Spamhaus block?

I have a problem with sending/receiving email

Running mail tests I see errors like this:

CDOSYS Error:
Error Number: -2147220977
Error Source:
Error Description: The server rejected one or more recipient addresses. The server response was: 451 http://www.spamhaus.org/query/bl?ip=64.187.106.138

Looking up the message in Spamhaus I see this:

64.187.106.138 is listed in the XBL, because it appears in:

CBL

Is there something Jodo needs to do to request to remove the blocking?

Thanks!
 
CBL is an auto block. We will need you to send a ticket for this so we can check the server and possibly change the mail greeting name, sometimes it can happen there, I thought all had been set right for a long time.

CBL isn't a spam block per se, so its not because someone has been naughty, just MS SMTP server 'goodness'
 
Hi Stephen,

It has happened again (actually twice more since I have posted and also turned in additional tickets) I have no idea why this keeps happening or why I am being impacted by it.

What happens is this:

Each time 64.187.106.138 IP which is linked to AccelerateBiz gets put in the Spamhaus XBL / CBL it impacts my ability to send receive email from my forums. I have no idea why.. but it does. Is some type of virus or hijacking a possibility?

If I need to open another ticket again I can do so..but it seemed to me that you may have understood what might have been happening.

Maybe my accounts need to be routed through different mail serves somehow? I don't know though of anything I can do from my end to stop this since I have no connetion at all with that IP address.

It's there again now:

http://www.spamhaus.org/query/bl?ip=64.187.106.138
 
This is very weird, it is saying the mail server is misnamed, BUT IT ISN'T.

That is the only reason the listing is coming, and nothing else, and I ha checked it was working properly before delisting the first time.
 
Hi Stephen,

Not sure if this helps or not..but two days ago (I think) someone from support got the listing removed...is it possible that additional information was needed?

Also is it possible that someone got some type of malicious mailing script or something into my forums..and that is somehow the cause?
 
Hi Stephen,

Not sure if this helps or not..but two days ago (I think) someone from support got the listing removed...is it possible that additional information was needed?

Also is it possible that someone got some type of malicious mailing script or something into my forums..and that is somehow the cause?

It is easy to get removed, I've done it twice now, explaining in comments section each time, I have triple verified the FQDN.

No, it has nothing to do with mails at all, CBL doesn't block for spam even.
It is just an RFC enforcement blocklist.
 
Hi Stephen,

Unfortunately it's back on again:

IP Address 64.187.106.138 is currently listed in the CBL.

It was detected at 2009-04-13 08:00 GMT (+/- 30 minutes), approximately 3 hours ago.
 
Ugh! and it is in the Spamhaus CBL listing again:

http://www.spamhaus.org/query/bl?ip=64.187.106.138

I just don't get it..why is my domain and mail being impacted by a CBL for AccelerateBiz? What is the relationship between JodoHost and AccelerateBiz?

Will moving my domain somehow get around this? Can routings somehow be changed so that 64.187.106.138 IP is no longer in the routing for my account?
 
Ugh! and it is in the Spamhaus CBL listing again:

http://www.spamhaus.org/query/bl?ip=64.187.106.138

I just don't get it..why is my domain and mail being impacted by a CBL for AccelerateBiz? What is the relationship between JodoHost and AccelerateBiz?

Will moving my domain somehow get around this? Can routings somehow be changed so that 64.187.106.138 IP is no longer in the routing for my account?

This has nothing to do with accelerate biz, it is all about the FQDN which I changed to try to suite them and still it relisted :( I have moved to using the jodoshared.com address on it and still relisted. This server is the only one I'e ever seen this trouble with.
 
Grrrrrrrrrrrrrrrrrr :(

Once again it is listed and I am not getting needed emails as a result (nor are others)..someone from Jodo needs to talk to someone at Spamhaus to get this permanently resolved.

Please do whatever needs to be done to get my domain moved, changed, fixed or whatever has to happen... so that there is no connection or routing needed with my account and64.187.106.138 IP address. This is totally ridiculous and unacceptable.
 
And once again I am not getting emails. This has become a daily occurence now.

IP Address 64.187.106.138 is currently listed in the CBL.

It was detected at 2009-04-23 21:00 GMT (+/- 30 minutes), approximately 15 hours ago.

It has been relisted following a previous removal at 2009-04-23 00:17 GMT

ATTENTION: please read this to find out why your IP was listed, and ways to fix it so it doesn't relist.

Once again I need this to be permanently fixed or my domain moved so that there are no routings that go through the AcelerateBiz of 64.187.106.138

Sorry if I sound like a stuck record but the problems/errors etc. that JodoHost is having/producing not only affect my account but they impact my business. They need to be fixed permanently and they need to be fixed quickly.
 
Joe,

We are working with them, that list of items is not why this is bieng listed it seems there is something else and I don't know what just yet. The normal spamhaus replies quickly but CBL is a bit of a different operation.
 
I'm seeing this same issue from 64.187.101.31 and opened ticket # BFW-53054-123.

Hopefully this can be taken care of permanently as I already requested delistment previously but it's back on the CBL.
 
Spamhaus seem to think the IP is a source of a Spam Bot
IP Address 64.187.101.31 is currently listed in the CBL.

It was detected at 2009-05-30 22:00 GMT (+/- 30 minutes), approximately 2 days, 5 hours ago.

It has been relisted following a previous removal at 2009-05-13 04:12 GMT

ATTENTION: At the time of detection, this IP was infected with, or NATting for a computer infected with a high volume spam sending trojan - it is participating or facilitating a botnet sending spam or spreading virus/spam trojans.

ATTENTION: If you simply repeatedly remove this IP address from the CBL without correcting the problem, the CBL WILL eventually stop letting you delist it and you will have to contact us directly.


This detection is of the DarkMailer/YellSOFT DirectMailer Trojan
See http://cbl.abuseat.org/lookup.cgi?ip=64.187.101.31 for full details
 
Hrm it hasn't been listed in a long time now. I am unsure why they think it is a spam bot, it is barely sending any email at all and I've looked through many of the logs and it doesn't seem to be just hammering away at emails. I will check it again now. I am glad CBL is finally giving more info readily anyway.

Edit: this IP is a linux server, I was thinking from the original post. I am having the linux team check this ASAP.
 
Back
Top