Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

vserver.site customers - do you have email delivery issues?

brueggusbrueggus Member, IPv6 Advocate

I logged into my @vserversite account a while ago and noticed an unpaid invoice which I haven't been notified about. Digging further, I seems like their WHMCS instance has generated several emails which I never received. This seems to be going on for several months.

Their support has checked and it looks like the emails have been sent properly. I have checked my SMTP logs but couldn't find any attempts from their side to deliver any email.

If you are a customer of theirs, could you check if you have received emails from them in Oct/Nov/Dec?

Comments

  • JabJabJabJab Member
    edited January 2025

    as always gonna tag the guy that loves smtp logs @jar and maybe he has something :-D

    Won't tag the new kids on the block (new in SMTP world) as they too new to have some sample size data :-D

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    They did send them, but they scored 28 with SpamAssassin. The main culprit being this rule:

    header MESSAGE_ID_SPAM_TLD Message-ID =~ /\.(online|shop|top|world|site|today|buzz|best|click|link|cloud)>?$/i
    score MESSAGE_ID_SPAM_TLD 25.0
    describe MESSAGE_ID_SPAM_TLD Email from popular spam TLD
    

    This rule was designed to combat spammers that were sending from new/cheap TLDs but using a transactional service to mask the envelope sender. It's quite an effective rule and this is the first false positive I'm aware of. After a quick audit, I've pulled the ".site" TLD from the rule. The change may take up to 1 hour to deploy.

    Thanked by 2Decicus brueggus
  • My own domain is .online. And it is expensive. Do spammers still use it for malice?

  • I was able to receive all their emails to my Outlook.com in November

    Thanked by 1brueggus
  • brueggusbrueggus Member, IPv6 Advocate

    @jar said: They did send them, but they scored 28 with SpamAssassin. The main culprit being this rule:

    Thanks for looking into this! I guess I should have opened a ticket instead of this thread. But since I couldn't find any traces of their emails in Direct Admin under "Email tracking", I didn't expect them to reach your servers at all.
    Even if their mails get such a high score, shouldn't I still see them in the logs?

    And I have set SpamAssassin to non-blocking mode, so I would expect them to end up in my Junk folder.

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    @brueggus said:

    @jar said: They did send them, but they scored 28 with SpamAssassin. The main culprit being this rule:

    Thanks for looking into this! I guess I should have opened a ticket instead of this thread. But since I couldn't find any traces of their emails in Direct Admin under "Email tracking", I didn't expect them to reach your servers at all.
    Even if their mails get such a high score, shouldn't I still see them in the logs?

    And I have set SpamAssassin to non-blocking mode, so I would expect them to end up in my Junk folder.

    DirectAdmin's EasySpamFighter still has an overriding high score rejection variable, and with everything combined it met that. I try to keep that to a fair value but I always reference that there is no high end (highly utilized, large customer base, etc) mail service that allows customers to completely receive 100% of what is sent to them. Since it's about protecting the servers from a larger number of issues than just one user's inbox. Stuff you know but I'm just putting it out there for general knowledge.

    Expanding on that if interested: Allowing users to completely override all filtering creates a scenario more frequently that I had to deal with just today, but because of the way I run things I only have to deal with it when someone created the problem elsewhere and then brought it into MXroute with them. Today I had to tell someone that I couldn't provide inbound service for 2 of their domains that collectively consumed over 100GB of memory and fork bombed the server by their catchalls that had been so used to being able to receive anything sent to them that it seemed as though the entirety of the internet wanted to effectively DDOS their MX 24/7. It caused inbound delivery delays for an entire server twice today and thankfully I won't likely see it again for another decade. But I'll make sure that I don't allow the situation to be born on our servers.

    @Levi said:
    My own domain is .online. And it is expensive. Do spammers still use it for malice?

    Afraid so, but it's getting better. We only clocked about 1400 known spam from .online domains in the last ~72h.

    Thanked by 3brueggus Decicus tototo
  • @Levi said:
    My own domain is .online. And it is expensive. Do spammers still use it for malice?

    Registration price of .online is usually cheap, so they often use it because domains are disposable not need to renew.

Sign In or Register to comment.