@lbutlr
2016-07-14 22:05:34 UTC
I get a few thousand messages like this every day:
mail postfix/smtpd[59689]: warning: hostname sa0877.azar-a.net does not resolve to address 91.219.236.126
And while I assume that these are all just spammers, it looks like the connection continues to get processed and (at least in the few I’ve checked) eventually gets rejected by an RBL check in postscreen.
This processing takes a while, and several connections are made, so is there anything I should consider doing to speed this reection process up? Or shoudl I just ignore this as “working as intended”? Here is one connecton from earlier today which appears to have made a total of 6 connections (4 CONNECT and 2 connect) over the course of about 90 seconds.
Jul 14 08:12:35 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:47075 to [65.121.55.42]:25
Jul 14 08:12:39 mail postfix/postscreen[19509]: PASS NEW [104.171.171.62]:47075
Jul 14 08:12:54 mail postfix/smtpd[23615]: warning: hostname rheocrat62.vwhconsulting.com does not resolve to address 104.171.171.62: hostname nor servname provided, or not known
Jul 14 08:12:54 mail postfix/smtpd[23615]: connect from unknown[104.171.171.62]
Jul 14 08:12:54 mail postfix/smtpd[23615]: lost connection after CONNECT from unknown[104.171.171.62]
Jul 14 08:12:54 mail postfix/smtpd[23615]: disconnect from unknown[104.171.171.62] commands=0/0
Jul 14 08:13:17 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:45788 to [65.121.55.42]:25
Jul 14 08:13:17 mail postfix/postscreen[19509]: PASS OLD [104.171.171.62]:45788
Jul 14 08:13:32 mail postfix/smtpd[23615]: warning: hostname rheocrat62.vwhconsulting.com does not resolve to address 104.171.171.62: hostname nor servname provided, or not known
Jul 14 08:13:32 mail postfix/smtpd[23615]: connect from unknown[104.171.171.62]
Jul 14 08:13:32 mail postfix/smtpd[23615]: lost connection after CONNECT from unknown[104.171.171.62]
Jul 14 08:13:32 mail postfix/smtpd[23615]: disconnect from unknown[104.171.171.62] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Jul 14 08:13:42 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:58369 to [65.121.55.42]:25
Jul 14 08:13:42 mail postfix/dnsblog[23446]: addr 104.171.171.62 listed by domain zen.spamhaus.org as 127.0.0.3
Jul 14 08:13:42 mail postfix/postscreen[19509]: DNSBL rank 7 for [104.171.171.62]:58369
Jul 14 08:13:42 mail postfix/postscreen[19509]: NOQUEUE: reject: RCPT from [104.171.171.62]:58369: 550 5.7.1 Service unavailable; client [104.171.171.62] blocked using zen.spamhaus.org; from=<***@amhea1.binncp.top>, to=<*munged*@*munged*>, proto=ESMTP, helo=<amhea1.binncp.top>
Jul 14 08:13:42 mail postfix/postscreen[19509]: DISCONNECT [104.171.171.62]:58369
Jul 14 08:14:00 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:39959 to [65.121.55.42]:25
Jul 14 08:14:00 mail postfix/dnsblog[23450]: addr 104.171.171.62 listed by domain zen.spamhaus.org as 127.0.0.3
Jul 14 08:14:01 mail postfix/postscreen[19509]: DNSBL rank 7 for [104.171.171.62]:39959
Jul 14 08:14:01 mail postfix/postscreen[19509]: NOQUEUE: reject: RCPT from [104.171.171.62]:39959: 550 5.7.1 Service unavailable; client [104.171.171.62] blocked using zen.spamhaus.org; from=<***@amhea1.binncp.top>, to=<*munged2*@*munged2*>, proto=ESMTP, helo=<amhea1.binncp.top>
Jul 14 08:14:01 mail postfix/postscreen[19509]: DISCONNECT [104.171.171.62]:39959
Jul 14 08:19:21 mail postfix/anvil[21876]: statistics: max connection rate 2/60s for (smtpd:104.171.171.62) at Jul 14 08:13:32
`dig rheocrat62.vwhconsulting.com` returns no ANSWER section, but `dig 104.171.171.62` returns "rheocrat62.vwhconsulting.com” so maybe it’s my DNS that is the issue, but `dig @8.8.8.8 rheocrat62.vwhconsulting.com` didn’t return a result either.
I am not sure, but it seems like a hostname not resolving to the connecting IP could easily be cause for immediate rejection without losing legitimate mail?
mail postfix/smtpd[59689]: warning: hostname sa0877.azar-a.net does not resolve to address 91.219.236.126
And while I assume that these are all just spammers, it looks like the connection continues to get processed and (at least in the few I’ve checked) eventually gets rejected by an RBL check in postscreen.
This processing takes a while, and several connections are made, so is there anything I should consider doing to speed this reection process up? Or shoudl I just ignore this as “working as intended”? Here is one connecton from earlier today which appears to have made a total of 6 connections (4 CONNECT and 2 connect) over the course of about 90 seconds.
Jul 14 08:12:35 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:47075 to [65.121.55.42]:25
Jul 14 08:12:39 mail postfix/postscreen[19509]: PASS NEW [104.171.171.62]:47075
Jul 14 08:12:54 mail postfix/smtpd[23615]: warning: hostname rheocrat62.vwhconsulting.com does not resolve to address 104.171.171.62: hostname nor servname provided, or not known
Jul 14 08:12:54 mail postfix/smtpd[23615]: connect from unknown[104.171.171.62]
Jul 14 08:12:54 mail postfix/smtpd[23615]: lost connection after CONNECT from unknown[104.171.171.62]
Jul 14 08:12:54 mail postfix/smtpd[23615]: disconnect from unknown[104.171.171.62] commands=0/0
Jul 14 08:13:17 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:45788 to [65.121.55.42]:25
Jul 14 08:13:17 mail postfix/postscreen[19509]: PASS OLD [104.171.171.62]:45788
Jul 14 08:13:32 mail postfix/smtpd[23615]: warning: hostname rheocrat62.vwhconsulting.com does not resolve to address 104.171.171.62: hostname nor servname provided, or not known
Jul 14 08:13:32 mail postfix/smtpd[23615]: connect from unknown[104.171.171.62]
Jul 14 08:13:32 mail postfix/smtpd[23615]: lost connection after CONNECT from unknown[104.171.171.62]
Jul 14 08:13:32 mail postfix/smtpd[23615]: disconnect from unknown[104.171.171.62] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Jul 14 08:13:42 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:58369 to [65.121.55.42]:25
Jul 14 08:13:42 mail postfix/dnsblog[23446]: addr 104.171.171.62 listed by domain zen.spamhaus.org as 127.0.0.3
Jul 14 08:13:42 mail postfix/postscreen[19509]: DNSBL rank 7 for [104.171.171.62]:58369
Jul 14 08:13:42 mail postfix/postscreen[19509]: NOQUEUE: reject: RCPT from [104.171.171.62]:58369: 550 5.7.1 Service unavailable; client [104.171.171.62] blocked using zen.spamhaus.org; from=<***@amhea1.binncp.top>, to=<*munged*@*munged*>, proto=ESMTP, helo=<amhea1.binncp.top>
Jul 14 08:13:42 mail postfix/postscreen[19509]: DISCONNECT [104.171.171.62]:58369
Jul 14 08:14:00 mail postfix/postscreen[19509]: CONNECT from [104.171.171.62]:39959 to [65.121.55.42]:25
Jul 14 08:14:00 mail postfix/dnsblog[23450]: addr 104.171.171.62 listed by domain zen.spamhaus.org as 127.0.0.3
Jul 14 08:14:01 mail postfix/postscreen[19509]: DNSBL rank 7 for [104.171.171.62]:39959
Jul 14 08:14:01 mail postfix/postscreen[19509]: NOQUEUE: reject: RCPT from [104.171.171.62]:39959: 550 5.7.1 Service unavailable; client [104.171.171.62] blocked using zen.spamhaus.org; from=<***@amhea1.binncp.top>, to=<*munged2*@*munged2*>, proto=ESMTP, helo=<amhea1.binncp.top>
Jul 14 08:14:01 mail postfix/postscreen[19509]: DISCONNECT [104.171.171.62]:39959
Jul 14 08:19:21 mail postfix/anvil[21876]: statistics: max connection rate 2/60s for (smtpd:104.171.171.62) at Jul 14 08:13:32
`dig rheocrat62.vwhconsulting.com` returns no ANSWER section, but `dig 104.171.171.62` returns "rheocrat62.vwhconsulting.com” so maybe it’s my DNS that is the issue, but `dig @8.8.8.8 rheocrat62.vwhconsulting.com` didn’t return a result either.
I am not sure, but it seems like a hostname not resolving to the connecting IP could easily be cause for immediate rejection without losing legitimate mail?
--
Don't congratulate yourself too much, or berate yourself either. You
choices are half chance; so are everybody else's.
Don't congratulate yourself too much, or berate yourself either. You
choices are half chance; so are everybody else's.