This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RBL blacklist not working?

Hello, I have setup "zen.spamhaus.org" as RBL 2 days before. Every day still some SPAM passes, but if I check the IP I can see it is blacklisted at ZEN (blacklist check with mxtoolbox).

Here is an example smtp log:

2020:03:20-01:36:10 zptfw01 smtpd[26594]: SCANNER[26594]: 1jF5dy-0006uw-1t <= sanitatshauscdfhyhwshop@felezyabkit.co R=1jF5dr-0006um-0k P=INPUT S=2078
2020:03:20-01:36:10 zptfw01 smtpd[26594]: SCANNER[26594]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="63.82.48.202" from="sanitatshauscdfhyhwshop@felezyabkit.co" to="destination@address.de" subject="Gegen Schnarchen: Anti Schnarch-Armband" queueid="1jF5dy-0006uw-1t" size="2078"
2020:03:20-01:36:11 zptfw01 exim-out[26599]: 2020-03-20 01:36:11 1jF5dy-0006uw-1t => destination@address.de P=<sanitatshauscdfhyhwshop@felezyabkit.co> R=static_route_hostlist T=static_smtp H=192.168.17.13 [192.168.17.13]:25 X=TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128 C="250 2.6.0 <7541538srunljrfcrlkdlriazfdw@psskak.felezyabkit.co> [InternalId=18193481465858, Hostname="
2020:03:20-01:36:11 zptfw01 exim-out[26599]: 2020-03-20 01:36:11 1jF5dy-0006uw-1t Completed

 

If I add an extra RBL is it directly active? do I need to do anything else? 



This thread was automatically locked due to age.
  • This is a DNS problem, not a UTM problem.  You need to disable DNS forwarding.   Ignore the advice in this forum and elsewhere to optimize your DNS peformance by using Google (8.8.8.8), CloudFlare (1.1.1.1), or to do DNS filtering with a service like Quad9 (9.9.9.9).

    The ZEN database is proprietary, and not visible to devices that request zone transfers.   Additionally, even if a forwarder resolves it correctly, it may introduce caching that produces time-lagged results.   By disabling forwarders, you ensure that Zen questions go to Zen and are resolved correctly. 

  • Doug, I don't know for sure, but you might be being misled by some of your previous use of other tools other than WebAdmin.

    I haven't seen this error before, but I might handle it a bit differently while retaining forwarders.  I would use a Request Route for zen.spanhaus.org and point it at a Network Group of a.gns.spamhaus.org through e.gns.spamhaus.org.  Otherwise I think you would need to fiddle at the command line to turn off the use of root hints and possibly tickle other things.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA