This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

black.rbl.ctipd.astaro.local blocking emails for one user but not another

I have someone emailing to my company from a @bellsouth.net address (which is actually yahoo email servers) and it is getting: Rejected: RBL (black.rbl.ctipd.astaro.local). Another person is able to receive email from this same email address with no problems.

Here are the errors I see in the SMTP Log:

Delivery from 98.139.44.112 rejected. Check at Check IP Reputation | Commtouch - Internet Security Solutions. Reference code: tid=0001.0A090301.4DA1F949.0153

Delivery from 98.139.44.129 rejected. Check at Check IP Reputation | Commtouch - Internet Security Solutions. Reference code: tid=0001.0A090304.4DA39AA2.0003

Yet when I check the IP addresses at commtouch, I get the result of:

IP Query Result:
 IP Address: 98.139.44.112
 Risk Level: No Risk
 Description: This IP address has not been used for sending Spam

IP Query Result:
 IP Address: 98.139.44.129
 Risk Level: No Risk
 Description: This IP address has not been used for sending Spam


This thread was automatically locked due to age.
Parents
  • EDIT 2020 June 02: CommTouch was purchased several years ago and is now named Cyren.  I have corrected the link.

    That IP currently is listed by CommTouch as "High RisK".  They probably have an automated tool that monitors some honeypots and populates their list quickly when an outbreak is seen.

    You can check and report false positives here.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • EDIT 2020 June 02: CommTouch was purchased several years ago and is now named Cyren.  I have corrected the link.

    That IP currently is listed by CommTouch as "High RisK".  They probably have an automated tool that monitors some honeypots and populates their list quickly when an outbreak is seen.

    You can check and report false positives here.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data