SMTP.AA.NET.UK - blocking of senders on Spamhaus block lists
MINOR Open Email
STATUS
Open
CREATED
Feb 04, 12:36 PM (6 days ago)
AFFECTING
Email
STARTED
Feb 03, 09:00 AM (7¼ days ago)
REFERENCE
42744 / AA42744
MASTODON
INFORMATION
  • INITIAL
    7¼ days ago by Andrew

    Over the past week we have seen a huge number of 'bots' trying to guess customer email credentials in order to try to send email through our outbound email servers: smtp.aa.net.uk.

    The attempts were being blocked due to wrong passwords being used, but this caused significant load on our severs due to all the database lookups involved. To address this, we are blocking IP addresses that are listed on the Spamhaus 'Exploits Blocklist (XBL)' and the Spamhaus 'Combined Spam Sources (CSS)' lists. -These are typically IP address known to have hijacked in some way or known spam senders.

    This has reduced the load on the email servers significantly, however we are are still blocking around 1.5 million unique IP addresses each day.

    We have had a small number of legitimate customers affected by this as their IP address is on these blocklists. (IPs can be looked up on https://check.spamhaus.org). In these cases, please do contact support and we can discuss workarounds.

  • UPDATE
    4¾ days ago by Andrew

    We have had a few customers who are using other ISPs and who are behind 'CGNAT' - this is where the IP address that is used to access the internet is shared with a number of other customers of that ISP. As the IP address is shared with others the listing of it in the Spamhaus lists could be due to the actions of any other customer of the ISP who also uses the shared IP address. In these cases, we'd suggest the following:

    • Ask your ISP about it -refer them to this web page
    • The ISP could go through the spamhaus procedure to de-list the IP - if they have investigated the cause of the initial listing (details are on the https://check.spamhaus.org page.
    • Use your ISPs mail server for sending email instead of ourd (if they allow this)
    • If you're still stuck, do let us know, and we can investigate other avenues.

  • NEXT UPDATE...

    Due in 21 hours