mail-in-a-box / mailinabox

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server in a box.
https://mailinabox.email/
Creative Commons Zero v1.0 Universal
14.07k stars 1.44k forks source link

Blacklists too strict #1638

Closed myfirstnameispaul closed 4 years ago

myfirstnameispaul commented 5 years ago

In signing up for the Dovecot mailing list, MiaB reports the following in the logs:

Sep  4 21:20:47 mail postfix/smtpd[21322]: NOQUEUE: reject: RCPT from talvi.dovecot.org[2a04:3542:1000:910:acc1:5bff:fe5e:125c]: 554 5.7.1 Service unavailable; Client host [2a04:3542:1000:910:acc1:5bff:fe5e:125c] blocked using zen.spamhaus.org; https://www.spamhaus.org/sbl/query/SBLCSS; from=<dovecot-bounces@dovecot.org> to=<miabuser@example.com> proto=ESMTP helo=<talvi.dovecot.org>

I emailed the list maintainer and he responded that they have not been able to keep off of the Spamhaus blacklists, despite the fact that there is no spam coming from their server.

I can appreciate how difficult it must be to come up with a configuration that works for everybody, but is it possible you might reconsider the rejection policy with regards to blacklists? IIRC, MiaB doesn't respect DMARC p=reject policies created by site admins, but you follow blacklists, which admins have zero control over.

jvolkenant commented 5 years ago

The issue is with spamhaus and not with MIAB. You can try to rbl whitelist this sender. But your changes will be overwritten when you run miab install.

myfirstnameispaul commented 5 years ago

So, Spamhaus is configuring MiaB?

JoshData commented 5 years ago

Lol ok. Chill please.

myfirstnameispaul commented 5 years ago

I didn't intend to express anything other than this doesn't seem to me to be an "it's the other project's fault" type of an issue.

pierreozoux commented 5 years ago

@myfirstnameispaul as @jvolkenant said, you have to contact spamhaus. This project can't do anything to help you.

COuld you please close the issue? thanks!

myfirstnameispaul commented 5 years ago

@pierreozoux There is no option to send to spam instead of blocking?

ctrl-i commented 5 years ago

@pierreozoux There is no option to send to spam instead of blocking?

As has already been recommended to you, you need to contact Spamhaus. This is not something MIAB can do for you. MIAB uses the Spamhaus lists to filter spam and MIAB has no way to edit the lists Spamhaus controls.

gellenburg commented 4 years ago

I'm having the same issue. I have several MIAB instances running at Linode. They are all in the New Jersey datacenter.

The MIAB instance I use for my personal Email and domain is not receiving mail sent from my own MIAB instance that I use for business email (and my business domain).

My personal MIAB instance is blocking email from my own domain due to zen.spamhaus.org. Which means, other email that is sent from my business domain is being blocked by other MIAB users and anyone else that uses zen.spamhaus.org. Fortunately the vast majority of my business correspondents are on Office 365 or use ProofPoint and neither of them have blocked my email.

Here's the rub. I know I have never sent any UCE from my business domain. Ever.

I have now gone through the process of getting my business MIAB removed from zen.spamhaus.org nine (yes 9) separate times, and it stays removed for a week or so.

This is getting old.

We really need a configurable option to decide which blacklists we want to support. I'm almost to the point of forking MIAB just so I can remove any and all references to zen.spamhaus.org from all code and configurations.

Spamhaus is an utter and complete joke.

Yes, I know some may think the solution is to change IPs but that's only putting a bandaid on the problem. The solution is to not use zen.spamhaus.org. Full stop.

jvolkenant commented 4 years ago

The problem you will find however, is not that you have stopped checking for inbound mail with zen.spamhaus.org. It will be that the people you are emailing might be using zen.spamhaus.org.

gellenburg commented 4 years ago

Yep. Finding that out. Only recourse seems to be to convince folks to migrate off Miab since there's no other option.

Which sucks because I really hate iredmail. 😔

Get Outlook for Androidhttps://aka.ms/ghei36


From: jvolkenant notifications@github.com Sent: Friday, September 11, 2020 5:19:31 PM To: mail-in-a-box/mailinabox mailinabox@noreply.github.com Cc: George Ellenburg george@ellenburg.net; Comment comment@noreply.github.com Subject: Re: [mail-in-a-box/mailinabox] Blacklists too strict (#1638)

The problem you will find however, is not that you have stopped checking for inbound mail with zen.spamhaus.org. It will be that the people you are emailing might be using zen.spamhaus.org.

— You are receiving this because you commented. Reply to this email directly, view it on GitHubhttps://github.com/mail-in-a-box/mailinabox/issues/1638#issuecomment-691316633, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ABVTQPXGGSABI5TMUQ4RHITSFKH6HANCNFSM4IT7JG3Q.

jvolkenant commented 4 years ago

If you are listed on any blacklist; that is not the fault of Mail in a box (or any other email server) I have bought VPS before that had IP's that were listed on blacklists that I could not get removed. I had to settle with changing IP's.

gellenburg commented 4 years ago

I'm not on any blacklist the problem is zen. I had a mail server that was in zen that I got removed then as a test I shut that box down I powered it off completely disabled the virtual machine then miraculously one week later Zen relisted that box again back in their blacklist The problem is zen.spamhaus.org and since mailing a box refuses to provide any sort of configurable option for disabling zen.spamhaus.org my only recourse was to migrate off of mail in a box which is what I'm doing as fast as I possibly can and educating others why they shouldn't be using mail in a box either I love mail in a box but the DNS block lists are hard coated and of course I can edit the post fixed main.cf file easy enough but the problem there is the next time I go to upgrade mail in a box that config file is going to get overwritten. I thought about forking mail in a box and creating my own project that didn't have zen.spamhaus.org but I don't have the time to keep something like that maintained. Am I frustrated Yes am I bitter a little bit because here's an organization that and it's only zen.spamhaus by the way that is causing me so much grief and frustration. apologies for the lack of formatting I'm on my phone and I'm using Google transcription.

Get Outlook for Androidhttps://aka.ms/ghei36


From: jvolkenant notifications@github.com Sent: Friday, September 11, 2020 8:36:43 PM To: mail-in-a-box/mailinabox mailinabox@noreply.github.com Cc: George Ellenburg george@ellenburg.net; Comment comment@noreply.github.com Subject: Re: [mail-in-a-box/mailinabox] Blacklists too strict (#1638)

If you are listed on any blacklist; that is not the fault of Mail in a box (or any other email server) I have bought VPS before that had IP's that were listed on blacklists that I could not get removed. I had to settle with changing IP's.

— You are receiving this because you commented. Reply to this email directly, view it on GitHubhttps://github.com/mail-in-a-box/mailinabox/issues/1638#issuecomment-691365887, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ABVTQPXTNMD6SZVEXGDDSADSFK7BXANCNFSM4IT7JG3Q.

nomandera commented 4 years ago

Would you consider posting a redacted copy of your conversations with spamhaus as it seems you have identified a bug they are not addressing.

gellenburg commented 4 years ago

There is no way to contact spamhaus except through their website and filling out an automated form to get a server removed from the Zen block list.

Get Outlook for Androidhttps://aka.ms/ghei36


From: anoma notifications@github.com Sent: Monday, September 14, 2020 4:39:40 AM To: mail-in-a-box/mailinabox mailinabox@noreply.github.com Cc: George Ellenburg george@ellenburg.net; Comment comment@noreply.github.com Subject: Re: [mail-in-a-box/mailinabox] Blacklists too strict (#1638)

Would you consider posting a redacted copy of your conversations with spamhaus as it seems you have identified a bug they are not addressing.

— You are receiving this because you commented. Reply to this email directly, view it on GitHubhttps://github.com/mail-in-a-box/mailinabox/issues/1638#issuecomment-691910000, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ABVTQPWAYOLJ6JSNB57V3P3SFXJEZANCNFSM4IT7JG3Q.

nomandera commented 4 years ago

I have never had occasion to contact them but they seem to have a github presence at least. https://github.com/spamhaus

From reviewing the comments so far it would indeed seem they have a possible bug but without knowing IPs and domain names etc you will have to self verify that.

gellenburg commented 4 years ago

M i a b is blocking other email from other m i a b users because of Zen but more importantly the fact that male administrators can't control or don't have granular control over the spam policies that are applied to their installation is a design flaw of m i a b in my opinion.

Get Outlook for Androidhttps://aka.ms/ghei36


From: anoma notifications@github.com Sent: Monday, September 14, 2020 10:25:43 AM To: mail-in-a-box/mailinabox mailinabox@noreply.github.com Cc: George Ellenburg george@ellenburg.net; Comment comment@noreply.github.com Subject: Re: [mail-in-a-box/mailinabox] Blacklists too strict (#1638)

I have never had occasion to contact them but they seem to have a github presence at least. https://github.com/spamhaus

From reviewing the comments so far it would indeed seem they have a possible bug but without knowing IPs and domain names etc you will have to self verify that.

— You are receiving this because you commented. Reply to this email directly, view it on GitHubhttps://github.com/mail-in-a-box/mailinabox/issues/1638#issuecomment-692089721, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ABVTQPX6EG4CH74W6BI52VLSFYRWPANCNFSM4IT7JG3Q.

myfirstnameispaul commented 4 years ago

I am currently unable to receive an email sent to my MiaB installation because the sender uses a provider that is on a blacklist.

I would strongly prefer such an email go to my spam folder instead of being blocked by the server.

There is nothing to inform the sender of the problem, other than when I call them on the telephone.

myfirstnameispaul commented 4 years ago

Missed an important email from Citibank because their sending service was in the Spamhaus DBL.

I do not find this to be a useful feature.

nomandera commented 4 years ago

It was remiss of Citibank not to act on this before you even knew about it.

RBLs are an imperfect but vital technology. For the handful of problem edge case we can report here millions, perhaps billions, of true spam mail is blocked to MIAB users because of it every year.

gellenburg commented 4 years ago

Not allowing a mail administrator granular control over the anti UCE policies applied to their organization's email is also remissive.

But we can't control citibank's policies.

Please allow us to control our's.

Get Outlook for Androidhttps://aka.ms/ghei36


From: anoma notifications@github.com Sent: Sunday, October 25, 2020 5:14:10 AM To: mail-in-a-box/mailinabox mailinabox@noreply.github.com Cc: George Ellenburg george@ellenburg.net; Comment comment@noreply.github.com Subject: Re: [mail-in-a-box/mailinabox] Blacklists too strict (#1638)

It was remiss of Citibank not to act on this before you even knew about it.

RBLs are an imperfect but vital technology. For the handful of problem edge case we can report here millions, perhaps billions, of true spam mail is blocked to MIAB users because of it every year.

— You are receiving this because you commented. Reply to this email directly, view it on GitHubhttps://github.com/mail-in-a-box/mailinabox/issues/1638#issuecomment-716116602, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ABVTQPTKFZ4N3GZ2E7ZVDCLSMPT6FANCNFSM4IT7JG3Q.

JoshData commented 4 years ago

I'm really getting tired of this thread. If you don't like things as they are you have SO MANY options:

gellenburg commented 4 years ago

And if Mail In A Box didn’t overwrite my custom Postfix main.cf and other settings there wouldn’t be a problem, but every time MAIB is updated it wirtes out a new main.cf overwriting any customizations a user may have implemented.

That’s the crux of the problem. 😊

JoshData commented 4 years ago

I'm closing and locking this issue. If there are constructive proposals for improvements to Mail-in-a-Box, please go ahead and open a new issue for the proposal. I appreciate the feedback but I don't think any further discussion is going to add any new information here. Blocklists are sometimes going to block too much and I empathize when something important gets lost, but this is how Mail-in-a-Box works until someone comes up with something better.