• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Question IP Address Mail Blacklisted SORBS- Cannot remove

BubbleDuck

New Pleskian
Hi
Forgive me as I'm quite new to this VPS stuff.
I have a plesk vps to host some websites, and I'm getting a number of my website clients contact me as people contacting them are getting email bouncebacks.
Turns out the IP address for my VPS has been added to a few blacklist. I was able to remove most however SORBS is automatically rejecting my requests with a bot and not responding to my tickets.

SORBS Response:
"Not all the IP space you requested can be delisted at this
time. Please review carefully our FAQ, located at the following URI


For efficiency, I review segments of IP space that may be larger than
what you requested, although I will delist your IP space once it is
eligible, regardless of its surroundings. In this case, I found the
following IP space, not eligible for delisting:

XX.XX.XX.XXX
(my server IP)


Please review our FAQ very carefully for actions you might need to
take. You may want to review your rDNS information for these IP
ranges. When checking the rDNS information, please don't forget to
consider the TTL. It must be 43200 seconds or longer"


I've gotten in touch with my VPS providor and they say since this is an unmanaged server, they are unable to assist.
Any help would be appreciated!
 
What have you already tried to ensure that your server is not sending spam?
All I have done/know to do is keeping an eye on the Mail Queue recently to check if anything is abnormal, which so far has been clear.
And in the settings (since I started the Plesk server) limited each mailbox to a max of 50 outgoing messages per hour.
Any further things I should be doing please let me know, I would be very grateful.
 
With an outgoing mail limit set to 50, is any mailbox, domain or subscription exceeding that limit?

Another good starting point is probably the /var/log/maillog file. Try to identify some spams in there. Mostly what is logged for outgoing mail already hints at the source of the spam.

Another good source can be looking into the mail headers from the mail queue entries.

Plesk has this article that can help to find the source of spam:

You could check the process list with "ps" for any unusual scripts that should not be there, for example "exim". But sometimes you'll also see some user account processes that run software they should not be running. That software can have cryptic names, so it is difficult to give specific advice what to look for. It normally won't be php, nginx, httpd, apache2, postfix. Also pay attention to anything that is run from the /tmp partition (or directory). That could also be a malware sending spam, circumventing security mechanisms.
 
Back
Top