EFA, Exchange 2010 and CBL Blacklist
Posted: 24 Sep 2014 16:22
Hi All,
I'm testing EFA between Internet and internal Exchange 2010.
The configuration is:
Ingoing emails: Internet (port 25) -> EFA -> Exchange 2010 -> Users Clients
Outgoing emails: Users Clients -> Exchange 2010 -> Internet
The EFA server is configured to accept all e-mail for our domains, even those recognized as spam and deliver them, marked, to the Exchange 2010 server.
This is to enable the delivery of e-mails identified as spam to the Junk folder for each user.
The problem is that the day after activating this configuration, our public IP address has been blacklisted in cbl.abuseat.org.
The cause seems to be an infection with the Cutwail spambot, it seems strange however, that in the weeks before I had no problems.
It's possible that some configuration problems can cause this type of problem?
For example, in my case the e-mails are accepted by the EFA without checking if the user exists in the domain, then Exchange (without going through EFA) may reject the message because the user does not exist. This behavior of accepting and then send back an e-mail from the system can be considered abnormal?
It 's normal to configure the system so that the E-Mail from Exchange do not go in EFA?
Any advice is welcome, I would try to understand the problem before try again, because to delete the IP from the Blacklist takes a few hours in which our emails are no longer being accepted.
Many thanks to all
Best Regards
Fil
I'm testing EFA between Internet and internal Exchange 2010.
The configuration is:
Ingoing emails: Internet (port 25) -> EFA -> Exchange 2010 -> Users Clients
Outgoing emails: Users Clients -> Exchange 2010 -> Internet
The EFA server is configured to accept all e-mail for our domains, even those recognized as spam and deliver them, marked, to the Exchange 2010 server.
This is to enable the delivery of e-mails identified as spam to the Junk folder for each user.
The problem is that the day after activating this configuration, our public IP address has been blacklisted in cbl.abuseat.org.
The cause seems to be an infection with the Cutwail spambot, it seems strange however, that in the weeks before I had no problems.
It's possible that some configuration problems can cause this type of problem?
For example, in my case the e-mails are accepted by the EFA without checking if the user exists in the domain, then Exchange (without going through EFA) may reject the message because the user does not exist. This behavior of accepting and then send back an e-mail from the system can be considered abnormal?
It 's normal to configure the system so that the E-Mail from Exchange do not go in EFA?
Any advice is welcome, I would try to understand the problem before try again, because to delete the IP from the Blacklist takes a few hours in which our emails are no longer being accepted.
Many thanks to all
Best Regards
Fil