kiwix / operations

Kiwix Kubernetes Cluster
http://charts.k8s.kiwix.org/
5 stars 0 forks source link

GANDI SMTP Issue #206

Open rgaudin opened 1 week ago

rgaudin commented 1 week ago

@RavanJAltaie is unable to send messages using her @kiwix.org address because our GANDI SMTP server refuses her requests due to her current IP address.

IP address is listed in an XBL list and reportedly attempted to send malware 2 days ago.

ISP is a small Iraqi one so it probably rotates its customers IP addresses. Yet it is still possible that @RavanJAltaie's computer is infected and the source of the issue…

There is an Anti-spam protection feature in GANDI email. It's a toggle for the whole domain. I tried to turn it off and have @RavanJAltaie send an email to see if it would go through. It did not. As suspected, this is an incoming email filter.

I believe we should raise this to GANDI since it is blocking an authenticated user on its own SMTP server… WDYT? In the mean time, possible solutions:

@Popolechien @benoit74 @kelson42


Your message did not reach some or all of the intended recipients.
     Subject:    Test
     Sent: 6/21/2024 7:02 PM
The following recipient(s) cannot be reached:
     '[reg@kiwix.org](mailto:reg@kiwix.org)' on 6/21/2024 7:02 PM
           Server error: '554 5.7.1 Service unavailable; Client host [212.237.123.29] blocked using [xbl.spamhaus.org](http://xbl.spamhaus.org/); Listed by XBL, see https://check.spamhaus.org/query/ip/212.237.123.29'

She couldn't find a way to get the raw message details

Popolechien commented 1 week ago

We can and should flag it to Gandi, but this hardly looks like a false positive so should consider a plan B already in case they ignore us (not sure they can white list/unblacklist a specific IP).

rgaudin commented 6 days ago

The most recent detection was on: June 19 2024, 12:50:00 UTC (+/- 5 minutes).

This could indicate that @RavanJAltaie's computer is not infected and is just reusing an IP that has been flagged. @RavanJAltaie short term solution is probably to use a VPN, as advised by @kelson42