This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SMTP UTM rejected mail but even that forwarded to mail server

Hi there, I've got strange behaviour of SMTP gateway. In SMTP log some mails are rejected and even that the are forwarded to mail server.

Here some logs from UTM:

2016:12:14-03:55:34 utm exim-in[3109]: 2016-12-14 03:55:34 H=([201.220.16.34]) [201.220.16.34]:13418 Warning: domain.cz profile excludes SANDBOX scan
2016:12:14-03:55:34 utm exim-in[3109]: 2016-12-14 03:55:34 id="1003" severity="info" sys="SecureMail" sub="smtp" name="email rejected" srcip="201.220.16.34" from="connie@diginsure.net" to="ig.sat@domain.cz" size="-1" reason="rdns_helo" extra="RDNS missing"
2016:12:14-03:55:34 utm exim-in[3109]: 2016-12-14 03:55:34 H=([201.220.16.34]) [201.220.16.34]:13418 F=<connie@diginsure.net> rejected RCPT <ig.sat@domain.cz>: No RDNS entry for 201.220.16.34
2016:12:14-03:55:34 utm exim-in[3109]: 2016-12-14 03:55:34 SMTP connection from ([201.220.16.34]) [201.220.16.34]:13418 closed by DROP in ACL

Here some logs from mail server:
EventId Source Sender Recipients MessageSubject
------- ------ ------ ---------- --------------
RECEIVE SMTP connie@diginsure.net {ig.sat@domain.cz} Re: Salary [$1500 /week]
DELIVER STORE... connie@diginsure.net {ig.sat@domain.cz} Re: Salary [$1500 /week]

Then during the investigation I have noticed some mails are not loged on UTM SMTP log which is also very strange.

I've run out of any idea because this happens just for some mails not for all.

Could anoney help me?

BR
Vojtech



This thread was automatically locked due to age.
Parents
  • Hi,

    Contact support if possible and verify logs from both the ends. I would rather suggest you to get the support and the Mail server administrator to co-ordinate together and monitor the behavior. As per the logs posted above, the mails is rejected due to RDNS failure. If you still suspect the behavior a live troubleshooting session can find a proper conclusion.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Reply
  • Hi,

    Contact support if possible and verify logs from both the ends. I would rather suggest you to get the support and the Mail server administrator to co-ordinate together and monitor the behavior. As per the logs posted above, the mails is rejected due to RDNS failure. If you still suspect the behavior a live troubleshooting session can find a proper conclusion.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

Children
No Data