1
how to find out why IP is blocked
Question asked by Russ Michaels - 1/28/2015 at 9:32 AM
Unanswered
I have a client whose IP address keeps getting blocked, I have gone through the pop, imap and smtp logs and I cannot find any clue or mention of the reason.
In the logs I can see all the users connections, then being immediately disconnected, which I presume is when they are blocked. 
But how and where do you find out why they got blocked in the first place ?
 

5 Replies

Reply to Thread
0
Employee Replied
Employee Post
Hi Russ.  One common cause of an IP address being blocked is a compromised account being used to relay spam through your mail server.  This KB Article will explain how to find a possible compromised account.
0
Webio Replied
IMHO you should vote for this topic:
 
http://portal.smartertools.com/community/a902/abuse-detection-blocks-history.aspx
 
Too bad that no one from ST didn't responded there. In my opinion this is badly needed logging and troubleshooting function.
0
Russ Michaels Replied
spam issues we can usually identify, we also have the scheduled reports to help with that. But the issue seems to be with abuse detection which is not logged at all, so there is no way at all to tell what caused it. The last one for example was caused by too many successive connections in 5 minutes as client had 68 users all connecting every couple of minutes. But there was no way at all to tell this, not a single thing in the logs. All we had was the blocked IP in the block list, but no explanation why.
0
Russ Michaels Replied
dang it appears this stupid forum stops you copying text too, so I cannot even copy that link
0
Employee Replied
Employee Post
Russ, what browser are you in? I have no problem copying the link from Chrome, Firefox or Safari.

Reply to Thread