Page 1 of 1

Domain not found

Posted: 13 Sep 2021 22:53
by AbriaCloud
I have a really odd issue that has never happened with eFa before. A domain that has been working for a number of years and is listed in the transport database and /etc/postfix/transport file is no longer receiving mail. Domain not found is appearing. I tried on two other eFa appliances (mirrored configuration) and it works fine there. There are 50 other domains in the transport file and they all work as well. Just this one domain.

/var/log/maillog:
Sep 13 12:23:29 spam-001 postfix/smtpd[18123]: connect from 123.mta.masked.tld[123.123.123.123]
Sep 13 12:23:30 spam-001 postfix/smtpd[18123]: Anonymous TLS connection established from 123.mta.masked.tld[123.123.123.123]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Sep 13 12:23:30 spam-001 postfix/smtpd[18123]: NOQUEUE: reject: RCPT from 123.mta.masked.tld[123.123.123.123]: 450 4.1.2 <user.one@domain-name.com>: Recipient address rejected: Domain not found; from=<bounce-69598_HTML-295442620-83475-514011619-821671@bounce.b.s11.pdmailservice.com> to=<user.one@domain-name.com> proto=ESMTP helo=<123.mta.masked.tld>
Sep 13 12:23:30 spam-001 postfix/smtpd[18123]: disconnect from 123.mta.masked.tld[123.123.123.123] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6

eFa-4.0.4
MailWatch Version: 1.2.16
Operating System Version: CentOS Linux 7 (Core)
Postfix Version: 3.5.9
MailScanner Version: 5.4.1
ClamAV Version: 0.103.3
SpamAssassin Version: 3.4.6
PHP Version: 7.4.21
MySQL Version: 10.2.30-MariaDB
GeoIP Database Version: GeoLite2 Country database 2021-08-23 14:51:43

Not sure where to start. I have postmapped the transport file, rebooted, etc.. No change.

Re: Domain not found

Posted: 15 Sep 2021 11:04
by shawniverson
This usually indicates a problem with DNS. Are you able to resolve the domain's A and MX records from the applicance?

Re: Domain not found

Posted: 16 Sep 2021 15:20
by AbriaCloud
You are correct. It looks like and internal vs external DNS server issue. I was assuming that eFa was looking at the transport file for the domain name, but it must be doing a lookup as well.

Thank you for catching this.