DNS blacklist not working - ORF Forums

DNS blacklist not working RSS Back to forum

1

I'm using DNS blacklists with "before arrival" and "on arrival".
I have "SORBS Combined List" enabled as one of the options.
I received a load of SPAM yesterday from 64.57.241.30 which has been listed on SORBS since Aug 2017.
How did these emails manage to get through? Surely they should have been blocked?

by gavpop111 5 years ago
2

@gavpop111: Hello gavpop111,

Please send us the ORF logs (i.e. orfee-2019-05-23.log) and the ORF configuration file (orfent.ini) from the day of the incident and we will investigate the issue. The requested files can be found in the ORF program directory by default (\Program Files (x86)\ORF Fusion).

Thank you.

by Daniel Novak (Vamsoft) 5 years ago
(in reply to this post)

3

@Daniel Novak (Vamsoft): Just a quick update for anyone who encounters the same problem:

The SORBS Combined (DNS) Blacklist (i.e. the "dnsbl.sorbs.net" aggregate zone), which was queried by ORF in this case, does not include the "spam.dnsbl.sorbs.net" zone/database which contains the IP address 64.57.241.30.

The "spam.dnsbl.sorbs.net" zone (and any other zone that is not part of the "dnsbl.sorbs.net" aggregate zone) can be added to ORF as an individual DNSBL if necessary. Note, however, that some of these databases are known to include the IP address of legitimate senders, so they should be tested before using in production.

The available SORBS zones are listed on the SORBS website at http://www.sorbs.net/general/using.shtml

by Daniel Novak (Vamsoft) 5 years ago
(in reply to this post)

New comment

Fill in the form below to add a new comment. All fields are required. If you are a registered user on our site, please sign in first.

It will not be published.
hnp1 | hnp2