• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Qmail Plesk 12 "550 5.7.1 Sorry, message looks like spam or phish to me (OP)"

Knutsen

New Pleskian
Hi!

I have a problem I can't find a solution for.
I don't even have a clue where to look further.

I have an Ubuntu-Webserver with Plesk 12.0.18 installed on. Qmail installed. No Postfix.


When I try to send a mail to a specific address, I get back a failure notice with the following content:
---------------------
(Remote server IP) failed after I sent the message.
Remote host said: 550 5.7.1 Sorry, message looks like spam or phish to me (OP)
---------------------


This happens even if I send a simple TXT-Message with no attachments.
When I try to send the mail through another adress on my server it will not ne accepted, too.
Mails from other Servers will be accepted.

So I checked my Server if it is on any Blacklist through mx-toolbox.com, but everything is ok.


Mail.log:
---------------------
Sep 26 13:13:42 qmail-queue-handlers[19958]: Handlers Filter before-queue for qmail started ...
Sep 26 13:13:42 qmail-queue-handlers[19958]: from=MYMAILADRESS
Sep 26 13:13:42 qmail-queue-handlers[19958]: to=REMOTEMAILADRESS
Sep 26 13:13:42 qmail-queue-handlers[19958]: handlers_stderr: PASS
Sep 26 13:13:42 qmail-queue-handlers[19958]: PASS during call 'limit-out' handler
Sep 26 13:13:42 qmail-queue-handlers[19958]: handlers_stderr: SKIP
Sep 26 13:13:42 qmail-queue-handlers[19958]: SKIP during call 'check-quota' handler
Sep 26 13:13:42 spf filter[19962]: Starting spf filter...
Sep 26 13:13:42 qmail-queue-handlers[19958]: handlers_stderr: SKIP
Sep 26 13:13:42 qmail-queue-handlers[19958]: SKIP during call 'spf' handler
Sep 26 13:13:42 qmail-queue-handlers[19958]: starter: submitter[19963] exited normally
Sep 26 13:13:42 qmail: 1443266022.980990 new msg 11537832
Sep 26 13:13:42 qmail: 1443266022.981060 info msg 11537832: bytes 1043 from <MYMAILADRESS> qp 19963 uid 2020
Sep 26 13:13:43 qmail: 1443266023.073218 starting delivery 8: msg 11537832 to remote REMOTEMAILADRESS
Sep 26 13:13:43 qmail: 1443266023.073292 status: local 0/10 remote 1/20
Sep 26 13:13:43 qmail-remote-handlers[19964]: Handlers Filter before-remote for qmail started ...
Sep 26 13:13:43 qmail-remote-handlers[19964]: from=MYMAILADRESS
Sep 26 13:13:43 qmail-remote-handlers[19964]: to=REMOTEMAILADRESS
Sep 26 13:13:44 qmail: 1443266024.024954 delivery 8: failure: 84.245.143.50_failed_after_I_sent_the_message./Remote_host_said:_550_5.7.1_Sorry,_message_looks_like_spam_or_phish_to_me_(OP)/
Sep 26 13:13:44 qmail: 1443266024.025495 status: local 0/10 remote 0/20
Sep 26 13:13:44 qmail-queue-handlers[19965]: Handlers Filter before-queue for qmail started ...
Sep 26 13:13:44 qmail-queue-handlers[19965]: from=
Sep 26 13:13:44 qmail-queue-handlers[19965]: to=MYMAILADRESS
Sep 26 13:13:44 qmail-queue-handlers[19965]: Unable to get sender domain by sender mailname
Sep 26 13:13:44 qmail-queue-handlers[19965]: Unable to get sender domain by sender mailname
Sep 26 13:13:44 qmail-queue-handlers[19965]: handlers_stderr: SKIP
Sep 26 13:13:44 qmail-queue-handlers[19965]: SKIP during call 'limit-out' handler
Sep 26 13:13:44 qmail-queue-handlers[19965]: handlers_stderr: SKIP
Sep 26 13:13:44 qmail-queue-handlers[19965]: SKIP during call 'check-quota' handler
Sep 26 13:13:44 spf filter[19968]: Starting spf filter...
Sep 26 13:13:44 qmail-queue-handlers[19965]: handlers_stderr: SKIP
Sep 26 13:13:44 qmail-queue-handlers[19965]: SKIP during call 'spf' handler
Sep 26 13:13:44 qmail-queue-handlers[19965]: starter: submitter[19969] exited normally
Sep 26 13:13:44 qmail: 1443266024.339087 bounce msg 11537832 qp 19965
Sep 26 13:13:44 qmail: 1443266024.339114 end msg 11537832
Sep 26 13:13:44 qmail: 1443266024.339398 new msg 11539332
Sep 26 13:13:44 qmail: 1443266024.339415 info msg 11539332: bytes 1675 from <> qp 19969 uid 2522
Sep 26 13:13:44 qmail: 1443266024.429273 starting delivery 9: msg 11539332 to local MYDOMAIN-MYMAILADRESS
Sep 26 13:13:44 qmail: 1443266024.429593 status: local 1/10 remote 0/20
Sep 26 13:13:44 qmail-local-handlers[19970]: Handlers Filter before-local for qmail started ...
Sep 26 13:13:44 qmail-local-handlers[19970]: from=
Sep 26 13:13:44 qmail-local-handlers[19970]: to=MYMAILADRESS
Sep 26 13:13:44 qmail-local-handlers[19970]: mailbox: /var/qmail/mailnames/MYDOMAIN.COM/web1p1
Sep 26 13:13:44 qmail-local-handlers[19970]: Unable to get sender domain by sender mailname
Sep 26 13:13:44 spamd[19400]: spamd: connection from localhost [::1]:57533 to port 783, fd 6
Sep 26 13:13:44 spamd[19400]: spamd: using default config for [email protected]: /var/qmail/mailnames/MYDOMAIN.COM/web1p1/.spamassassin/user_prefs
Sep 26 13:13:44 spamd[19400]: spamd: processing message (unknown) for [email protected]:30
Sep 26 13:13:44 spamd[19400]: spamd: clean message (-1.4/6.0) for [email protected]:30 in 0.3 seconds, 1675 bytes.
Sep 26 13:13:44 spamd[19400]: spamd: result: . -1 - BAYES_00,MISSING_MID,NO_RELAYS,URIBL_BLOCKED scantime=0.3,size=1675,[email protected],uid=30,required_score=6.0,rhost=localhost,raddr=::1,rport=57533,mid=(unknown),bayes=0.000000,autolearn=no autolearn_force=no
Sep 26 13:13:44 qmail-local-handlers[19970]: handlers_stderr: PASS
Sep 26 13:13:44 qmail-local-handlers[19970]: PASS during call 'spam' handler
Sep 26 13:13:44 qmail: 1443266024.792616 delivery 9: success: did_0+0+2/
Sep 26 13:13:44 qmail: 1443266024.793939 status: local 0/10 remote 0/20
Sep 26 13:13:44 qmail: 1443266024.794828 end msg 11539332
---------------------

Strange looking, that there is no "From" defined in the middle of my log.
Is it possible, that SPF removes this, so that the mail will be recognised as spam on the other server?

I don't have a clue where to go ahead...

Cheers
Knut
 
Hi Knutsen,

Is it possible, that SPF removes this, so that the mail will be recognised as spam on the other server?
No. The recipient server uses 3rd party RBL to protect their mail - server. Once that one of your mails is identified as suspicious, your IP will be blocked, untill removement. Try to contact the recipient server administration contact and ask for the IP removement, or wait for automatic removement.

Please keep in mind, that some RBL lists are rather strict and may temporary blacklist your IP, when there are missing SPF and DMARC entries.

For further investigations, please provide your IP or FQDN ( fully qualified domain name ).
 
Thanks. :)

My problem is solved. The server was blacklisted on cyren.com, which is not included in mxtoolbox.com.

I had a compromised webspace several weeks ago, which is clean now.
Thought no one had noticed. The mail-traffic is reduced to 10 mails per hour, and is working quite fine.

Regards
 
Back
Top