2015:01:27-23:14:09 7552-5 exim-in[4684]: 2015-01-27 23:14:09 SMTP connection from [216.109.115.45]:42512 (TCP/IP connection count = 1) 2015:01:27-23:14:09 7552-5 exim-in[7898]: 2015-01-27 23:14:09 [216.109.115.45] F= R= Verifying recipient address with callout 2015:01:27-23:14:10 7552-5 exim-in[7898]: 2015-01-27 23:14:10 1YGK13-00023O-2y DKIM: d=yahoo.com s=s2048 c=relaxed/relaxed a=rsa-sha256 t=1422418307 [verification succeeded] 2015:01:27-23:14:10 7552-5 exim-in[7898]: 2015-01-27 23:14:10 1YGK13-00023O-2y ctasd reports 'Unknown' RefID:str=0001.0A020206.54C86212.002A,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0 2015:01:27-23:14:10 7552-5 exim-in[7898]: 2015-01-27 23:14:10 1YGK13-00023O-2y Greylisting: Greylisted 216.109.115.45 2015:01:27-23:14:10 7552-5 exim-in[7898]: [1\34] 2015-01-27 23:14:10 1YGK13-00023O-2y H=nm44-vm9.bullet.mail.bf1.yahoo.com [216.109.115.45]:42512 F= temporarily rejected after DATA: Temporary local problem, please try again! Repeats a minute later, and then finally: 2015:01:27-23:17:54 7552-5 exim-in[4684]: 2015-01-27 23:17:54 SMTP connection from [216.109.115.45]:58297 (TCP/IP connection count = 1) 2015:01:27-23:17:55 7552-5 exim-in[8386]: 2015-01-27 23:17:55 [216.109.115.45] F= R= Verifying recipient address with callout 2015:01:27-23:17:55 7552-5 exim-in[8386]: 2015-01-27 23:17:55 1YGK4h-0002BG-0X DKIM: d=yahoo.com s=s2048 c=relaxed/relaxed a=rsa-sha256 t=1422418307 [verification succeeded] 2015:01:27-23:17:55 7552-5 exim-in[8386]: 2015-01-27 23:17:55 1YGK4h-0002BG-0X ctasd reports 'Unknown' RefID:str=0001.0A020206.54C862F3.0096,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0 2015:01:27-23:17:55 7552-5 exim-in[8386]: 2015-01-27 23:17:55 1YGK4h-0002BG-0X Greylisting: Successful greylist retry from 216.109.115.45 (original host was 216.109.115.45/32) 2015:01:27-23:17:55 7552-5 exim-in[8386]: 2015-01-27 23:17:55 1YGK4h-0002BG-0X work R=SCANNER T=SCANNER 2015:01:27-23:18:00 7552-5 smtpd[8391]: SCANNER[8391]: 1YGK4h-0002BG-0X Completed 2015:01:27-23:18:01 7552-5 exim-out[8394]: 2015-01-27 23:18:01 1YGK4m-0002BL-84 => valid-user@test-domain.com P= R=static_route_hostlist T=static_smtp H=68.166.142.198 [68.166.142.198]:25 X=TLSv1[[[[:D]]]]HE-RSA-AES256-SHA:256 C="250 OK id=1YGK4m-0002Js-Vp" 2015:01:27-23:18:01 7552-5 exim-out[8394]: 2015-01-27 23:18:01 1YGK4m-0002BL-84 Completed
2015:01:27-22:59:01 7552-5 exim-in[4684]: 2015-01-27 22:59:01 SMTP connection from [72.30.238.197]:59824 (TCP/IP connection count = 1) 2015:01:27-22:59:03 7552-5 exim-in[6625]: 2015-01-27 22:59:03 [72.30.238.197] F= R= Verifying recipient address with callout 2015:01:27-22:59:03 7552-5 exim-in[6625]: 2015-01-27 22:59:03 1YGJmR-0001ir-0Z DKIM: d=yahoo.com s=s2048 c=relaxed/relaxed a=rsa-sha256 t=1422417541 [verification succeeded] 2015:01:27-22:59:03 7552-5 exim-in[6625]: 2015-01-27 22:59:03 1YGJmR-0001ir-0Z ctasd reports 'Unknown' RefID:str=0001.0A020201.54C85E87.00CD,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0 2015:01:27-22:59:03 7552-5 exim-in[6625]: 2015-01-27 22:59:03 1YGJmR-0001ir-0Z Greylisting: Greylisted 72.30.238.197 2015:01:27-22:59:03 7552-5 exim-in[6625]: [1\34] 2015-01-27 22:59:03 1YGJmR-0001ir-0Z H=nm35.bullet.mail.bf1.yahoo.com [72.30.238.197]:59824 F= temporarily rejected after DATA: Temporary local problem, please try again! Repeats a minute later, and then finally: 2015:01:27-23:05:10 7552-5 exim-in[4684]: 2015-01-27 23:05:10 SMTP connection from [72.30.238.197]:44096 (TCP/IP connection count = 1) 2015:01:27-23:05:10 7552-5 exim-in[7289]: 2015-01-27 23:05:10 [72.30.238.197] F= R= Verifying recipient address with callout 2015:01:27-23:05:10 7552-5 exim-in[7289]: 2015-01-27 23:05:10 1YGJsM-0001tZ-23 DKIM: d=yahoo.com s=s2048 c=relaxed/relaxed a=rsa-sha256 t=1422417541 [verification succeeded] 2015:01:27-23:05:10 7552-5 exim-in[7289]: 2015-01-27 23:05:10 1YGJsM-0001tZ-23 ctasd reports 'Unknown' RefID:str=0001.0A020204.54C85FF6.0141,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0 2015:01:27-23:05:10 7552-5 exim-in[7289]: 2015-01-27 23:05:10 1YGJsM-0001tZ-23 Greylisting: Successful greylist retry from 72.30.238.197 (original host was 72.30.238.197/32) 2015:01:27-23:05:10 7552-5 exim-in[7289]: 2015-01-27 23:05:10 1YGJsM-0001tZ-23 work R=SCANNER T=SCANNER 2015:01:27-23:05:20 7552-5 smtpd[7295]: SCANNER[7295]: 1YGJsM-0001tZ-23 Completed 2015:01:27-23:05:21 7552-5 exim-out[7298]: 2015-01-27 23:05:21 1YGJsW-0001tf-7Y => non-existent@test-domain.com P= R=static_route_hostlist T=static_smtp H=68.166.142.198 [68.166.142.198]:25 X=TLSv1[[[[:D]]]]HE-RSA-AES256-SHA:256 C="250 OK id=1YGJsW-00026N-Ue" 2015:01:27-23:05:21 7552-5 exim-out[7298]: 2015-01-27 23:05:21 1YGJsW-0001tf-7Y Completed
2015-01-27 23:18:00 [21032] SMTP connection from [96.253.126.67]:45340 I=[68.166.142.198]:25 (TCP/IP connection count = 1) 2015-01-27 23:18:00 [8920] H=7552-5.UTM-server.com [96.253.126.67]:45340 I=[68.166.142.198]:25 Warning: Sender rate 1.7 / 1h 2015-01-27 23:18:01 [8920] 1YGK4m-0002Js-Vp H=7552-5.UTM-server.com [96.253.126.67]:45340 I=[68.166.142.198]:25 Warning: Message has been scanned: no virus or other harmful content was found 2015-01-27 23:18:01 [8920] 1YGK4m-0002Js-Vp for valid-user@test-domain.com 2015-01-27 23:18:01 [8922] cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1YGK4m-0002Js-Vp 2015-01-27 23:18:01 [8920] SMTP connection from 7552-5.UTM-server.com [96.253.126.67]:45340 I=[68.166.142.198]:25 closed by QUIT 2015-01-27 23:18:01 [8922] 1YGK4m-0002Js-Vp => test-sender (vaild-forwarder@test-domain.com, vaild-forwarder@test-domain.com, valid-user@test-domain.com) F= P= R=virtual_user T=virtual_userdelivery S=3181 QT=1s DT=0s 2015-01-27 23:18:01 [8922] 1YGK4m-0002Js-Vp => test-sender F= P= R=virtual_user T=virtual_userdelivery S=3181 QT=1s DT=0s 2015-01-27 23:18:01 [8922] 1YGK4m-0002Js-Vp Completed QT=1s
2015-01-27 23:05:20 [21032] SMTP connection from [96.253.126.67]:45332 I=[68.166.142.198]:25 (TCP/IP connection count = 2) 2015-01-27 23:05:20 [8083] H=7552-5.UTM-server.com [96.253.126.67]:45332 I=[68.166.142.198]:25 Warning: Sender rate 1.0 / 1h 2015-01-27 23:05:21 [8083] 1YGJsW-00026N-Ue H=7552-5.UTM-server.com [96.253.126.67]:45332 I=[68.166.142.198]:25 Warning: Message has been scanned: no virus or other harmful content was found 2015-01-27 23:05:21 [8083] 1YGJsW-00026N-Ue for non-existent@test-domain.com 2015-01-27 23:05:21 [8085] cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1YGJsW-00026N-Ue 2015-01-27 23:05:21 [8083] SMTP connection from 7552-5.UTM-server.com [96.253.126.67]:45332 I=[68.166.142.198]:25 closed by QUIT 2015-01-27 23:05:21 [8085] 1YGJsW-00026N-Ue ** non-existent@test-domain.com F=: Unrouteable address 2015-01-27 23:05:21 [8088] cwd=/var/spool/exim 7 args: /usr/sbin/exim -t -oem -oi -f <> -E1YGJsW-00026N-Ue 2015-01-27 23:05:21 [8088] 1YGJsX-00026S-57 <> R=1YGJsW-00026N-Ue U=mailnull P=local S=3930 M8S=0 T="Mail delivery failed: returning message to sender" from <> for test-sender@yahoo.com 2015-01-27 23:05:21 [8090] cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1YGJsX-00026S-57 2015-01-27 23:05:21 [8085] 1YGJsW-00026N-Ue Completed QT=1s 2015-01-27 23:05:23 [8090] 1YGJsX-00026S-57 => test-sender@yahoo.com F=<> P=<> R=dkim_lookuphost T=dkim_remote_smtp S=4356 H=mta7.am0.yahoodns.net [98.136.216.26]:25 X=TLSv1:RC4-SHA:128 CV=no DN="/C=US/ST=California/L=Sunnyvale/O=Yahoo Inc./OU=Information Technology/CN=*.am0.yahoodns.net" C="250 ok dirdel" QT=2s DT=2s 2015-01-27 23:05:23 [8090] 1YGJsX-00026S-57 Completed QT=2s
Best Regards - HTG Frustrated Sophos Partner seeing all the thingsthat brought me to Sophos slowly slip away. RIP astaro.org
Hi htguru, UTM verification with callout will not work if your internal mail server doesn't have some kind of spam agent that checks if the receipient exist in the organization (after "RCPT TO" SMTP command). Look at my example in the screenshot. Exchange server behind UTM will accept mail for non-existent user (it doesn't have any spam agent installed on it). It will later fail to deliver it, of course, and reply from the postmaster will be generated for the sender. You can test it from UTM shell with your mail server.
Just to add this....the goal of this company was to collect all wrong e-mails in postmaster mailbox (just in case that outside user misspelled e-mail address). You can see the screenshot from another production Exchange server where that check is enabled.
MAIL FROM:<> 250 Requested mail action okay, completed RCPT TO: 250 Requested mail action okay, completed QUIT 221 Service closing transmission channel
MAIL FROM: SIZE=4049 250 Requested mail action okay, completed RCPT TO: 250 Requested mail action okay, completed DATA 354 Start mail input; end with QUIT 221 Service closing transmission channel
MAIL FROM:<> 250 Requested mail action okay, completed RCPT TO: 550 Requested action not taken: mailbox unavailable or not local QUIT 221 Service closing transmission channel
2015:01:28-17:18:58 utm exim-in[32401]: 2015-01-28 17:18:58 [209.85.218.53] F= R= Verifying recipient address with callout 2015:01:28-17:18:58 utm exim-in[32401]: 2015-01-28 17:18:58 id="1003" severity="info" sys="SecureMail" sub="smtp" name="email rejected" srcip="209.85.218.53" from="vilic@externaldomain.rs" to="jsmith2@internaldomain.com" size="2829" reason="address_verification" extra="Address unknown"
H=mail-oi0-f54.google.com [209.85.218.54]:47734 F= rejected RCPT : Address unknown
The [verification succeeded] you're seeing in your logs is related to DKIM, not recipient verification.Cheers - Bob
2015-01-28 17:49:19 [21032] SMTP connection from [96.253.126.67]:45739 I=[68.166.142.198]:25 (TCP/IP connection count = 1) 2015-01-28 17:49:19 [7330] H=7552-5.UTM-server.com [96.253.126.67]:45739 I=[68.166.142.198]:25 Warning: Sender rate 1.9 / 1h 2015-01-28 17:49:19 [7330] H=7552-5.UTM-server.com [96.253.126.67]:45739 I=[68.166.142.198]:25 incomplete transaction (QUIT) from <> for valid-user@test-domain.com 2015-01-28 17:49:19 [7330] SMTP connection from 7552-5.UTM-server.com [96.253.126.67]:45739 I=[68.166.142.198]:25 closed by QUIT
2015-01-28 17:11:56 [21032] SMTP connection from [96.253.126.67]:45726 I=[68.166.142.198]:25 (TCP/IP connection count = 1) 2015-01-28 17:11:56 [3953] H=7552-5.UTM-server.com [96.253.126.67]:45726 I=[68.166.142.198]:25 Warning: Sender rate 1.0 / 1h 2015-01-28 17:11:56 [3953] H=7552-5.UTM-server.com [96.253.126.67]:45726 I=[68.166.142.198]:25 incomplete transaction (QUIT) from <> for invalid-user@test-domain.com 2015-01-28 17:11:56 [3953] SMTP connection from 7552-5.UTM-server.com [96.253.126.67]:45726 I=[68.166.142.198]:25 closed by QUIT