This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to change HELO hostname for outbound SMTP sessions?

Hi!

I'm facing a strange problem: My mailserver, which is behind an XG, recently get blocked by Cisco's SenderBase algorithm because it identifies itself with a wrong hostname when issuing the HELO/EHLO command. I've already confirmed that the mailserver does send the correct name ("HELO mail.mydomain.com") but Cisco told me, they were informed that my server sends a "HELO Sophos" instead!

That gave me a real bad reputation on their list and some SMTP server are already starting to refuse connections from my host.

It looks to me that the XG uses somekind of (transparent) outbound SMTP proxy which rewrites the commands my mailserver issues.

Is there any possibility to either deactivate this behaviour or, even better, to change the HELO hostname?

Thanks in advance...



This thread was automatically locked due to age.
Parents Reply Children
  • But it's still unclear to me which component is causing this. I mean, does my XG intercept "some" (definitely not every) outgoing SMTP connections? Does the XG tries to send some mails on its own?

  • Hi,

    is there any update on this ? 

    /bin/awarrensmtp

    .    ^H..    ^H..    ^HX.    ^HH.    ^H..    ^H .    ^H . 

    ^@rcptto != NULL^@nfy != NULL^@nfy->mailserver != NULL^@forward_mail: '%s'                                                                                                                                                                                                    

    ^@Waiting for reply                                                                                                                                                                                                                                                           

    ^@%s:%d:: fgets(%s) failed: %s                                                                                                                                                                                                                                                

    ^@NFY < '%s'                                                                                                                                                                                                                                                                  

    ^@%s:%d:: Invalid reply '%s'                                                                                                                                                                                                                                                  

    ^@%s:%d:: -ve reply: '%s'                                                                                                                                                                                                                                                     

    ^@HELO Sophos^M                                                                                                                                                                                                                                                               

    ^@NFY > '%s'                                                                                                                                                                                                                                                                  

    ^@%s:%d:: fputs(%s) failed: %s                                                                                                                                                                                                                                                

    ^@Done Sending mail body                                                                                                                                                                                                                                                      

    ^@^M                                                                                                                                                                                                                                                                          

    .^M                                                                                                                                                                                                                                                                           

    ^@QUIT^M               

    We got blacklisted in spamhouse because of bad HELO=Sophos                                                                                                                                                                                                                                                    

  • Hi Everyone,

    Update XG to v16 (beta now) where MTA is back and you can change even the SMTP Hostname and almost all other settings like UTM 9

  • Thanks for the info Luk.

    EDIT: but unfortunately v16 beta is not released for our hardware. 

  • When 15.01 MR-4 will be released? I have to route all outgoing mail through second gateway due to "HELO Sophos" bug, that is causing our domain blacklisted (Cisco SenderBase and SORBS). I don't want to test V16beta on production firewall now.

    Over 2 months of waiting to fix this critical issue and still no MR-4 :(

  • I was facing the same problem but finally fixed it, my mails are no longer bounced, they're delivered just fine.

     

     

    Solution: Go to Email >> General Settings >> SMTP Hostname [This will be used in HELO and SMTP greeting strings].

    In the Value of SMTP Hostname, put in your domain eg, XXXXX.com, XXXX.co.bk  [but not hostname of your mail server as that will cause a loop back given that your firewall is just acting as an SMTP Relay]

    I this reply is late but I hope it helps someone facing the same problem.

     

    Regards,

    andsjeff