Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

90% aller Mails als Spam(confirmed) markiert - auf einmal??

Hallo zusammen,

seit Montag haben wir das Problem das 90% unserer eingehenden Mails als Spam(confirmed) markiert werden, täglich ankommend ca 3500 Mails insgesamt. Mails von Absendern mit denen wir schon lange kommunizieren. Im Einsatz ist eine SG230 UTM 9.506-2. Geändert wurde auf unserer Seite nichts.

Normalerweise landen solche Mails immer in Quarantäne (sind eigentlich nie viele gewesen) und wurden dann manuell geprüft. Ist jetzt so ja nicht mehr umsetzbar! Habe erst mal die Regel bei Spam(confirmed) geändert auf "Warnen" mit entsprechenden Zusatz im Header. Aber dies ist ja keine dauerhafte Lösung!

Reboot hat nicht geholfen.

Über Tips würde ich mich freuen.

 

Danke,

 

Ingo



This thread was automatically locked due to age.
Parents
  • Hallo Ingo,

    (Sorry, my German-speaking brain isn't creating thoughts at the moment. [:(])

    If you still need help with this, please show us the section of the SMTP log where one of the false-positive rejections occurred.

    MfG - Bob (Bitte auf Deutsch weiterhin.)

  • Hallo,

     

    hier ist mal ein Auszug aus dem Protokoll. Die erste Mail wurde positive false gekennzeichnet.

    2018:03:10-10:10:18 XXXXXXXX exim-in[6239]: 2018-03-10 10:10:18 SMTP connection from [10.252.80.36]:38679 (TCP/IP connection count = 1)
    2018:03:10-10:10:18 XXXXXXXX exim-in[26980]: 2018-03-10 10:10:18 H=(idvdirektmail02.services.datevnet.de) [10.252.80.36]:38679 Warning: xxxxx.de profile excludes greylisting: Skipping greylisting for this message
    2018:03:10-10:10:18 XXXXXXXX exim-in[26980]: 2018-03-10 10:10:18 H=(idvdirektmail02.services.datevnet.de) [10.252.80.36]:38679 Warning: xxxxx.de profile excludes SANDBOX scan
    2018:03:10-10:10:18 XXXXXXXX exim-in[26980]: 2018-03-10 10:10:18 [10.252.80.36] F=<xxxxx@gmail.com> R=<xxxxx@xxxxx.de> Verifying recipient address in Active Directory
    2018:03:10-10:10:18 XXXXXXXX exim-in[26980]: 2018-03-10 10:10:18 1euaWA-00071A-21 DKIM: d=gmail.com s=20161025 c=relaxed/relaxed a=rsa-sha256 [verification succeeded]
    2018:03:10-10:10:18 XXXXXXXX exim-in[26980]: 2018-03-10 10:10:18 1euaWA-00071A-21 ctasd reports 'Confirmed' RefID:str=0001.0A0B0203.5AA3A0FA.00E8,ss=4,re=0.000,recu=0.000,reip=0.000,cl=4,cld=1,fgs=8
    2018:03:10-10:10:18 XXXXXXXX exim-in[26980]: 2018-03-10 10:10:18 1euaWA-00071A-21 <= xxxxx@gmail.com H=(idvdirektmail02.services.datevnet.de) [10.252.80.36]:38679 P=esmtp S=27508 id=D9DC29C8-663E-44DA-ADFC-5D10A4AF6345@gmail.com
    2018:03:10-10:10:18 XXXXXXXX exim-in[26980]: 2018-03-10 10:10:18 SMTP connection from (idvdirektmail02.services.datevnet.de) [10.252.80.36]:38679 closed by QUIT
    2018:03:10-10:10:20 XXXXXXXX smtpd[6223]: QMGR[6223]: 1euaWA-00071A-21 moved to work queue
    2018:03:10-10:10:30 XXXXXXXX smtpd[26989]: SCANNER[26989]: 1euaWM-00071J-4t <= xxxxx@gmail.com R=1euaWA-00071A-21 P=INPUT S=22188
    2018:03:10-10:10:30 XXXXXXXX smtpd[26989]: SCANNER[26989]: id="1001" severity="info" sys="SecureMail" sub="smtp" name="email quarantined" srcip="10.252.80.36" from="xxxxx@gmail.com" to="xxxxx@xxxxx.de" subject="Re: xxxxxzahlungen 2018" queueid="1euaWM-00071J-4t" size="22188" reason="as" extra="confirmed"
    2018:03:10-10:10:30 XXXXXXXX smtpd[26989]: SCANNER[26989]: 1euaWA-00071A-21 => work R=SCANNER T=SCANNER
    2018:03:10-10:10:30 XXXXXXXX smtpd[26989]: SCANNER[26989]: 1euaWA-00071A-21 Completed
    2018:03:10-10:10:55 XXXXXXXX exim-in[6239]: 2018-03-10 10:10:55 SMTP connection from [10.252.80.30]:57856 (TCP/IP connection count = 1)
    2018:03:10-10:10:55 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:55 H=(idsdirektmail01.services.datevnet.de) [10.252.80.30]:57856 Warning: xxxxx.de profile excludes greylisting: Skipping greylisting for this message
    2018:03:10-10:10:55 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:55 H=(idsdirektmail01.services.datevnet.de) [10.252.80.30]:57856 Warning: xxxxx.de profile excludes SANDBOX scan
    2018:03:10-10:10:55 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:55 [10.252.80.30] F=<Bounce_Eintracht+mlkr2cfwi3bkticl5pjvhkzhkd4@tr.inxmail-commerce.com> R=<xxxxx@xxxxx.de> Verifying recipient address in Active Directory
    2018:03:10-10:10:55 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:55 1euaWl-00071j-2U DKIM: d=inxserver.com s=inxdeka c=relaxed/simple a=rsa-sha256 t=1520673046 [verification failed - signature did not verify (headers probably modified in transit)]
    2018:03:10-10:10:55 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:55 1euaWl-00071j-2U DKIM: d=eintracht-frankfurt.de s=tx c=relaxed/simple a=rsa-sha256 t=1520673046 [verification succeeded]
    2018:03:10-10:10:56 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:56 1euaWl-00071j-2U ctasd reports 'Unknown' RefID:str=0001.0A0B0201.5AA3A120.0018,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0
    2018:03:10-10:10:56 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:56 1euaWl-00071j-2U <= Bounce_Eintracht+mlkr2cfwi3bkticl5pjvhkzhkd4@tr.inxmail-commerce.com H=(idsdirektmail01.services.datevnet.de) [10.252.80.30]:57856 P=esmtp S=117257 id=INXCOM2.eintracht.m.lkr2cfwi3bkticl5pjva.2io25xdwwbfdzlhuhpchmhtlwe@inxmail-commerce.com
    2018:03:10-10:10:56 XXXXXXXX exim-in[27015]: 2018-03-10 10:10:56 SMTP connection from (idsdirektmail01.services.datevnet.de) [10.252.80.30]:57856 closed by QUIT
    2018:03:10-10:10:57 XXXXXXXX smtpd[6223]: QMGR[6223]: 1euaWl-00071j-2U moved to work queue
    2018:03:10-10:10:58 XXXXXXXX smtpd[26989]: SCANNER[26989]: 1euaWo-00071J-9v <= bounce_eintracht+mlkr2cfwi3bkticl5pjvhkzhkd4@tr.inxmail-commerce.com R=1euaWl-00071j-2U P=INPUT S=112614
    2018:03:10-10:10:58 XXXXXXXX smtpd[26989]: SCANNER[26989]: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="10.252.80.30" from="bounce_eintracht+mlkr2cfwi3bkticl5pjvhkzhkd4@tr.inxmail-commerce.com" to="xxxxx@xxxxx.de" subject="Infos der Fanabteilung!" queueid="1euaWo-00071J-9v" size="112614"
    2018:03:10-10:10:58 XXXXXXXX smtpd[26989]: SCANNER[26989]: 1euaWl-00071j-2U => work R=SCANNER T=SCANNER
    2018:03:10-10:10:58 XXXXXXXX smtpd[26989]: SCANNER[26989]: 1euaWl-00071j-2U Completed
    2018:03:10-10:10:58 XXXXXXXX exim-out[27020]: 2018-03-10 10:10:58 1euaWo-00071J-9v => xxxxx@xxxxx.de P=<bounce_eintracht+mlkr2cfwi3bkticl5pjvhkzhkd4@tr.inxmail-commerce.com> R=static_route_hostlist T=static_smtp H=192.168.1.30 [192.168.1.30]:25 X=TLSv1.2:ECDHE-RSA-AES256-SHA384:256 C="250 2.6.0 <INXCOM2.eintracht.m.lkr2cfwi3bkticl5pjva.2io25xdwwbfdzlhuhpchmhtlwe@inxmail-commerce.com>"
    2018:03:10-10:10:58 XXXXXXXX exim-out[27020]: 2018-03-10 10:10:58 1euaWo-00071J-9v Completed

  • So, "the first one" is 1euaWA-00071A-21.  I interpret "ctasd reports 'Confirmed' RefID:str=0001.0A0B0203.5AA3A0FA.00E8..." as confirming Steve's suggestion that the problem is an issue with ctasd or CommTouch.

    I would open a ticket with Sophos so that they know there's an issue.

    MfG - Bob (Bitte auf Deutsch weiterhin.)

Reply
  • So, "the first one" is 1euaWA-00071A-21.  I interpret "ctasd reports 'Confirmed' RefID:str=0001.0A0B0203.5AA3A0FA.00E8..." as confirming Steve's suggestion that the problem is an issue with ctasd or CommTouch.

    I would open a ticket with Sophos so that they know there's an issue.

    MfG - Bob (Bitte auf Deutsch weiterhin.)

Children
No Data