• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

IPV6 mail Forwarding with GMAIL

Stephan Lallement

New Pleskian
Hello,
----------------------
PLESK 12.0.18
CENTOS 6.6
QMAIL
----------------------

I have an IPv6 configuration for a domain that works great for sending mail to Gmail.
I added the PTR (AAAA) DKIM, DMARK, SPF rules as gmail request.

If I send an email from my plesk domain to gmail in IVP6 : no problem,
but if I activate a redirect in plesk, gmail refuses the redirected message, as if there were no IPV6 configuration.

SAMPLES :

[email protected] -> [email protected] => works fine :

Delivered-To: [email protected]
Received: by 10.25.41.72 with SMTP id p69csp2104348lfp;
Wed, 7 Oct 2015 00:52:49 -0700 (PDT)
X-Received: by 10.180.206.52 with SMTP id ll20mr213876wic.48.1444204369365;
Wed, 07 Oct 2015 00:52:49 -0700 (PDT)
Return-Path: <[email protected]>
Received: from hosting.mydomain.tld ([2001:41d0:2:97b0::])
by mx.google.com with ESMTPS id y10si43839173wjx.70.2015.10.07.00.52.49
for <[email protected]>
(version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Wed, 07 Oct 2015 00:52:49 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 2001:41d0:2:97b0:: as permitted sender) client-ip=2001:41d0:2:97b0::;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 2001:41d0:2:97b0:: as permitted sender) [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=mydomain.tld
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=default; d=mydomain.tld;
b=fnMBUEfHcZODR2crA0uVygVkSZKvTGR8s+jKmq06Ik794WEQpG8yOMvBi8UAlqz4F5OnmqNcH4adWKDddYRxdNPsHRKc6AesSbJKfvUVndW4/iVp2gqTCVq4fbh+mAn64CJZ5y9A5r3NUh2YKQXevI2R1hwq9OQhmdxIMJOuwPE=;
h=Received:Received:Message-ID:From:To:Subject:Date:MIME-Version:Content-Type:X-Priority:X-MSMail-Priority:Importance:X-Mailer:X-MimeOLE:X-Antivirus:X-Antivirus-Status;
Received: (qmail 26439 invoked from network); 7 Oct 2015 09:52:51 +0200
Received: from xxxxxxxxxxxxxxxxxxxxxxx (HELO mySenderPC) (83.113.4.135)
by mydomain.tld with ESMTPA; 7 Oct 2015 09:52:51 +0200
Message-ID: <F3C5A0F26DF24F2DA5B7EFB4A4BFD647@mySenderPC>
From: <[email protected]>
To: <[email protected]>
Subject: test gmail
Date: Wed, 7 Oct 2015 09:52:57 +0200
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0075_01D100E5.F1E80300"



-----------------------------------------------------

BUT if Redirect :

SOURCE -> TO PLESK EMAIL => REDIRECT TO
[email protected] -> [email protected] => [email protected]
RESULT -> OK => KO



Hi. This is the qmail-send program at hosting.mydomain.tld.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.


<[email protected]>:
2a00:1450:400c:0c04:0000:0000:0000:001b failed after I sent the message.
Remote host said: 550-5.7.1 [2001:41d0:2:97b0::] Our system has detected that this message does
550-5.7.1 not meet IPv6 sending guidelines regarding PTR records and
550-5.7.1 authentication. Please review
550-5.7.1 https://support.google.com/mail/?p=ipv6_authentication_error for more
550 5.7.1 information. pe9si2663845wic.10 - gsmtp

--- Below this line is a copy of the message.

Return-Path: <[email protected]>
Received: (qmail 30758 invoked by uid 30); 7 Oct 2015 11:10:24 +0200
Delivered-To: [email protected]
DomainKey-Status: no signature
Received: (qmail 30750 invoked from network); 7 Oct 2015 11:10:23 +0200
Received-SPF: pass (hosting.mydomain.tld: domain of hotmail.fr designates 157.55.1.165 as permitted sender) client-ip=157.55.1.165; [email protected]; helo=DUB004-OMC2S26.hotmail.com;
Received: from dub004-omc2s26.hotmail.com (157.55.1.165)
by mydomain.tld with (AES256-SHA256 encrypted) SMTP; 7 Oct 2015 11:10:23 +0200
Received: from DUB129-DS14 ([157.55.1.136]) by DUB004-OMC2S26.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.23008);
Wed, 7 Oct 2015 02:10:17 -0700
X-TMN: [lf33L3mL2gWFQ4JrKREq3qC/djtgN3jN]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Return-Path: [email protected]
From: <[email protected]>
To: <[email protected]>
Subject: test ipv6
Date: Wed, 7 Oct 2015 11:10:25 +0200
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_00C3_01D100F0.C46C7BD0"
X-Priority: 3
X-MSMail-Priority: Normal
Importance: Normal
X-Mailer: Microsoft Windows Live Mail 16.4.3528.331
X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3528.331
X-OriginalArrivalTime: 07 Oct 2015 09:10:17.0682 (UTC) FILETIME=[FC0C3320:01D100DF]

----------------------------------------------------------------------------

DNS CONFIG :

mydomain.tld. A SERVER-IPV4
mydomain.tld. AAAA SERVER-IPV6
mydomain.tld. MX (10) mail.mydomain.tld.
mydomain.tld. TXT v=spf1 ip6:SERVER-IPV6 ip4:SERVER-IPV4 a:SERVERNAME include:_spf.google.com ~all
SERVER-IPV4 / 24 PTR mydomain.tld.
_dmarc.mydomain.tld. TXT v=DMARC1; p=none
_domainkey.mydomain.tld. TXT o=-
dkim._domainkey.mydomain.tld. TXT p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQ....
mail.mydomain.tld. A SERVER-IPV4
mail.mydomain.tld. AAAA SERVER-IPV6

So what's wrong in mail redirection... Any (good) idea is welcome ;)
 
Hi Stephan Lallement,

did you probably forget to change the DNS - settings over the nameserver at your domain provider? Often enough, your Plesk server is not the initial nameserver. You can check your actual settings for example at: http://www.dnswatch.info/ or http://digwebinterface.com/ ... and please keep in mind, that changes on a nameserver can take up to 48-72 hours, untill they are sync all over the world.

For further investigations, we really need the fully qualified domain name ( FQDN ), because every other suggestion could only be a shot in the dark.
 
Hi @UFFH01,
I can confirm this bug on CentOS 7, Plesk 12.5 latest MU.

Postfix uses the wrong IPv6. I guess its the IPv6 of the subscription that is the last modified, but I'm not sure yet.

The domain sending the redirects is not associated with the domain of which the IPv6 is used at all. They belong to different customers. Plesk is set up to use the ips of a subscription to send mails - which works when sending mail directly but not when mail is forwarded.

And yes, all RDNS pointers are correct. Postfix simply uses the wrong IPv6 on redirections.
 
Hi,
Yes I agree with Adrian.
I can add that it is random. I also have the problem when plesk is sending the daily logs on my Gmail address. Some days it goes through and some others it doesn't.

I suspected it came from the fact I was using some failover ip's.
 
Back
Top