hotmail spam

Discussion in 'General' started by eros23, May 8, 2014.

  1. eros23

    eros23 New Member

    When I send an email from my server, it arrives as spam in hotmail.
    Yet I do I make checks with dkim and spf. Everything works correctly.

    What could cause this problem?
    I changed several servers. I changed several IP.
    I'm getting really stupid with these configurations. These configurations do not make me sleep at night!
    This is an email that I sent:
    PHP:
    x-store-info:4r51+eLowCe79NzwdU2kRyU+pBy2R9QCgtQWRKs+T6ZA0kdvUISuTxogHy/SIUqnAezff9UgF2PBhFT5OuTXC0X0kxoL4umW+e983Y00/Q4BRp/Pnjny4KPwxzDPqbkfn6a4ph3DJ0A=
    Authentication-Resultshotmail.comspf=pass (sender IP is 37.187.199.12smtp.mailfrom=giovanni@lgnuke.comdkim=pass header.d=lgnuke.comx-hmca=pass header.id=w3bm4st3r@lgnuke.com
    X
    -SID-PRAgiovanni@lgnuke.com
    X
    -AUTH-ResultPASS
    X
    -SID-ResultPASS
    X
    -Message-Statusn:n
    X
    -Message-DeliveryVj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtHRD0yO1NDTD00
    X
    -Message-Info11chDOWqoTl520xsJLdDpXfRDFnIpR7dCXa4gK8w3PkfNJgDyrP0rX89sh/+aAq+N3rdRBFtAE/boGOZD2yEgKyk+0upPdt80Le6L1kmLILskkABQQ8+jOzp1FtfnoWQ8Yt9D0Mk4PDl222kq7y0+5SJdXYFPKxU04djYP77bIg3fB86qbhlkH2QlN362om1DiUYP4/zVRKPLMO6zEbmDMSDP1uN4pEh
    Received
    from vps.lgnuke.com ([37.187.199.12]) by BAY0-MC5-F21.Bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
         
    Thu8 May 2014 07:12:00 -0700
    Received
    from localhost (localhost.localdomain [127.0.0.1])
        
    by vps.lgnuke.com (Postfixwith ESMTP id CD9C62C212
        
    for <gabriele.lagana@outlook.it>; Thu,  8 May 2014 16:11:59 +0200 (CEST)
    DKIM-Signaturev=1a=rsa-sha256c=relaxed/simpled=lgnuke.comh=
        
    content-transfer-encoding:content-type:content-type:subject
        
    :subject:mime-version:user-agent:from:from:date:date:message-id;
         
    s=default; t=1399558309x=1401372710bh=A6e2LeOMlw36h133YT5Dd
        V98DQwghx36GWoVWnr5
    +Qw=; b=NMJ7B48OHrEH2IrT/5v9MysyiGIXz7N4LfxRT
        zVqtb6ofUoIlNW5eA6GLGb86BFBeKX6tS8SaWjtSdIXXFKq9XTqk5O8jqk
    /iHe+y
        4hkB2ET02GJg
    +dTdhoPZ0Z9cFwO83XNiCdMI8Q8Cw7dEW0ocnnSBxcK/mtUSpmNA
        1nucRg
    =
    X-Virus-ScannedDebian amavisd-new at vps.lgnuke.com
    Received
    from vps.lgnuke.com ([127.0.0.1])
        
    by localhost (vps.lgnuke.com [127.0.0.1]) (amavisd-new, port 10026)
        
    with ESMTP id 3OtTkFZceErT for <gabriele.lagana@outlook.it>;
        
    Thu,  8 May 2014 16:11:49 +0200 (CEST)
    Receivedfrom [192.168.1.128] (2-226-99-120.ip180.fastwebnet.it [2.226.99.120])
        (
    Authenticated sendergiovanni@lgnuke.com)
        
    by vps.lgnuke.com (Postfixwith ESMTPSA id 812352C20E
        
    for <gabriele.lagana@outlook.it>; Thu,  8 May 2014 16:11:49 +0200 (CEST)
    Message-ID: <536B90A0.2010600@lgnuke.com>
    DateThu08 May 2014 16:11:44 +0200
    From
    Gabriele Lagana <giovanni@lgnuke.com>
    User-AgentMozilla/5.0 (Windows NT 6.1WOW64rv:24.0Gecko/20100101 Thunderbird/24.5.0
    MIME
    -Version1.0
    To
    gabriele.lagana@outlook.it
    Subject
    : as d
    Content
    -Typetext/plaincharset=ISO-8859-15format=flowed
    Content
    -Transfer-Encoding7bit
    Return-Pathgiovanni@lgnuke.com
    X
    -OriginalArrivalTime08 May 2014 14:12:01.0162 (UTCFILETIME=[7AFF46A0:01CF6AC7]

    asd asd
    /etc/postfix/main.cf

    PHP:
    root@vps:~# cat /etc/postfix/main.cf
    # See /usr/share/postfix/main.cf.dist for a commented, more complete version


    # Debian specific:  Specifying a file name will cause the first
    # line of that file to be used as the name.  The Debian default
    # is /etc/mailname.
    # myorigin = /etc/mailname

    smtpd_banner $myhostname ESMTP $mail_name (Debian/GNU)
    biff no

    # appending .domain is the MUA's job.
    append_dot_mydomain no

    # Uncomment the next line to generate "delayed mail" warnings
    #delay_warning_time = 4h

    readme_directory = /usr/share/doc/postfix

    # TLS parameters
    smtpd_tls_cert_file = /etc/postfix/smtpd.cert
    smtpd_tls_key_file 
    = /etc/postfix/smtpd.key
    smtpd_use_tls 
    yes
    smtpd_tls_session_cache_database 
    btree:${data_directory}/smtpd_scache
    smtp_tls_session_cache_database 
    btree:${data_directory}/smtp_scache

    # See /usr/share/doc/postfix/TLS_README.gz in the postfix-doc package for
    # information on enabling SSL in the smtp client.

    myhostname vps.lgnuke.com
    alias_maps 
    hash:/etc/aliaseshash:/var/lib/mailman/data/aliases
    alias_database 
    hash:/etc/aliaseshash:/var/lib/mailman/data/aliases
    myorigin 
    = /etc/mailname
    mydestination 
    vps.lgnuke.com
    #mydestination = vps.lgnuke.com, localhost, localhost.localdomain
    relayhost =
    mynetworks 37.187.199.12 [::1]/128
    mailbox_size_limit 
    0
    recipient_delimiter 
    = +
    inet_interfaces all
    html_directory 
    = /usr/share/doc/postfix/html
    virtual_alias_domains 
    =
    virtual_alias_maps proxy:mysql:/etc/postfix/mysql-virtual_forwardings.cfproxy:mysql:/etc/postfix/mysql-virtual_email2email.cfhash:/var/lib/mailman/data/virtual-mailman
    virtual_mailbox_domains 
    proxy:mysql:/etc/postfix/mysql-virtual_domains.cf
    virtual_mailbox_maps 
    proxy:mysql:/etc/postfix/mysql-virtual_mailboxes.cf
    virtual_mailbox_base 
    = /var/vmail
    virtual_uid_maps 
    = static:5000
    virtual_gid_maps 
    = static:5000
    inet_protocols 
    all
    smtpd_sasl_auth_enable 
    yes
    broken_sasl_auth_clients 
    yes
    smtpd_sasl_authenticated_header 
    yes
    smtpd_recipient_restrictions 
    check_recipient_access mysql:/etc/postfix/mysql-virtual_recipient.cfpermit_mynetworkspermit_sasl_authenticatedreject_unauth_destination
    smtpd_tls_security_level 
    may
    transport_maps 
    hash:/var/lib/mailman/data/transport-mailmanproxy:mysql:/etc/postfix/mysql-virtual_transports.cf
    relay_domains 
    mysql:/etc/postfix/mysql-virtual_relaydomains.cf
    relay_recipient_maps 
    mysql:/etc/postfix/mysql-virtual_relayrecipientmaps.cf
    proxy_read_maps 
    $local_recipient_maps $mydestination $virtual_alias_maps $virtual_alias_domains $virtual_mailbox_maps $virtual_mailbox_domains $relay_recipient_maps $relay_domains $canonical_maps $sender_canonical_maps $recipient_canonical_maps $relocated_maps $transport_maps $mynetworks
    smtpd_sender_restrictions 
    check_sender_access regexp:/etc/postfix/tag_as_originating.repermit_mynetworkspermit_sasl_authenticatedcheck_sender_access mysql:/etc/postfix/mysql-virtual_sender.cfcheck_sender_access regexp:/etc/postfix/tag_as_foreign.re
    smtpd_client_restrictions 
    check_client_access mysql:/etc/postfix/mysql-virtual_client.cf
    smtpd_client_message_rate_limit 
    100
    maildrop_destination_concurrency_limit 
    1
    maildrop_destination_recipient_limit 
    1
    virtual_transport 
    dovecot
    header_checks 
    regexp:/etc/postfix/header_checks
    mime_header_checks 
    regexp:/etc/postfix/mime_header_checks
    nested_header_checks 
    regexp:/etc/postfix/nested_header_checks
    body_checks 
    regexp:/etc/postfix/body_checks
    owner_request_special 
    no
    smtp_tls_security_level 
    may
    dovecot_destination_recipient_limit 
    1
    smtpd_sasl_type 
    dovecot
    smtpd_sasl_path 
    = private/auth
    content_filter 
    amavis:[127.0.0.1]:10024
    receive_override_options 
    no_address_mappings
    message_size_limit 
    0

    Help me :(
     
    Last edited: May 9, 2014
  2. srijan

    srijan New Member HowtoForge Supporter

  3. eros23

    eros23 New Member

    I'm not blacklisted. I use dyndns domain as the domain and not as dynamic. I I purchased the domain from them. I have also tried other providers for this but that was not the problem. I also tried different IP.
    My reverse DNS appears to be correct.

    PHP:
    root@vps:~# dig lgnuke.com

    ; <<>> DiG 9.8.4-rpz2+rl005.12-P1 <<>> lgnuke.com
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>
    HEADER<<- opcodeQUERYstatusNOERRORid65230
    ;; flagsqr aa rd raQUERY1ANSWER1AUTHORITY2ADDITIONAL4

    ;; QUESTION SECTION:
    ;
    lgnuke.com.                    IN      A

    ;; ANSWER SECTION:
    lgnuke.com.             3600    IN      A       37.187.199.12

    ;; AUTHORITY SECTION:
    lgnuke.com.             3600    IN      NS      rita.ns.cloudflare.com.
    lgnuke.com.             3600    IN      NS      dave.ns.cloudflare.com.

    ;; 
    ADDITIONAL SECTION:
    dave.ns.cloudflare.com22609   IN      A       173.245.59.109
    dave
    .ns.cloudflare.com25388   IN      AAAA    2400:cb00:2049:1::adf5:3b6d
    rita
    .ns.cloudflare.com22609   IN      A       173.245.58.140
    rita
    .ns.cloudflare.com105667  IN      AAAA    2400:cb00:2049:1::adf5:3a8c

    ;; Query time1 msec
    ;; SERVER127.0.0.1#53(127.0.0.1)
    ;; WHENFri May  9 08:17:54 2014
    ;; MSG SIZE  rcvd184
     
  4. Iheb

    Iheb New Member

    I have the same problem,i know when is the problem but i dont know jow resolve it:
    How is it now: Received: from localhost (localhost.localdomain [127.0.0.1])
    The correct mode is ( in your case) Received: from vps.lgnuke.com (vps.lgnuke.com [37.187.199.12])

    Anyone say how resolve it please ?
     
  5. till

    till Super Moderator Staff Member ISPConfig Developer

    That's not necessarily a problem, a localhost mail header can be absolutely fine. Please post the complete headers of that mail.
     
  6. Iheb

    Iheb New Member

    Ok, i will post configuration file and header , thank !
     
    Last edited: Oct 25, 2017
  7. Iheb

    Iheb New Member

    - I want to tell you that into my servers contain 2 Domains, but i usually use just one
    - Another problem that i find it's that my IP is into 2 Blackists: can it possible problem?
    - I want to tell you when insto ssh i digit hostname it compare mail.ihebtech.online, and when i digit hostname -f it compare again mail.ihebtech.online
    Header
    PHP:
    Receivedfrom VE1EUR03HT073.eop-EUR03.prod.protection.outlook.com
    (2603:10a6:207:3::15by AM4PR09MB0739.eurprd09.prod.outlook.com with HTTPS
    via AM3PR05CA0137
    .EURPRD05.PROD.OUTLOOK.COMWed25 Oct 2017 11:09:19 +0000
    Received
    from VE1EUR03FT034.eop-EUR03.prod.protection.outlook.com
    (10.152.18.52by VE1EUR03HT073.eop-EUR03.prod.protection.outlook.com
    (10.152.19.202with Microsoft SMTP Server (version=TLS1_2,
    cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384id 15.20.156.4Wed25
    Oct 2017 11
    :09:19 +0000
    Authentication
    -Resultsspf=pass (sender IP is 54.36.191.189)
    smtp.mailfrom=ihebtech.ithotmail.itdkim=pass (signature was verified)
    header.d=ihebtech.it;hotmail.itdmarc=pass action=none
    header
    .from=ihebtech.it;
    Received-SPFPass (protection.outlook.comdomain of ihebtech.it designates
    54.36.191.189 
    as permitted senderreceiver=protection.outlook.com;
    client-ip=54.36.191.189helomail.ihebtech.online;
    Receivedfrom COL004-MC4F32.hotmail.com (10.152.18.56by
    VE1EUR03FT034
    .mail.protection.outlook.com (10.152.18.85with Microsoft SMTP
    Server 
    (version=TLS1_2cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384id
    15.20.156.4 via Frontend Transport
    Wed25 Oct 2017 11:09:18 +0000
    X
    -IncomingTopHeaderMarkerOriginalChecksum:E1DE364A87515C662876FC0810F0549AB9AB2C83DBF9FFDB72D5D6C20F0C674D;UpperCasedChecksum:F0D9CE656B6CBACCAE57F59FDE6C34AC3ECEC0A96A70D11A640F7C264FBFD129;SizeAsReceived:1989;Count:15
    Received
    from mail.ihebtech.online ([54.36.191.189]) by COL004-MC4F32.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.23143);
         
    Wed25 Oct 2017 04:09:15 -0700
    Received
    from localhost (localhost [127.0.0.1])
        
    by mail.ihebtech.online (Postfixwith ESMTP id 1BBA345D37
        
    for <aouamiheb98@hotmail.it>; Wed25 Oct 2017 13:09:14 +0200 (CEST)
    DKIM-Signaturev=1a=rsa-sha256c=relaxed/simpled=ihebtech.ith=
        
    content-type:content-type:mime-version:from:from:message-id:date
        
    :dates=default; t=1508929753x=1510744154bh=F9o4W8zBNIpWbEB
        fgJsB2JOB1TINrgtmFkLqmle9Vo0
    =; b=ArbBYa2uk8GTtl8mYDu0uRRcgFpFDnQ
        szPzrWGxj
    /l3VSFu8Pm2xSYOB+A8MBAzM/K3cD3eR9OA5aQNYaJPCOpAQIbUUUQA
        jbw8yMMDFNEIT
    +ANwYQYzkaGUHknYvkITT/OGOIAJL2xrzGxCUPGjIaA902tm7uV
        ZYwn8rgveY5EZPa3tvZ9Om
    +w+3X89ZFVe+NU+tMwoyykQJOQ1dr9nO5NwtpebAHs
        k24zmCQxHzmKxVfPMWCYduLNXagxyK2ekXKlrAFcORZA65OHkqM8oSl29mQz69f1
        rJwow6x74NLcvdVsbH4hLBIRc
    /Dfni0YYgjYgB7A6cSqx3NfT7kSBtA==
    X-Virus-ScannedDebian amavisd-new at mail.ihebtech.online
    Received
    from mail.ihebtech.online ([127.0.0.1])
        
    by localhost (mail.ihebtech.online [127.0.0.1]) (amavisd-new, port 10026)
        
    with ESMTP id 4pxWAkkZcjMq for <aouamiheb98@hotmail.it>;
        
    Wed25 Oct 2017 13:09:13 +0200 (CEST)
    Receivedfrom [192.168.1.187] (host234-6-dynamic.59-82-r.retail.telecomitalia.it [82.59.6.234])
        (
    Authenticated senderiheb.aouam@ihebtech.it)
        
    by mail.ihebtech.online (Postfixwith ESMTPSA id 79C3745B1A
        
    for <aouamiheb98@hotmail.it>; Wed25 Oct 2017 13:09:13 +0200 (CEST)
    DateWed25 Oct 2017 13:09:11 +0200
    Message
    -ID: <6hg9o415a2nab79knbxpy9de.1508929751639@email.android.com>
    From"[email protected]<iheb.aouam@ihebtech.it>
    To: <aouamiheb98@hotmail.it>
    Content-Typemultipart/alternativeboundary="--_com.samsung.android.email_555974415150840"
    Return-Pathiheb.aouam@ihebtech.it
    X
    -OriginalArrivalTime25 Oct 2017 11:09:16.0038 (UTCFILETIME=[B23DA260:01D34D81]
    X-IncomingHeaderCount15
    X
    -MS-Exchange-Organization-Network-Message-Idf2739709-6939-400f-291c-08d51b98d689
    X
    -EOPAttributedMessage0
    X
    -EOPTenantAttributedMessage84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
    X
    -MS-Exchange-Organization-MessageDirectionalityIncoming
    CMM
    -sender-ip54.36.191.189
    CMM
    -sending-ip54.36.191.189
    CMM
    -Authentication-Resultshotmail.comspf=pass (sender IP is
    54.36.191.189
    identity alignment result is pass and alignment mode is
    relaxed
    smtp.mailfrom=iheb.aouam@ihebtech.itdkim=pass (identity alignment
    result is pass 
    and alignment mode is relaxedheader.d=ihebtech.it;
    x-hmca=pass header.id=iheb.aouam@ihebtech.it
    CMM
    -X-SID-PRAiheb.aouam@ihebtech.it
    CMM
    -X-AUTH-ResultPASS
    CMM
    -X-SID-ResultPASS
    Configurazion File main.cf (Postfix)
    PHP:
    # See /usr/share/postfix/main.cf.dist for a commented, more complete version


    # Debian specific:  Specifying a file name will cause the first
    # line of that file to be used as the name.  The Debian default
    # is /etc/mailname.
    #myorigin = /etc/mailname

    smtpd_banner $myhostname ESMTP $mail_name (Ubuntu)
    biff no

    # appending .domain is the MUA's job.
    append_dot_mydomain no

    # Uncomment the next line to generate "delayed mail" warnings
    #delay_warning_time = 4h

    readme_directory = /usr/share/doc/postfix

    # TLS parameters
    smtpd_tls_cert_file = /etc/postfix/smtpd.cert
    smtpd_tls_key_file 
    = /etc/postfix/smtpd.key
    smtpd_use_tls 
    yes
    smtpd_tls_session_cache_database 
    btree:${data_directory}/smtpd_scache
    smtp_tls_session_cache_database 
    btree:${data_directory}/smtp_scache

    # See /usr/share/doc/postfix/TLS_README.gz in the postfix-doc package for
    # information on enabling SSL in the smtp client.

    smtpd_relay_restrictions permit_mynetworks permit_sasl_authenticated defer_unauth_destination
    myhostname 
    mail.ihebtech.online
    alias_maps 
    hash:/etc/aliaseshash:/var/lib/mailman/data/aliases
    alias_database 
    hash:/etc/aliaseshash:/var/lib/mailman/data/aliases
    myorigin 
    = /etc/mailname
    mydestination 
    mail.ihebtech.onlinelocalhostlocalhost.localdomain
    relayhost 
    =
    mynetworks 127.0.0.0/[::1]/128
    mailbox_size_limit 
    1073741824
    recipient_delimiter 
    = +
    inet_interfaces all
    inet_protocols 
    all
    html_directory 
    = /usr/share/doc/postfix/html
    virtual_alias_domains 
    =
    virtual_alias_maps hash:/var/lib/mailman/data/virtual-mailmanproxy:mysql:/etc/postfix/mysql-virtual_forwardings.cfproxy:mysql:/etc/postfix/mysql-virtual_email2em$
    virtual_mailbox_domains proxy:mysql:/etc/postfix/mysql-virtual_domains.cf
    virtual_mailbox_maps 
    proxy:mysql:/etc/postfix/mysql-virtual_mailboxes.cf
    virtual_mailbox_base 
    = /var/vmail
    virtual_uid_maps 
    mysql:/etc/postfix/mysql-virtual_uids.cf
    virtual_gid_maps 
    mysql:/etc/postfix/mysql-virtual_gids.cf
    sender_bcc_maps 
    proxy:mysql:/etc/postfix/mysql-virtual_outgoing_bcc.cf
    smtpd_sasl_auth_enable 
    yes
    broken_sasl_auth_clients 
    yes
    smtpd_sasl_authenticated_header 
    yes
    smtpd_restriction_classes 
    greylisting
    greylisting 
    check_policy_service inet:127.0.0.1:10023
    smtpd_recipient_restrictions 
    permit_mynetworkspermit_sasl_authenticatedreject_unauth_destinationreject_rbl_client zen.spamhaus.orgcheck_recipient_access mysq$
    smtpd_tls_security_level may
    transport_maps 
    hash:/var/lib/mailman/data/transport-mailmanproxy:mysql:/etc/postfix/mysql-virtual_transports.cf
    relay_domains 
    mysql:/etc/postfix/mysql-virtual_relaydomains.cf
    relay_domains 
    mysql:/etc/postfix/mysql-virtual_relaydomains.cf
    relay_recipient_maps 
    mysql:/etc/postfix/mysql-virtual_relayrecipientmaps.cf
    smtpd_sender_login_maps 
    proxy:mysql:/etc/postfix/mysql-virtual_sender_login_maps.cf
    proxy_read_maps 
    $local_recipient_maps $mydestination $virtual_alias_maps $virtual_alias_domains $sender_bcc_maps $virtual_mailbox_maps $virtual_mailbox_domains $rela$
    smtpd_helo_required yes
    smtpd_helo_restrictions 
    permit_sasl_authenticatedpermit_mynetworkscheck_helo_access regexp:/etc/postfix/helo_accessreject_invalid_hostnamereject_non_fqdn_hos$
    smtpd_sender_restrictions check_sender_access regexp:/etc/postfix/tag_as_originating.re permit_mynetworkspermit_sasl_authenticatedcheck_sender_access mysql:/et$
    smtpd_client_restrictions check_client_access mysql:/etc/postfix/mysql-virtual_client.cf
    smtpd_client_message_rate_limit 
    100
    maildrop_destination_concurrency_limit 
    1
    maildrop_destination_recipient_limit 
    1
    virtual_transport 
    dovecot
    header_checks 
    regexp:/etc/postfix/header_checks
    mime_header_checks 
    regexp:/etc/postfix/mime_header_checks
    nested_header_checks 
    regexp:/etc/postfix/nested_header_checks
    body_checks 
    regexp:/etc/postfix/body_checks
    owner_request_special 
    no
    smtp_tls_security_level 
    may
    smtpd_tls_mandatory_protocols 
    = !SSLv2, !SSLv3
    smtpd_tls_protocols 
    = !SSLv2,!SSLv3
    smtp_tls_protocols 
    = !SSLv2,!SSLv3
    smtpd_tls_exclude_ciphers 
    RC4aNULL
    smtp_tls_exclude_ciphers 
    RC4aNULL
    dovecot_destination_recipient_limit 
    1
    smtpd_sasl_type 
    dovecot
    smtpd_sasl_path 
    = private/auth
    content_filter 
    amavis:[127.0.0.1]:10024
    receive_override_options 
    no_address_mappings
    message_size_limit 
    20971520
    I want to report also my configuration /etc/hosts:
    PHP:
    # Example: 127.0.0.1
    127.0.0.1       localhost

    # Example: 54.36.191.189
    54.36.191.189   mail.ihebtech.online    mail

    # Example: 127.0.1.1
    127.0.1.1       vps466177.ovh.net       vps466177
    P.S: Sorry for my bad english !
     

Share This Page