邮件服务器-邮件系统-邮件技术论坛(BBS)

标题: 退信,很奇怪,请高手看一下是什么问题 [打印本页]

作者: wollam    时间: 2009-2-19 16:30
标题: 退信,很奇怪,请高手看一下是什么问题
-----Original Message-----
From: Mail Delivery System [mailto:MAILER-DAEMON@hnrelay1.coxhn.net]
Sent: Thursday, February 19, 2009 3:42 PM
To: xxxxx@xxxxxx.com
Subject: Undelivered Mail Returned to Sender

This is the mail system at host hnrelay1.coxhn.net.

I'm sorry to have to inform you that your message could not be delivered to
one or more recipients. It's attached below.

For further assistance, please send mail to <postmaster>

If you do so, please include this problem report. You can delete your own
text from the attached returned message.

                   The mail system
作者: Kyan    时间: 2009-2-20 01:44


能否請你把 To: xxxxx@xxxxxx.com 真實的網域名稱貼出來?








作者: tdk    时间: 2009-2-20 09:39
贴下发送日志看看有没有什么线索
作者: wollam    时间: 2009-2-20 15:53
自己发自己也不行,出错,是从美国那边发过来的


Fri 2009-02-20 05:41:32: D=129-96-231-201.fibertel.com.ar TTL=(359) A=[201.231.96.129]
Fri 2009-02-20 05:41:32: --> 250 wollamgroup.com Hello 129-96-231-201.fibertel.com.ar, 很高兴见到你
Fri 2009-02-20 05:41:33: <-- MAIL FROM:<oliver@wollamgroup.com>
Fri 2009-02-20 05:41:33: 垃圾邮件封锁器正在检查 201.231.96.129 (正在连接 IP)
Fri 2009-02-20 05:41:33: * bl.spamcop.net - 发送失败
Fri 2009-02-20 05:41:33: * sbl-xbl.spamhaus.org - 发送失败
Fri 2009-02-20 05:41:33: * cblplus.anti-spam.org.cn - 发送失败
Fri 2009-02-20 05:41:33: 垃圾邮件封锁器完成
Fri 2009-02-20 05:41:33: --> 250 <oliver@wollamgroup.com> , 发信人完成。
Fri 2009-02-20 05:41:33: <-- RCPT TO:<oliver@wollamgroup.com>
Fri 2009-02-20 05:41:33: --> 250 <oliver@wollamgroup.com>, 收信人完成。
Fri 2009-02-20 05:41:33: 正在 socket 读取时发生错误!
Fri 2009-02-20 05:41:33: Winsock Error 10054 连接被另一端重设!
Fri 2009-02-20 05:41:33: SMTP 连接被终止(字节入/出: 107/235)
作者: wollam    时间: 2009-2-20 16:02
汉,一直是裸奔的,没开
作者: Kyan    时间: 2009-2-20 16:32
原帖由 wollam 于 2009-2-20 15:53 发表
自己发自己也不行,出错,是从美国那边发过来的


Fri 2009-02-20 05:41:32: D=129-96-231-201.fibertel.com.ar TTL=(359) A=[201.231.96.129]
Fri 2009-02-20 05:41:32: --> 250 wollamgroup.com Hello 129-96- ...


wollamgroup.com IP 應該是 60.190.26.210 是屬於中國 Ningbo Wollam Tex Apparel Co.,Ltd 它的網段是 60.190.26.208 - 60.190.26.215 共有 8 IP能用的有 5 個。無論是由美國寄來或由你寄往美國,怎麼在日誌都沒有提這些 IP而在日誌提到的 IP-201.231.96.129 卻是 "阿根廷" 的,這是怎麼一回事?















[ 本帖最后由 Kyan 于 2009-2-20 17:10 编辑 ]
作者: wollam    时间: 2009-2-20 17:15
我不知道为什么日志里为什么没提,我公司在用的MD是7.2.1版本的,这个完整的连接日起,请看一下,是我设置哪里不对吗?

Fri 2009-02-20 05:41:33: Session 9385; child 2; thread 1516
Fri 2009-02-20 05:41:31: 接收 SMTP 来自[201.231.96.129 : 65468]的连接
Fri 2009-02-20 05:41:31: Looking up PTR record for 201.231.96.129 (129.96.231.201.IN-ADDR.ARPA)
Fri 2009-02-20 05:41:31: D=129.96.231.201.IN-ADDR.ARPA TTL=(1439) PTR=[129-96-231-201.fibertel.com.ar]
Fri 2009-02-20 05:41:31: Gathering A-records for PTR hosts
Fri 2009-02-20 05:41:31: D=129-96-231-201.fibertel.com.ar TTL=(359) A=[201.231.96.129]
Fri 2009-02-20 05:41:31: --> 220 wollamgroup.com ESMTP MDaemon 7.2.1; Fri, 20 Feb 2009 05:41:31 +0800
Fri 2009-02-20 05:41:32: <-- HELO 129-96-231-201.fibertel.com.ar
Fri 2009-02-20 05:41:32: Performing lookup on 129-96-231-201.fibertel.com.ar (looking for 201.231.96.129)
Fri 2009-02-20 05:41:32: D=129-96-231-201.fibertel.com.ar TTL=(359) A=[201.231.96.129]
Fri 2009-02-20 05:41:32: --> 250 wollamgroup.com Hello 129-96-231-201.fibertel.com.ar, 很高兴见到你
Fri 2009-02-20 05:41:33: <-- MAIL FROM:<oliver@wollamgroup.com>
Fri 2009-02-20 05:41:33: 垃圾邮件封锁器正在检查 201.231.96.129 (正在连接 IP)
Fri 2009-02-20 05:41:33: * bl.spamcop.net - 发送失败
Fri 2009-02-20 05:41:33: * sbl-xbl.spamhaus.org - 发送失败
Fri 2009-02-20 05:41:33: * cblplus.anti-spam.org.cn - 发送失败
Fri 2009-02-20 05:41:33: 垃圾邮件封锁器完成
Fri 2009-02-20 05:41:33: --> 250 <oliver@wollamgroup.com> , 发信人完成。
Fri 2009-02-20 05:41:33: <-- RCPT TO:<oliver@wollamgroup.com>
Fri 2009-02-20 05:41:33: --> 250 <oliver@wollamgroup.com>, 收信人完成。
Fri 2009-02-20 05:41:33: 正在 socket 读取时发生错误!
Fri 2009-02-20 05:41:33: Winsock Error 10054 连接被另一端重设!
Fri 2009-02-20 05:41:33: SMTP 连接被终止(字节入/出: 107/235)
作者: wollam    时间: 2009-2-20 17:24
下一段更怪,那个是我们公司同事,5点钟还没上班,问过家里也没上,是不是我中毒了?还是邮件地址被人破了

Fri 2009-02-20 05:41:34: Session 9386; child 3; thread 1132
Fri 2009-02-20 05:41:31: 接收 SMTP 来自[201.231.96.129 : 65434]的连接
Fri 2009-02-20 05:41:31: Looking up PTR record for 201.231.96.129 (129.96.231.201.IN-ADDR.ARPA)
Fri 2009-02-20 05:41:31: D=129.96.231.201.IN-ADDR.ARPA TTL=(1439) PTR=[129-96-231-201.fibertel.com.ar]
Fri 2009-02-20 05:41:31: Gathering A-records for PTR hosts
Fri 2009-02-20 05:41:31: D=129-96-231-201.fibertel.com.ar TTL=(359) A=[201.231.96.129]
Fri 2009-02-20 05:41:31: --> 220 wollamgroup.com ESMTP MDaemon 7.2.1; Fri, 20 Feb 2009 05:41:31 +0800
Fri 2009-02-20 05:41:32: <-- HELO 129-96-231-201.fibertel.com.ar
Fri 2009-02-20 05:41:32: Performing lookup on 129-96-231-201.fibertel.com.ar (looking for 201.231.96.129)
Fri 2009-02-20 05:41:32: D=129-96-231-201.fibertel.com.ar TTL=(359) A=[201.231.96.129]
Fri 2009-02-20 05:41:32: --> 250 wollamgroup.com Hello 129-96-231-201.fibertel.com.ar, 很高兴见到你
Fri 2009-02-20 05:41:33: <-- MAIL FROM:<paulineshen@wollamgroup.com>
Fri 2009-02-20 05:41:33: 垃圾邮件封锁器正在检查 201.231.96.129 (正在连接 IP)
Fri 2009-02-20 05:41:33: * bl.spamcop.net - 发送失败
Fri 2009-02-20 05:41:33: * sbl-xbl.spamhaus.org - 发送失败
Fri 2009-02-20 05:41:33: * cblplus.anti-spam.org.cn - 发送失败
Fri 2009-02-20 05:41:33: 垃圾邮件封锁器完成
Fri 2009-02-20 05:41:33: --> 250 <paulineshen@wollamgroup.com> , 发信人完成。
Fri 2009-02-20 05:41:34: <-- RCPT TO:<paulineshen@wollamgroup.com>
Fri 2009-02-20 05:41:34: --> 250 <paulineshen@wollamgroup.com>, 收信人完成。
Fri 2009-02-20 05:41:34: <--
Fri 2009-02-20 05:41:34: --> 500 什么? 我不理解这个。
Fri 2009-02-20 05:41:34: <-- .
Fri 2009-02-20 05:41:34: --> 500 什么? 我不理解这个。
Fri 2009-02-20 05:41:34: <-- QUIT
Fri 2009-02-20 05:41:34: --> 221 下回见
Fri 2009-02-20 05:41:34: SMTP 连接成功完成(字节入/出: 128/309)
作者: Kyan    时间: 2009-2-20 17:39
原帖由 wollam 于 2009-2-20 17:15 发表
我不知道为什么日志里为什么没提,我公司在用的MD是7.2.1版本的,这个完整的连接日起,请看一下,是我设置哪里不对吗?

Fri 2009-02-20 05:41:33: Session 9385; child 2; thread 1516
Fri 2009-02-20 05:41:31: ...


Fri 2009-02-20 05:41:31: 接收 SMTP 来自[201.231.96.129 : 65468]的连接
Fri 2009-02-20 05:41:31: Looking up PTR record for 201.231.96.129 (129.96.231.201.IN-ADDR.ARPA)
Fri 2009-02-20 05:41:31: D=129.96.231.201.IN-ADDR.ARPA TTL=(1439) PTR=[129-96-231-201.fibertel.com.ar]
Fri 2009-02-20 05:41:31: Gathering A-records for PTR hosts
Fri 2009-02-20 05:41:31: D=129-96-231-201.fibertel.com.ar TTL=(359) A=[201.231.96.129]
Fri 2009-02-20 05:41:31: --> 220 wollamgroup.com ESMTP MDaemon 7.2.1; Fri, 20 Feb 2009 05:41:31 +0800
Fri 2009-02-20 05:41:32: <-- HELO 129-96-231-201.fibertel.com.ar


反解的是 "阿根廷" 的 IP(PTR=[129-96-231-201.fibertel.com.ar])

與你 HELO 的也是 129-96-231-201.fibertel.com.ar(請參閱我第二張圖示)。沒有見到有你們的 IP-60.190.26.210

你可否將你設定主域頁貼出給大家研究研究?



作者: wollam    时间: 2009-2-20 17:52
请问您好还些什么设置,我可以一起上传

01.JPG (37.23 KB, 下载次数: 0)

01.JPG

02.JPG (55.56 KB, 下载次数: 0)

02.JPG

作者: Kyan    时间: 2009-2-20 18:37
你第一張主域的 IP 似乎填錯了,你按圖示改填為你們的 IP-60.190.26.210127.0.0.1 試試看。你目前填的 IP-192.168.0.250 是 Internet 內部使用的 IP






[ 本帖最后由 Kyan 于 2009-2-21 01:10 编辑 ]
作者: wollam    时间: 2009-2-20 19:13
谢谢,我先试试, 还有没有其他设置需要注意的?

[ 本帖最后由 wollam 于 2009-2-20 19:17 编辑 ]
作者: Kyan    时间: 2009-2-20 19:38
原帖由 wollam 于 2009-2-20 19:13 发表
谢谢,我先试试, 还有没有其他设置需要注意的?



你試了把結果貼上來,讓我知道什麽地方還需要改進的。
作者: leungys    时间: 2009-2-20 22:20
原帖由 Kyan 于 2009-2-20 18:37 发表
你第一張主域的 IP 似乎填錯了,你按圖示改填為你們的 IP-60.190.26.210 或 127.0.0.1 試試看。你目前填的 IP-192.168.0.250 是美國 Internet Assigned Numbers Authority 的 IP。


Senior Kyan, just for reminding !!

TCP/IP addresses reserved for 'private' networks are:
10.0.0.0       to     10.255.255.255
172.16.0.0     to     172.31.255.255
192.168.0.0    to     192.168.255.255
169.254.0.0    to     169.254.255.255
These are invalid addresses on the internet.
作者: Kyan    时间: 2009-2-21 00:35
原帖由 leungys 于 2009-2-20 22:20 发表


Senior Kyan, just for reminding !!

10.0.0.0       to     10.255.255.255
172.16.0.0     to     172.31.255.255
192.168.0.0    to     192.168.255.255
169.254.0.0    to     169.254.255.255
These are invalid addresses on the internet


謝謝你的提醒,我知道這些 IP 都保留作為內部使用,所以我才會對他說 "不知道你是從那裡得來的"。但我卻查到 192.168.0.250 是美國 Internet Assigned Numbers Authority,請參閱以下圖示:




同時,我也被 10 網段的某個 IP(後面的數值我忘了)攻擊過,不知他們是怎麼做的?

啊!我沒有注意到它是 Internet Corporation for Assigned Names and Number.



[ 本帖最后由 Kyan 于 2009-2-21 01:06 编辑 ]
作者: leungys    时间: 2009-2-21 08:58
wollan 網友,

1) 什麼時候出問題? 你有沒有改動什麼? 你是不是唯一可改動的人呢?
2) 你有沒有用中繼呢?
3) 你的 email server 是不是在內聯網設置的, 這部機的 IP 為何? #11 是不是 192.168.0.250?  有沒有多於一張 network card 呢? 這部機自己有沒有真 IP? 是不是 60.190.26.210?
4) 有沒有用 firewall 或 router 呢?
5) 201.231.96.129 這個 IP 你認識嗎?
6) 有沒有暫時停用垃圾郵件封鎖器作測試?
7) 你自己做了什麼測試?

小建議
a) 因為你的 mail exchanger 是 mail.wollamgroup.com , 所以 #11 HELO 域名應改為 mail.wollamgroup.com,
   (雖然 wollamgroup.com 和 mail.wollamgroup.com 是同一個 IP, 沒有多大影響)


[ 本帖最后由 leungys 于 2009-2-21 09:42 编辑 ]
作者: Kyan    时间: 2009-2-21 09:19
它沒有另設 mail exchanger,只是在 DNS 設定 domain name - wollamgroup.com,mail.wollamgroup.com 是依附在 wollamgroup.com (如下圖所示)。他每次有問必答,沒有回答可能是己經解決了。


作者: leungys    时间: 2009-2-21 09:40
原帖由 Kyan 于 2009-2-21 09:19 发表
它沒有另設 mail exchanger,只是在 DNS 設定 domain name - wollamgroup.com,mail.wollamgroup.com 是依附在 wollamgroup.com (如下圖所示)。他每次有問必答,沒有回答可能是己經解決了。


I think the software SmartWhois is not so smart as you think, you may double-check the domain's DNS records with nslookup command.
作者: Kyan    时间: 2009-2-21 12:27
原帖由 leungys 于 2009-2-21 09:40 发表


I think the software SmartWhois is not so smart as you think, you may double-check the domain's DNS records with nslookup command.


抱歉,我看不出有什麼不同。









[ 本帖最后由 Kyan 于 2009-2-21 13:57 编辑 ]
作者: leungys    时间: 2009-2-21 13:59
原帖由 Kyan 于 2009-2-21 12:27 发表
抱歉,我看不出有什麼不同。


In order to test whether the MX record of wollamgroup.com exist, you may try the following simple steps at DOS console: (where ns1.cnnb.net is a primary DNS of the checked domain)

nslookup
> server ns1.cnnb.net
Default Server:  ns1.cnnb.net
Address:  202.101.189.3

> set type=mx
> wollamgroup.com
Server:  ns1.cnnb.net
Address:  202.101.189.3

wollamgroup.com MX preference = 5, mail exchanger = mail.wollamgroup.com
wollamgroup.com nameserver = ns1.cnnb.net
mail.wollamgroup.com    internet address = 60.190.26.210
ns1.cnnb.net    internet address = 202.101.189.3

>exit


I hope these help



[ 本帖最后由 leungys 于 2009-2-21 14:00 编辑 ]
作者: Kyan    时间: 2009-2-21 14:22
原帖由 leungys 于 2009-2-21 13:59 发表


In order to test whether the MX record of wollamgroup.com exist, you may try the following simple steps at DOS console: (where ns1.cnnb.net is a primary DNS of the checked domain)

nslookup
> s ...


我認為這是 domain 商代它設定的 mail server 的地址,像我自己也是這樣,請看我下列圖示:





202.101.189.3 是 Ningbo Telecom Co.ltd 的 IP 地址(202.101.189.0 -- 202.101.189.255)。




[ 本帖最后由 Kyan 于 2009-2-21 15:01 编辑 ]
作者: leungys    时间: 2009-2-21 14:56
原帖由 Kyan 于 2009-2-21 14:22 发表
我認為這是 domain 商代它設定的 mail server 的地址,像我自己也是這樣,請看我下列圖示:


Basically, to get domain's MX records from DNS, for example xxx.com,  we should only check xxx.com, not mail.xxx.com.

Okay, take a domain xxx.com as an example, Let say, if there are three mail exchangers available for xxx.com, how do you check it? mail00.xxx.com mail01.xxx.com or anything else. obviously, we just only check xxx.com. Therefore, your checking is already wrong at the very beginning.

My domains are also parked at foreign DNS servers but I haven't seen any preset record from them up to now.
作者: Kyan    时间: 2009-2-21 15:14
原帖由 leungys 于 2009-2-21 14:56 发表


Basically, to get domain's MX records from DNS, for example xxx.com,  we should only check xxx.com, not mail.xxx.com.

Okay, take a domain xxx.com as an example, Let say, if there are three mail ...



如果你要三個不同的 MX,我的做法是 ms1.abcd.com、ms2.abcd.com 和 ms3.abcd.com,各賦與它三個不同的 IP。先設定 type 為 「A」,再以 MX Exchange 來設定它的 type 為 「MX」。你以為我這樣做是否正確?



作者: leungys    时间: 2009-2-21 16:15
原帖由 Kyan 于 2009-2-21 15:14 发表
如果你要三個不同的 MX,我的做法是 ms1.abcd.com、ms2.abcd.com 和 ms3.abcd.com,各賦與它三個不同的 IP。先設定 type 為 「A」,再以 MX Exchange 來設定它的 type 為 「MX」。你以為我這樣做是否正確?


In my opinion, if just for abcd.com and not independent use of each email server, I think just setting A records but MX should be enough because MX records are already set at abcd.com DNS. But It is not what I wanna say in this case.

If you need to check the MX records of abcd.com, how do you check with nslookup? That is the point. At the very beginning, of course, the number of servers available are unknown.

The results from the associated DNS should return the following like this if the parameters being used are correct  (Assume all priority is 10)
abcd.com    MX preference = 10,  mail exchanger = ms1.abcd.com
abcd.com    MX preference = 10,  mail exchanger = ms2.abcd.com
abcd.com    MX preference = 10,  mail exchanger = ms3.abcd.com

[ 本帖最后由 leungys 于 2009-2-21 16:27 编辑 ]
作者: Kyan    时间: 2009-2-21 16:47
原帖由 leungys 于 2009-2-21 16:15 发表


In my opinion, if just for abcd.com and not independent use of each email server, I think just setting A records but MX should be enough because MX records are already set at abcd.com DNS. But It  ...


但是我這樣設定速度可能比較快,因為它的 IP 都是各個獨立的。

因為我的 IP 多,設定為 MX 後不作其他用途,雖然優先權都是 10,但可能會比較快,並且我還可以設定各個不同的收信條件。








[ 本帖最后由 Kyan 于 2009-2-21 16:58 编辑 ]
作者: wollam    时间: 2009-2-25 13:37
汉,这两天忙联系中继服务的事,后来发现可能是邮件地址被盗了,很多个,由不同的IP地址发过来的垃圾邮件,邮件主题和内容差不多,但不是完全一样,都是自己发自己,有什么办法屏避这些垃圾邮件?
ps:我们的邮件服务器是放在公司的局域网内,通过端口映射来实现IP绑定的,而且网内的IP是192。168。0。250,没有真正的IP地址

两段日志:
Wed 2009-02-25 09:22:33: Session 9547; child 2; thread 1052
Wed 2009-02-25 09:22:28: 接收 SMTP 来自[200.117.194.84 : 29498]的连接
Wed 2009-02-25 09:22:28: Looking up PTR record for 200.117.194.84 (84.194.117.200.IN-ADDR.ARPA)
Wed 2009-02-25 09:22:28: D=84.194.117.200.IN-ADDR.ARPA TTL=(1440) PTR=[host84.200-117-194.telecom.net.ar]
Wed 2009-02-25 09:22:28: Gathering A-records for PTR hosts
Wed 2009-02-25 09:22:28: D=host84.200-117-194.telecom.net.ar TTL=(120) A=[200.117.194.84]
Wed 2009-02-25 09:22:28: --> 220 wollamgroup.com ESMTP MDaemon 7.2.1; Wed, 25 Feb 2009 09:22:28 +0800
Wed 2009-02-25 09:22:29: <-- HELO host84.200-117-194.telecom.net.ar
Wed 2009-02-25 09:22:29: Performing lookup on host84.200-117-194.telecom.net.ar (looking for 200.117.194.84)
Wed 2009-02-25 09:22:29: D=host84.200-117-194.telecom.net.ar TTL=(119) A=[200.117.194.84]
Wed 2009-02-25 09:22:29: --> 250 wollamgroup.com Hello host84.200-117-194.telecom.net.ar, 很高兴见到你
Wed 2009-02-25 09:22:30: <-- MAIL FROM:<zhor@wollamgroup.com>
Wed 2009-02-25 09:22:30: --> 250 <zhor@wollamgroup.com> , 发信人完成。
Wed 2009-02-25 09:22:30: <-- RCPT TO:<zhor@wollamgroup.com>
Wed 2009-02-25 09:22:33: --> 250 <zhor@wollamgroup.com>, 收信人完成。
Wed 2009-02-25 09:22:33: <--
Wed 2009-02-25 09:22:33: --> 500 什么? 我不理解这个。
Wed 2009-02-25 09:22:33: <-- .
Wed 2009-02-25 09:22:33: --> 500 什么? 我不理解这个。
Wed 2009-02-25 09:22:33: <-- QUIT
Wed 2009-02-25 09:22:33: --> 221 下回见
Wed 2009-02-25 09:22:33: SMTP 连接成功完成(字节入/出: 117/298)

第二段:
Wed 2009-02-25 03:41:09: Session 8192; child 8; thread 1412
Wed 2009-02-25 03:41:07: 接收 SMTP 来自[92.85.96.44 : 60801]的连接
Wed 2009-02-25 03:41:07: Looking up PTR record for 92.85.96.44 (44.96.85.92.IN-ADDR.ARPA)
Wed 2009-02-25 03:41:07: 名称服务器报告域名未知
Wed 2009-02-25 03:41:07: --> 220 wollamgroup.com ESMTP MDaemon 7.2.1; Wed, 25 Feb 2009 03:41:07 +0800
Wed 2009-02-25 03:41:07: <-- HELO alston.com
Wed 2009-02-25 03:41:07: Performing lookup on alston.com (looking for 92.85.96.44)
Wed 2009-02-25 03:41:08: D=alston.com TTL=(1440) A=[12.192.18.94]
Wed 2009-02-25 03:41:08: --> 250 wollamgroup.com Hello alston.com(可能被伪造), 很高兴见到你
Wed 2009-02-25 03:41:08: <-- MAIL FROM:<luciashi@wollamgroup.com>
Wed 2009-02-25 03:41:08: --> 250 <luciashi@wollamgroup.com> , 发信人完成。
Wed 2009-02-25 03:41:09: <-- RCPT TO:<luciashi@wollamgroup.com>
Wed 2009-02-25 03:41:09: --> 250 <luciashi@wollamgroup.com>, 收信人完成。
Wed 2009-02-25 03:41:09: <--
Wed 2009-02-25 03:41:09: --> 500 什么? 我不理解这个。
Wed 2009-02-25 03:41:09: <-- .
Wed 2009-02-25 03:41:09: --> 500 什么? 我不理解这个。
Wed 2009-02-25 03:41:09: <-- QUIT
Wed 2009-02-25 03:41:09: --> 221 下回见
Wed 2009-02-25 03:41:09: SMTP 连接成功完成(字节入/出: 102/295
作者: Kyan    时间: 2009-2-25 16:32
原帖由 wollam 于 2009-2-25 13:37 发表
汉,这两天忙联系中继服务的事,后来发现可能是邮件地址被盗了,很多个,由不同的IP地址发过来的垃圾邮件,邮件主题和内容差不多,但不是完全一样,都是自己发自己,有什么办法屏避这些垃圾邮件?
ps:我们的邮件服务 ...


你的 mail server 被人當作跳板了,但沒有成功‧請速做好衛護。
作者: wollam    时间: 2009-2-25 16:56
请问我应该怎么做?
作者: Kyan    时间: 2009-2-25 18:04
原帖由 wollam 于 2009-2-25 16:56 发表
请问我应该怎么做?


根據我的做法是先:

1. 在 Security -> Security Setting ->POP before SMTP -> 在小空格裡打勾,將後面時間改為 1 分鐘。

2. 在下一項 Trusted Hosts 裡加入你所有帳戶的 domain 或 IP。

3. 再在下二大項的 Screening 裡的 Host Screen (不是 IP Screen) 封鎖你自己的 IP。






作者: wollam    时间: 2009-2-25 18:31
第二步和第三步会不会造成自己在公司以外的地方用不了?
作者: leungys    时间: 2009-2-25 19:06
原帖由 wollam 于 2009-2-25 16:56 发表
请问我应该怎么做?


wollan 網友,

設置 SPF 便可, 如懂英文可參考以下:

http://www.microsoft.com/mscorp/safety/content/technologies/senderid/wizard/

[ 本帖最后由 leungys 于 2009-2-25 19:59 编辑 ]
作者: wollam    时间: 2009-2-25 20:14
spf记录,先试一下,论坛里有相关介绍,贴出来方便公享:
http://www.5dmail.net/bbs/viewthread.php?tid=155436&pid=168216&page=1&extra=#pid168216
作者: Kyan    时间: 2009-2-26 23:04
有些 DNS 沒有可以設定 text 的位置,對 fps 無能為力,亳無用處可言。
作者: leungys    时间: 2009-2-27 07:23
原帖由 Kyan 于 2009-2-26 23:04 发表
有些 DNS 沒有可以設定 text 的位置,對 fps 無能為力,亳無用處可言。


It is well known that DNS records of type TXT must be allowed to modify first, otherwise, email server cannot take benefit of it - SPF. By the way, what does fps mean?

You may communicate with me in English later on, don't you?




欢迎光临 邮件服务器-邮件系统-邮件技术论坛(BBS) (http://bbs.5dmail.net/) Powered by Discuz! X3.2