January 28, 2012

L2.APEWS.ORG False Positive #11

First one this month so far, not bad going. This is another of the sending servers for the travel industry, some of our users found this in their spam folder, incorrectly. It must have been recently listed, I haven't checked as yet what the listing says but as far as we are concerned here, the IP is a trusted source. Here is the email header;

Fri 2012-01-27 16:33:25: [6810:112] Accepting SMTP connection from [205.201.136.59]
Fri 2012-01-27 16:33:25: [6810:112] Looking up PTR record for 205.201.136.59 (59.136.201.205.IN-ADDR.ARPA)
Fri 2012-01-27 16:33:25: [6810:112] D=59.136.201.205.in-addr.arpa TTL=(1440) PTR=[mail59.us4.mandrillapp.com]
Fri 2012-01-27 16:33:25: [6810:112] Gathering A-records for PTR hosts
Fri 2012-01-27 16:33:25: [6810:112] D=mail59.us4.mandrillapp.com TTL=(1440) A=[205.201.136.59]
Fri 2012-01-27 16:33:25: [6810:112] --> 220 xxx.xxx.xxx ESMTP MDaemon 6.7.9; Fri, 27 Jan 2012 16:33:25 -0500
Fri 2012-01-27 16:33:25: [6810:112] <-- EHLO mail59.us4.mandrillapp.com
Fri 2012-01-27 16:33:25: [6810:112] Performing reverse lookup on mail59.us4.mandrillapp.com (looking for 205.201.136.59)
Fri 2012-01-27 16:33:26: [6810:112] D=mail59.us4.mandrillapp.com TTL=(1440) A=[205.201.136.59]
Fri 2012-01-27 16:33:26: [6810:112] --> 250-xxx.xxx.xxx Hello mail59.us4.mandrillapp.com, pleased to meet you
Fri 2012-01-27 16:33:26: [6810:112] --> 250-ETRN
Fri 2012-01-27 16:33:26: [6810:112] --> 250-AUTH=LOGIN
Fri 2012-01-27 16:33:26: [6810:112] --> 250-AUTH LOGIN CRAM-MD5
Fri 2012-01-27 16:33:26: [6810:112] --> 250-8BITMIME
Fri 2012-01-27 16:33:26: [6810:112] --> 250 SIZE 0
Fri 2012-01-27 16:33:26: [6810:112] <-- MAIL FROM: BODY=8BITMIME
Fri 2012-01-27 16:33:26: [6810:112] Performing reverse lookup on mail59.us4.mandrillapp.com (looking for 205.201.136.59)
Fri 2012-01-27 16:33:26: [6810:112] D=mail59.us4.mandrillapp.com TTL=(1439) A=[205.201.136.59]
Fri 2012-01-27 16:33:26: [6810:112] Spam Blocker A-record resolution of [59.136.201.205.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...
Fri 2012-01-27 16:33:26: [6810:112] Spam Blocker D=59.136.201.205.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]
Fri 2012-01-27 16:33:26: [6810:112] L2.APEWS.ORG LISTED
Fri 2012-01-27 16:33:26: [6810:112] Message will be accepted and X-RBL-Warning: header will be inserted.
Fri 2012-01-27 16:33:26: [6810:112] --> 250 , Sender ok
Fri 2012-01-27 16:33:26: [6810:112] <-- RCPT TO:
Fri 2012-01-27 16:33:26: [6810:112] --> 250 , Recipient ok
Fri 2012-01-27 16:33:26: [6810:112] <-- DATA
Fri 2012-01-27 16:33:26: [6810:112] --> 354 Enter mail, end with .
Fri 2012-01-27 16:33:27: [6810:112] --> 250 Ok, message saved
Fri 2012-01-27 16:33:27: [6810:112] <-- QUIT
Fri 2012-01-27 16:33:27: [6810:112] --> 221 See ya in cyberspace
Fri 2012-01-27 16:33:27: [6810:112] SMTP session successful, 30303 bytes transferred.
Fri 2012-01-27 16:33:27: [6810:112] Shuffling message(s) into proper queue(s)
Fri 2012-01-27 16:33:27: [6810:112] Message received from mail59.us4.mandrillapp.com [205.201.136.59] with SMTP for [Size 32292] {j:\localq\0005140404.msg}

We will check this and report back in due course.

9 comments:

  1. Having looked into this some we find that it wasn't a recently listed IP address but actually a long listed CIDR for reasons of forward and reverse dns missing or mismatch. We have to assume that the travel newsletter changed their IP address for this edition. From what we could see at Senderbase.org, most of the IP addresses within theat CIDR do in fact have matching forward and reverse dns. Good news is that the IP address had been delisted.

    ReplyDelete
  2. Dear Apews.org

    I am a forum owner hosted by Godaddy.com, and our website has nothing to do with spam or other kind of spam mails!

    It startet when my users couldnt get Activation emails to HOTMAIL.com, and I had to search the issue, and I am very new with websiting and spam blockings! So I startet to search and test my ip for Blacklistings! I checked our ip at Blacklistalert.org and it was clean all the way, only 1 place called "l2.apews.org" said it was listed! So I clicked on the link wich said "SEE WHY" and It took me to apews.org website! I had problems finding out where to write you guys a message, now I dont know if I sould PAST my IP in here, but I wont, instead, I trully hope you can send my a reply about why I our forum is listet at "apews.org" Our ip is 50.63.40.1 and website Barbie-Designs.com.....Thank u so much in advance!

    apews.org

    ReplyDelete
    Replies
    1. From Whois we can see that Godaddy.com are announcing the CIDR 50.62.0.0/15. The reputation of Godaddy could affect the delivery of emails from an IP address in that CIDR. The likes of Hotmail etc have their own blacklists and filters and I doubt they use 3rd party lists like APEWS, more likely you are seeing at least 2 separate problems. Your domain shows email handled by; 58c35e0e29ab1a44bd0fb3525da51c.pamx1.hotmail.com and mailstore1.secureserver.net but with an IP 50.63.40.1, is that right? It seems odd to have an MX of Hotmail and delivery problems into Hotmail by your users.

      Delete
  3. Maybe, this isn't the place to post my requirement, but I need urgent help.
    Today, I realized that my IP is blacklisted in apews and In the webpage there isn't the way to deslist my IP.
    Thanks a lot!!!

    ReplyDelete
    Replies
    1. This is just a blog for APEWS users to publish errors so if you have a client that uses APEWS and your emails are now being rejected, ask your client to post the email header and perhaps the APEWS Administrators will edit their data. How good is the reputation of the IP address management? Have you informed them of the blacklisting?

      Delete
  4. iam not spammer and i am listed to your data base please how to deslist my IP from your list ..........

    ReplyDelete
    Replies
    1. Maybe your IP address is in a bad IP neighborhood, or someone else was abusive and got that IP blacklisted before you got it. Are you getting email delivery problems? If you checked APEWS.org and its listed, and your email recipients are using APEWS.org then you can ask them to whitelist your IP, also publish an email header here showing your email to be a false positive. At least give the IP address or the CIDR so that it can be checked.

      Delete
  5. mail domain is cng.edu how I can deslist of you dns black list? we are not spam generatos. please tell me

    ReplyDelete
  6. thx youuuu thxxx youuuuuuuuu mérciiiiiiiii
    http://jeuxjeux99.blogspot.com/
    العاب سيارات هنا سوف ستجدون تشكيلة مميزة من أروع و أفضل ما يوجد في العاب سيارات يمكنك اللعب مباشرة وبسهولة تامة بدون تحميل و مرحبا بالجميع في موقع العاب سيارات .

    ReplyDelete