This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problems with Spam 550 Prohibition

Hello,

we have problems with our spam system. Since monday several mails declared as spam. I´ve made the latest update of Sophos 9.313-3. 
Each of the sender could send mails before that date.
We configured the spam system, that confirmed spam will be rejected.
Do you have any ideas. 

Thanks a lot

Björn

Here is, what the senders get:
Action: failed
Status: 5.0.0
Remote-MTA: dns; mailout.hwk-freiburg.de
Diagnostic-Code: smtp; 550 Administrative prohibition

The log of our sophos:
2015:07:07-08:29:38 vegeta-1 exim-in[6091]: 2015-07-07 08:29:38 [x.x.x.x] F= R= Verifying recipient address with callout
2015:07:07-08:29:38 vegeta-1 exim-in[6090]: 2015-07-07 08:29:38 [x.x.x.x] F= R= Verifying recipient address with callout
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: 2015-07-07 08:29:39 1ZCMNu-0001aE-1j ctasd reports 'Confirmed' RefID:str=0001.0A0C0203.559A5384.01C2,ss=4,sh,re=0.000,recu=0.000,reip=0.000,cl=4,cld=1,fgs=8
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: 2015-07-07 08:29:39 1ZCMNu-0001aE-1j id="1003" severity="info" sys="SecureMail" sub="smtp" name="email rejected" srcip="x.x.x.x" from="s.sch@***.cc" to="m.***@hwk-freiburg.de" subject="Re: Aktuelle Fehlermeldungen" queueid="1ZCMNu-0001aE-1j" size="1325964" reason="as" extra="confirmed"
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [1\30] 2015-07-07 08:29:39 1ZCMNu-0001aE-1j H=mail.aufwind-solutions.de [x.x.x.x]:38192 F= rejected after DATA
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [5\30]        by mailout.hwk-freiburg.de with esmtp (Exim 4.82_1-5b7a7c0-XX)
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [6\30]        (envelope-from )
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [15\30] P Received: from [192.168.129.35] (unknown [213.144.26.7])
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [16\30]      by mail.aufwind-solutions.de (Postfix) with ESMTP id 7E356288092;
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [17\30]      Tue,  7 Jul 2015 08:29:36 +0200 (CEST)
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [18\30]   X-CTCH-RefID: str=0001.0A0C0203.559A5384.01C2,ss=4,sh,re=0.000,recu=0.000,reip=0.000,cl=4,cld=1,fgs=8
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [19\30]   Subject: Re: Aktuelle Fehlermeldungen
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [20\30]   Mime-Version: 1.0 (Apple Message framework v1081)
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [21\30]   Content-Type: multipart/alternative; boundary=Apple-Mail-42-529399718
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [23\30]   X-Priority: 1
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: [30/30]   X-Mailer: Apple Mail (2.1081)
2015:07:07-08:29:39 vegeta-1 exim-in[6090]: 2015-07-07 08:29:39 1ZCMNu-0001aE-1j SMTP connection from mail.***.de [x.x.x.x]:38192 closed by DROP in ACL
2015:07:07-08:29:39 vegeta-1 exim-in[6091]: 2015-07-07 08:29:39 1ZCMNu-0001aF-1j ctasd reports 'Confirmed' RefID:str=0001.0A0C0203.559A5384.01C2,ss=4,sh,re=0.000,recu=0.000,reip=0.000,cl=4,cld=1,fgs=8
2015:07:07-08:29:40 vegeta-1 exim-in[6091]: 2015-07-07 08:29:40 1ZCMNu-0001aF-1j id="1003" severity="info" sys="SecureMail" sub="smtp" name="email rejected" srcip="x.x.x.x" from="s.sch@***.cc" to="t.***@wissen-hoch-drei.de" subject="Re: Aktuelle Fehlermeldungen" queueid="1ZCMNu-0001aF-1j" size="1325964" reason="as" extra="confirmed"
2015:07:07-08:29:40 vegeta-1 exim-in[6091]: [1\30] 2015-07-07 08:29:40 1ZCMNu-0001aF-1j H=mail.***.de [x.x.x.x]:38191 F= rejected after DATA


This thread was automatically locked due to age.
Parents
  • "ctasd reports 'confirmed'" is the key here.  It indicates that the  content of the emails are too similar to known spams.  Check the KnowledgeBase for the article on reporting emails that are not spam. 

    Cheers - Bob

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • "ctasd reports 'confirmed'" is the key here.  It indicates that the  content of the emails are too similar to known spams.  Check the KnowledgeBase for the article on reporting emails that are not spam. 

    Cheers - Bob

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data