- Joined
- Apr 29, 2021
- Messages
- 1
- Reaction score
- 0
Hope the following assists 3CX in amending mail delivery routing or SPF (Sender Policy Framework) associated with the 3cx.com domain as 25% of all mail via Microsoft are being rejected, in accordance with how the 3cx.com DMARC record is structured.
Herewith mail processing logs where it shows the mail to have originated from 104.47.2.57 which doesn't match SPF records (controlled by 3CX). The 3cx.com domain's DMARC record (again controlled by 3CX) indicates that 25% of messages failing SPF should be rejected.
Herewith the mail processing logs:
Herewith mail processing logs where it shows the mail to have originated from 104.47.2.57 which doesn't match SPF records (controlled by 3CX). The 3cx.com domain's DMARC record (again controlled by 3CX) indicates that 25% of messages failing SPF should be rejected.
Herewith the mail processing logs:
Code:
15:25:05.499 Thread 5124 running on 29 Apr 2021 (using v8.2.4.11170) for new message.
15:25:05.499 TX: <220 mma2.redacted ESMTP Trustwave SEG (v8.2.4.11170) Ready>
15:25:05.672 RX: <EHLO EUR01-DB5-obe.outbound.protection.outlook.com>
15:25:05.853 <104.47.2.57> has a PTR record, but does not match HELO string <EUR01-DB5-obe.outbound.protection.outlook.com>, accepting anyway
Ptrs = mail-db5eur01lp2057.outbound.protection.outlook.com
15:25:05.853 TX: <250-mma2.redacted Hello EUR01-DB5-obe.outbound.protection.outlook.com (104.47.2.57)
250-AUTH CRAM-MD5 PLAIN LOGIN
250-AUTH=CRAM-MD5 PLAIN LOGIN
250-STARTTLS
250-XLHASH
250 SIZE
>
15:25:06.026 RX: <STARTTLS>
15:25:06.079 TX: <220 Ready to start TLS>
15:25:06.253 TLS: Certificate has no distribution points
15:25:06.609 TLS: CRL distribution point found: http://crl3.digicert.com/DigiCertCloudServicesCA-1-g1.crl
15:25:06.609 TLS: CRL distribution point found: http://crl4.digicert.com/DigiCertCloudServicesCA-1-g1.crl
15:25:06.609 TLS: Checking CRL distribution point: http://crl3.digicert.com/DigiCertCloudServicesCA-1-g1.crl
15:25:06.610 TLS: Retrieved CRL from distribution point: http://crl3.digicert.com/DigiCertCloudServicesCA-1-g1.crl
15:25:06.610 TLS: Checking CRL distribution point: http://crl4.digicert.com/DigiCertCloudServicesCA-1-g1.crl
15:25:06.611 TLS: Retrieved CRL from distribution point: http://crl4.digicert.com/DigiCertCloudServicesCA-1-g1.crl
15:25:06.611 TLS: Client certificate received.
15:25:06.615 TLS negotiation successful.
15:25:06.615 TLS version: TLSv1.2, TLS cipher: ECDHE-RSA-AES256-GCM-SHA384
15:25:06.789 RX: <EHLO EUR01-DB5-obe.outbound.protection.outlook.com>
15:25:06.790 <104.47.2.57> has a PTR record, but does not match HELO string <EUR01-DB5-obe.outbound.protection.outlook.com>, accepting anyway
Ptrs = mail-db5eur01lp2057.outbound.protection.outlook.com
15:25:06.790 TX: <250-mma2.redacted Hello EUR01-DB5-obe.outbound.protection.outlook.com (104.47.2.57)
250-AUTH CRAM-MD5 PLAIN LOGIN
250-AUTH=CRAM-MD5 PLAIN LOGIN
250-XLHASH
250 SIZE
>
15:25:07.004 RX: <MAIL FROM:<[email protected]> SIZE=30702 AUTH=<>>
15:25:07.004 MAIL: got arg SIZE="30702"
15:25:07.004 MAIL: got arg AUTH="<>"
15:25:07.004 TX: <250 sender ok <[email protected]>>
15:25:07.217 RX: <RCPT TO:<[email protected]>>
15:25:07.218 Checking user criteria for Rule Global ESMTP Authentication Policy:Accept Messages from Authenticated Users
15:25:07.218 Checking user criteria for Rule License Enforcement Policy:Reject Emails Addressed for Unlicensed Users
15:25:07.218 SPE Direction does NOT match on ruleset - Array Policy - STANDARD POLICY(Connection Policy (Outbound))
15:25:07.218 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Deny Senders in Global Blacklist
15:25:07.219 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Deny Messages over 40MB
15:25:07.219 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Accept Authenticated Senders
15:25:07.219 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):SPF - Log information
15:25:08.990 SPF evaluation result: Fail. Explanation: SPF MAIL FROM check failed
15:25:08.990 Array Policy - STANDARD POLICY(Connection Policy (Inbound)):SPF - Log information triggered.
15:25:08.990 Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):SPF - Log information continuing to process rules
15:25:08.990 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Deny mail from IPs in Barracuda BRBL DNS Blacklist
15:25:08.996 Reputation lookup: 104.47.2.57 is not listed in <Barracuda BRBL b.barracudacentral.org> - rcode(0)
15:25:08.997 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Deny mail from IPs in Spamcop DNS Blacklist
15:25:09.335 Reputation lookup: 104.47.2.57 is not listed in <SpamCop bl.spamcop.net> - rcode(1)
15:25:09.336 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Deny mail from IPs in XBL Spamhaus DNS Blacklist
15:25:09.341 Reputation lookup: 104.47.2.57 is not listed in <Spamhaus SBL-XBL sbl-xbl.spamhaus.org> - rcode(1)
15:25:09.342 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Deny mail from IPs in Dynamic IP SORBS Blacklist
15:25:09.515 Reputation lookup: 104.47.2.57 is not listed in <SORBS Dynamic IP dul.dnsbl.sorbs.net> - rcode(1)
15:25:09.515 Checking user criteria for Rule Array Policy - STANDARD POLICY(Connection Policy (Inbound)):Deny Messages where IP used in HELO String
15:25:09.515 Checking user criteria for Rule Customer Policy - REDACTED(Incoming):Unwanted sender
15:25:09.515 SPE Customer ID=2, SPE Domain ID=1, direction=incoming
15:25:09.516 Created temp mail file <~B608ab3b50000.000000000001.0006.mml>
15:25:09.516 TX: <250 recipient ok <[email protected]>>
15:25:09.730 RX: <DATA>
15:25:09.730 TX: <354 send the mail data, end with .>
15:25:09.945 Message data received.
15:25:09.945 speCustomerId: 2, speDomainId: 1, Direction: incoming
15:25:09.945 Original id 2, recalculation 2.
15:25:09.945 Checking relay tables for customer id 2
15:25:09.945 Entry not found when checking relay tables for customer id 2
15:25:09.945 Found 0 matching relay entries
15:25:09.945 Post Body: SPE Customer ID=2, SPE Domain ID=1, direction=incoming
15:25:09.945 IP was not in the customer relay table.
15:25:09.945 DKIM: Checking signature.
15:25:10.161 DKIM: v=1; a=rsa-sha256; c=relaxed/relaxed; d=3cx.com; s=s1; h=content-transfer-encodin:content-type:from:mime-version:to:subject; b=Xr7BkbP1...
15:25:10.161 DKIM: Verification completed.
15:25:10.330 Receiver DMARC result is: Pass, pct=25 (sampled false)