer (-53): retry time not reached for any host
 
Edit:
 
not on any blacklist / spamlist
DNS is working


This thread was automatically locked due to age.
Parents
  • Hallo Wolfgang,

    Holger pointed out the lack of an MX record for gmail.de.  In addition, there's a TXT record v=spf1 -all.

    It appears that Google registered gmail.de to prevent domain squatting by people like German businessman Daniel Giersch with whom Google had a long-running lawsuit that was settled in 2012.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • HI Bob, 

    i have the same issues with gmail.com, same error messages like in  t he  1 post.

     as u can see here, log from today :

     

    2020:02:24-19:38:20 matrix exim-out[10946]: 2020-02-24 19:38:20 1j6IcW-0002qW-Fp ** user@gmail.com P=<prvs=0323833c78=post@domain.de> R=dnslookup T=remote_smtp: retry time not reached for any host after a long failure period
    2020:02:24-19:38:20 matrix exim-out[10949]: 2020-02-24 19:38:20 1j6IcW-0002qb-2U <= <> R=1j6IcW-0002qW-Fp U=exim P=local S=1527
    2020:02:24-19:38:20 matrix exim-out[10946]: 2020-02-24 19:38:20 1j6IcW-0002qW-Fp Completed

     

    any ideas on that ?

     

    it would be also nice to know how to do some basic exim things in the UTM 9,  such as:

    /usr/sbin/exim_tidydb -t 1d /var/spool/exim retry > /dev/null
    /usr/sbin/exim_tidydb -t 1d /var/spool/exim reject > /dev/null
    /usr/sbin/exim_tidydb -t 1d /var/spool/exim wait-remote_smtp > /dev/null
    /scripts/eximup --force


  • Well this changed to a utm 9 DNS problem:

     

    on the firewall:

    FW:/root # dig mx gmail.com

    ; <<>> DiG 9.9.6-P1 <<>> mx gmail.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56229
    ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 4096
    ;; QUESTION SECTION:
    ;gmail.com. IN MX

    ;; AUTHORITY SECTION:
    gmail.com. 60 IN SOA gmail.com. do-not-reply.fw-notify.net. 1582573347 10800 900 604800 60

    ;; Query time: 0 msec
    ;; SERVER: 127.0.0.1#53(127.0.0.1)
    ;; WHEN: Mon Feb 24 21:27:31 CET 2020
    ;; MSG SIZE rcvd: 100

    Fw :/root

     doesn't matter what forwarder i use in the forwarder tab

     

    same request on my internal nameserver:

     

    root@se:/etc/bind# dig mx gmail.com

    ; <<>> DiG 9.11.5-P4-5.1-Debian <<>> mx gmail.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 59123
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 4, ADDITIONAL: 9

    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 4096
    ; COOKIE: 3b17a2ab9ad2aae29d83ab3b5e5432594cb1b9d2589e298c (good)
    ;; QUESTION SECTION:
    ;gmail.com. IN MX

    ;; ANSWER SECTION:
    gmail.com. 2989 IN MX 5 gmail-smtp-in.l.google.com.
    gmail.com. 2989 IN MX 10 alt1.gmail-smtp-in.l.google.com.
    gmail.com. 2989 IN MX 40 alt4.gmail-smtp-in.l.google.com.
    gmail.com. 2989 IN MX 30 alt3.gmail-smtp-in.l.google.com.
    gmail.com. 2989 IN MX 20 alt2.gmail-smtp-in.l.google.com.

    ;; AUTHORITY SECTION:
    gmail.com. 172189 IN NS ns3.google.com.
    gmail.com. 172189 IN NS ns2.google.com.
    gmail.com. 172189 IN NS ns4.google.com.
    gmail.com. 172189 IN NS ns1.google.com.

    ;; ADDITIONAL SECTION:
    ns1.google.com. 345095 IN A 216.239.32.10
    ns2.google.com. 345095 IN A 216.239.34.10
    ns3.google.com. 345095 IN A 216.239.36.10
    ns4.google.com. 345095 IN A 216.239.38.10
    ns1.google.com. 172189 IN AAAA 2001:4860:4802:32::a
    ns2.google.com. 172189 IN AAAA 2001:4860:4802:34::a
    ns3.google.com. 172189 IN AAAA 2001:4860:4802:36::a
    ns4.google.com. 172189 IN AAAA 2001:4860:4802:38::a

    ;; Query time: 0 msec
    ;; SERVER: 127.0.0.1#53(127.0.0.1)
    ;; WHEN: Mo Feb 24 21:30:17 CET 2020
    ;; MSG SIZE rcvd: 437

    root@se:/etc/bind#

     

    anyone who can bring me to the light ?

  • Wolfgang, how does your setup compare to DNS best practice?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply Children
No Data