Re: Website link for 216.54.14.84

Bert Driehuis <[email protected]> Mon, 4 Dec 2006 16:36:40 +0100 (CET)
Newsgroups gmane.mail.spam.dsbl.admin
Message-ID <[email protected]>
[ Note: I do not represent DSBL. I just track [email protected] to keep abreast
of possible issues that might affect my use of DSBL, and occasionally I help
out with questions. You may get responses from other subscribers to
[email protected], possibly even with dissenting opinions. ]

On Sat, 2 Dec 2006, Joan Burt wrote:

> I am extremely concerned about getting this resolved. We had several
> issues with our email system last week. At first glance we believed that
> the issue you had with us was related to our reverse DNS entry. We
> resolved that and requested removal. Apparently we had other issues as
> well and yesterday our anti-virus\spam software prevented any messages
> from being received to the mailbox server where our postmaster resides.
> So my engineer who sent the request for removal did not receive your
> confirmation email. We have that resolved now too.

Listings never occur because of reverse DNS. Only IP addresses with 
security issues are eligible for listing. It would appear that whoever 
operates 216.54.120.135 (ADEXFE1.vbschools.com) has switched off 
"relaying for authorized users" or whatever it's called in Exchange, so 
the security issue is probably resolved by disabling the vector. Please 
note that the weak username/password still exists, so depending on your 
system configuration you may have other security issues remaining on 
that system.

> We must also have another issue since your status page said that we
> accepted the message which I took as we must be relaying in some manner.

No, it just means that your server took responsibility for delivering 
the message (and, apparently, then deleted it).

> We ran tests to see if we were in fact relaying and we continuously get
> the message that says we are not relaying. Our tests must not be
> sufficient. Would you please let us know how we can test to verify that
> this is resolved to your satisfaction?  Please feel free to call me if
> needed and I will make changes immediately if necessary.

Most open relay tests do not check for this condition:
   http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK2669

The removal requirement for DSBL is to accept an e-mail and click on a 
link contained there-in. The process is designed to mimic a postmaster 
who tries to contact you.

It is quite likely that a misguided spam filter discarded the e-mail 
(filters should _never_ discard e-mail; acceptable options include 
rejecting the e-mail, quaranteening and delivering suspected spam with a 
tag). It is likely that the reason the filter kicked in was that the 
message was sent with an empty SMTP envelope "<>".