• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved Undelivered Mail Returned to Sender

Ddungu

Basic Pleskian
Hello Forum,

I have an issue whenever I send emails to hotmail.com. Could anyone be knowing what could be the issue.

This is the mail system at host plesk-1.2703529.cloudfabric.net.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The mail system

<[email protected]>: host
outlook-com.olc.protection.outlook.com[XXX.XX.XX.XX] said: 550 5.7.1
Service unavailable, Client host [XX.XX.XXX.X] blocked using Spamhaus. To
request removal from this list see
https://www.spamhaus.org/query/ip/XX.XX.XXX.X (AS3130).
[DM6NAM10FT101.eop-nam10.prod.protection.outlook.com] (in reply to MAIL
FROM command)
 
I followed all the procedures and even wrote to SPAMHAUS but I am still experiencing the same problem.
 
@Ddungu Most large mail hosters block servers which have no valid hostname (FQDN, check DNS MX entry) and use instead a generic hostname like yours.
You use plesk-12703529.cloudfabric.net instead of mail.mydomain.ork (subdomain of you domain).
 
@Ddungu Most large mail hosters block servers which have no valid hostname (FQDN, check DNS MX entry) and use instead a generic hostname like yours.
You use plesk-12703529.cloudfabric.net instead of mail.mydomain.ork (subdomain of you domain).
Hello, @GwenDragon I did not understand your answer, could you please give a clear explanation? Thank you.
 
Hello @GwenDragon, thanks for the reply but we are using a shared server, won´t this affect other domains? This happens whenever I send a mail to Hotmail.com
 
A server needs a valid hostname f.ex. server2.your-own-server-domin.tld, and the mail server needs to use something like mail.your-own-server-domin.tld.
Can you understand what i mean?
 
@Ddungu If you have a hostname as your plesk-1.2703529.cloudfabric.net, the Hotmal servers will reject mails; Hotmails uses its own rules to block spam servers.
 
I have been removed from the SPAMHAUS blacklist but I have been advised to block port 25 on my office router. Besides that, I am going to fill in the support request form.

Thank you very much for your support @GwenDragon.
 

Why was this IP listed?​

81.46.XXX.2 is making connections with values that indicate a problem: either a misconfiguration or a malware infection.

Technical information​

The most recent connection(s): December 12 2022, 19:00:00 UTC (+/- 5 minutes). The observed HELO value(s) were:

(IP, UTC timestamp, HELO value)

81.46.XXX.2 2022-12-12 19:00:00 PLESK-1.2703529.cloudfabric.net
81.46.XXX.2 2022-12-12 13:00:00 PLESK-1.2703529.cloudfabric.net
81.46.XXX.2 2022-12-10 14:55:00 PLESK-1.2703529.cloudfabric.net
81.46.XXX.2 2022-12-09 15:05:00 PLESK-1.2703529.cloudfabric.net
81.46XXX.2 2022-12-07 15:00:00 PLESK-1.2703529.cloudfabric.net

Notable things about the HELOs:

  • They usually do not exist in DNS - they have no A record. This can be caused by misconfiguration as well as malware.
  • They often have dynamic-appearing rDNS, and the domain(s) used can appear to be geographically far from the IP geolocation
  • They can include "impossible" HELO values like "gmail.com", "hotmail.com" etc - Gmail & Hotmail do not use these
  • The cause of this problem is frequently found to be coming from a phone or laptop with a "free" VPN or channel unlocker app on it.

What should be done about it?​

If this is a shared server, please call your hosting company or ISP!

If this is a misconfiguration of a HELO setting or a Plesk host, that should be corrected.

HELO/EHLO & DNS CHECKS:

You can test a server's HELO configuration by sending an email from it to [email protected]. A bounce that contains the required information will be returned immediately. It will look like an error, but it is not. Examine the contents of this email.

  • If the HELO/EHLO value does NOT exist in DNS, that should be corrected
  • If the HELO/EHLO value is NOT correct, that should be fixed
  • If the HELO/EHLO is using a domain that does NOT exist, that should be corrected
  • If the HELO/EHLO IS what you expect it to be AND it exists in DNS, then there is a spambot or some other kind of malware! This needs to be found and removed.
NOTE: this check does not currently work on IPv6. This is only a syntax check, NOT a verification that the DNS problem has been resolved.

If the HELO configuration is correct and as expected, then there is another problem, probably malware.

MALWARE CHECKS:

  • Secure your firewall to not allow any packets outbound on port 25, except those coming from any email server(s) on your local network. Remote sending of email to servers or printers on the Internet will still work if web-based, or correctly configured to use port 587 using SMTP-AUTH.
  • Guest networks should also be secured - infected personal devices are a big issue!
NOTE: limiting port 25 outbound will only prevent the abusive connections from leaving your network and will not find or remove the malware. In order to do that, we suggest setting up network logging/packet logging to monitor anomalous traffic. This will help identify sources of malware if the scans do not find anything.

  • Perform complete scans with an up to date anti-virus/malware on all devices behind this IP on a scheduled basis.
  • Remember to check personal devices such as laptops, phones, tablets, as well as routers, etc. Malware can be on almost anything that is connected to the internet, including a smart doorbell.
  • Consider the router or firewall as a source of the problem if scans find no other devices.
This FAQ can be helpful: https://www.spamhaus.org/faq/section/Hacked...%20Here's%20help

Removal from CSS​

If the problem on 81.46.XXX.2 has been addressed, you can request removal:
 

How do I configure HELO settings?

Thank you for contacting Spamhaus CSS removals,

Please use Google Translate for language translation, if needed.

IF THIS HAS ALREADY BEEN FIXED PLEASE REPLY TO THIS MESSAGE IMMEDIATELY, AND INCLUDE THE DETAILS OF WHAT WAS FIXED AND HOW.

If this is a shared server, please call your hosting company or ISP!

This IP is making SMTP connections with HELO values that indicate a problem. The HELOs that it is connecting with are as follows:

(IP, UTC timestamp, HELO value)
81.46.000. 2022-12-12 19:00:00 PLESK-1.2703529.cloudfabric.net
81.46.000.2 2022-12-12 13:00:00 PLESK-1.2703529.cloudfabric.net
81.46.000.2 2022-12-10 14:55:00 PLESK-1.2703529.cloudfabric.net
81.46.000.2 2022-12-09 15:05:00 PLESK-1.2703529.cloudfabric.net
81.46.000.2 2022-12-07 15:00:00 PLESK-1.2703529.cloudfabric.net


Notable things about the HELOs:
* These HELOs do not exist in DNS - they have no A record
* They are often dynamic-looking rDNS and often claim to be from geographically very different networks
* This behaviour is frequently found to be caused by third party apps on an Android device that are acting as a proxy. These apps are often "free" vpns, channel unlockers, streaming, etc.
 
If this has already been resolved, kindly respond to this message right once with details on what was resolved and how.
I resolved the issue but still have some issues
You may want to publish a DNS record (A type) for the hostname server.exmple.net or use a different hostname in your mail software.
 
Back
Top