Discussion:
Stopping backscatter from MessageLabs via a split domain
(too old to reply)
s***@gmail.com
2013-10-15 00:12:35 UTC
Permalink
Hi,

I hope I'm not missing something obvious, but I wasn't able to find a solution in this list or in the Postfix docs. Admittedly, I don't know postfix very well.

Most of our incoming mail is handed off to a local IMAP server, and that all works fine. However for 3 users we have purchased accounts at ExchangeMyMail so they can use the Exchange features they want.

We have a forwarding rule for each account that forwards from ***@ourdomain.com to ***@ourdomain.4emm.com. (ExchangeMyMail hosts the 4emm.com domain.)

This worked fine until August when ExchangeMyMail switched from Postini for spam filtering to MessageLabs (a Symantec product). Now we have messages like this in /var/log/mail.log:

Oct 11 07:43:35 SERVERHOSTNAME postfix/smtp[10547]: 1DCAA145C34: to=<***@ourdomain.4emm.com>, orig_to=<***@ourdomain.com>, relay=server1.inboundmx.com[216.82.253.99]:25, delay=0.69, delays=0.08/0/0.22/0.39, dsn=5.0.0, status=bounced (host server1.inboundmx.com[216.82.253.99] said: 553-Message filtered. Please see the FAQs section on spam 553-at http://www.messagelabs.com/support/ for more 553 information. (#5.7.1) (in reply to end of DATA command))

(An aside: I'm amused that Symantec purchased MessageLabs but couldn't be troubled to fix that URL to go someplace useful.)

Such messages in our logs aren't a problem, but I just realized that our mail queue has a bunch of bounce notifications (failing to go) to spammers because of this. For example:

F0117145B7A 3796 Sat Oct 12 06:54:53 MAILER-DAEMON
(connect to huncal.biz[213.239.219.231]:25: Connection refused)
***@huncal.biz

Postfix has made a bunch of attempts to deliver this failure notice.

Here is my understanding of the situation:

1) For our normal addresses that don't forward to EMM, we don't generate backscatter and everything is fine.

2) Before EMM switched to MessageLabs, mail forwarded to EMM was always accepted (even obvious spam) so this wasn't an issue. Postini would just quarantine the spam.

3) MessageLabs is not accepting obvious spam, and somehow because it is rejected by MessageLabs our Postfix is now trying to send backscatter.

My goal: Convince Postfix to just forget about any mail that MessageLabs rejects in this way, so we don't generate backscatter.

We've using Postfix 2.7.

Any help on this would be much appreciated. Thank you!

Jason
s***@gmail.com
2013-10-15 16:01:34 UTC
Permalink
Argh, nevermind. I searched better and found relevant discussions. Please disregard. Sorry about that.

Jason

Loading...