Hello,
We have a client using a security service (Zix) due to their working in the financial market. We’ve whitelisted the servers that are filtering their emails (in-bound and outbound) and this is clearly shown below in the SMTP logs BUT in the Delivery Logs we are seeing their emails blocked due to a high spam ranking.
How can the whitelists be ignored?
I also added the IP addresses to the Declude whitelist to make sure it was not happening prior to hitting SmarterMail.
SMTP Logs
[2022.09.27] 13:29:29.596 [8.31.233.164][61124116] rsp: 220 mail.sgdesign.net Tue, 27 Sep 2022 20:29:29 +0000 UTC | SmarterMail Enterprise 16.3.0 [2022.09.27] 13:29:29.596 [8.31.233.164][61124116] connected at 9/27/2022 1:29:29 PM
[2022.09.27] 13:29:29.596 [8.31.233.164][61124116] Country code: Unknown
[2022.09.27] 13:29:29.596 [8.31.233.164][61124116] IP in whitelist
[2022.09.27] 13:29:29.627 [8.31.233.164][61124116] rsp: 250 mail.sgdesign.net Hello [8.31.233.164] [2022.09.27] 13:29:29.643 [8.31.233.164][61124116] Sender accepted. Weight: 0. Block threshold: 30.
[2022.09.27] 13:29:29.690 [8.31.233.164][61124116] cmd: DATA
[2022.09.27] 13:29:29.690 [8.31.233.164][61124116] Performing PTR host name lookup for 8.31.233.164
[2022.09.27] 13:29:29.690 [8.31.233.164][61124116] rsp: 354 Start mail input; end with <CRLF>.<CRLF>
[2022.09.27] 13:29:29.971 [8.31.233.164][61124116] rsp: 250 OK
[2022.09.27] 13:29:29.987 [8.31.233.164][61124116] Received message size: 55476 bytes
[2022.09.27] 13:29:29.987 [8.31.233.164][61124116] Successfully wrote to the HDR file. (c:\SmarterMail\Spool\proc\51025202.hdr)
[2022.09.27] 13:29:29.987 [8.31.233.164][61124116] cmd: RSET
[2022.09.27] 13:29:29.987 [8.31.233.164][61124116] rsp: 250 OK
[2022.09.27] 13:29:30.003 [8.31.233.164][61124116] Sender accepted. Weight: 0. Block threshold: 30.
[2022.09.27] 13:29:30.049 [8.31.233.164][61124116] cmd: DATA
[2022.09.27] 13:29:30.049 [8.31.233.164][61124116] Performing PTR host name lookup for 8.31.233.164
[2022.09.27] 13:29:30.049 [8.31.233.164][61124116] rsp: 354 Start mail input; end with <CRLF>.<CRLF>
[2022.09.27] 13:29:30.331 [8.31.233.164][61124116] rsp: 250 OK
[2022.09.27] 13:29:30.346 [8.31.233.164][61124116] Received message size: 55488 bytes
[2022.09.27] 13:29:30.346 [8.31.233.164][61124116] Successfully wrote to the HDR file. (c:\SmarterMail\Spool\proc\51025203.hdr)
[2022.09.27] 13:29:30.346 [8.31.233.164][61124116] Data transfer succeeded, writing mail to 51025203.eml
[2022.09.27] 13:29:30.346 [8.31.233.164][61124116] cmd: QUIT
[2022.09.27] 13:29:30.346 [8.31.233.164][61124116] rsp: 221 Service closing transmission channel
[2022.09.27] 13:29:30.346 [8.31.233.164][61124116] disconnected at 9/27/2022 1:29:30 PM
[2022.09.27] 13:29:39.925 [51025202] Added to SpamCheckQueue (1 queued; 4/30 processing)
[2022.09.27] 13:29:39.925 [51025202] [SpamCheckQueue] Begin Processing.
[2022.09.27] 13:29:39.925 [51025202] Blocked Sender Checks started.
[2022.09.27] 13:29:39.925 [51025202] Blocked Sender Checks completed.
[2022.09.27] 13:29:39.925 [51025202] Windows Defender Checks error: Unknown error (0x800106ba)
[2022.09.27] 13:29:39.925 [51025202] Spam Checks started.
[2022.09.27] 13:33:23.474 [51025202] Spam Check results: [REVERSE DNS LOOKUP: 0,Passed], [_SPF: 30,Fail], [BACKSCATTER: 0,passed], [BARRACUDA - BRBL: 0,passed], [BONDEDSENDER: 0,passed], [CBL - ABUSE SEAT - DO NOT USE FOR OUTGOING: 0,passed], [DNSBL: 0,passed], [GBUDB: 0,passed], [HOSTKARMA-BLACK: 0,passed], [HOSTKARMA-YELLOW: 0,passed], [IADB: 0,passed], [IX: 0,passed], [MAILSPIKE-H1: 0,passed], [MAILSPIKE-H2: 0,passed], [MAILSPIKE-H3: 0,passed], [MAILSPIKE-H4: 0,passed], [MAILSPIKE-H5: 0,passed], [MAILSPIKE-L1: 0,passed], [MAILSPIKE-L2: 0,passed], [MAILSPIKE-L3: 0,passed], [MAILSPIKE-L4: 0,passed], [MAILSPIKE-L5: 0,passed], [MCAFEE: 0,passed], [MSRBL: 0,passed], [NOABUSE: 0,passed], [NOPOSTMASTER: 0,passed], [SEM-BL: 0,passed], [SEM-URIBL: 0,passed], [SEM-URIRED: 0,passed], [SENDERSCORE: 0,passed], [SORBS 02 - HTTP: 0,passed], [SORBS 03 - SOCKS: 0,passed], [SORBS 04 - MISC: 0,passed], [SORBS 05 - SMTP: 0,passed], [SORBS 06 - RECENT: 0,passed], [SORBS 07 - WEB: 0,passed], [SORBS 08 - BLOCK: 0,passed], [SORBS 09 - ZOMBIE: 0,passed], [SORBS 10 - DYNAMIC IP: 0,passed], [SORBS 11 - BAD CONFIG: 0,passed], [SORBS 12 - NOMAIL: 0,passed], [SORBS 13 - NOSERVER: 0,passed], [SORBS-NEW: 0,passed], [SPAMCOP: 0,passed], [SPAMHAUS - PBL 1: 0,passed], [SPAMHAUS - PBL2: 0,passed], [SPAMHAUS - SBL 1: 0,passed], [SPAMHAUS - SBL 2: 0,passed], [SPAMHAUS - XBL 1: 0,passed], [SPAMHAUS - XBL 2: 0,passed], [SPAMHAUS - XBL 3: 0,passed], [SPAMHAUS - XBL 4: 0,passed], [SPAMHAUS - ZEN: 10,failed], [SPAMRATS: 0,passed], [SURBL: 0,passed], [SURRIEL: 0,passed], [UCEPROTECT LEVEL 1: 0,passed], [UCEPROTECT-2: 0,passed], [UCEPROTECT-3: 0,passed], [URIBL - BLACK: 0,passed], [URIBL - GREY: 0,passed], [URIBL - RED: 0,passed], [URIBL - WHITE: 1 results -2,failed], [VIRUS RBL - MSRBL: 0,passed], [SPAMEATINGMONKEY: 0,passed]
[2022.09.27] 13:33:23.474 [51025202] Spam Checks completed.
[2022.09.27] 13:33:23.474 [51025202] Removed from SpamCheckQueue (9 queued or processing)
[2022.09.27] 13:33:24.943 [51025202] Added to LocalDeliveryQueue (1 queued; 1/50 processing)
[2022.09.27] 13:33:24.943 [51025202] [LocalDeliveryQueue] Begin Processing.
[2022.09.27] 13:33:24.943 [51025202] Removed from LocalDeliveryQueue (0 queued or processing)
[2022.09.27] 13:33:54.945 [51025202] Added to RemoteDeliveryQueue (1 queued; 1/50 processing)
[2022.09.27] 13:33:54.945 [51025202] [RemoteDeliveryQueue] Begin Processing.
[2022.09.27] 13:33:54.976 [51025202] Failed to connect to the recipient's mail server. No MX records were found for the 'encryptsh201.appriver.com' domain. Failing over to A records. [2022.09.27] 13:33:54.976 [51025202] MxRecord count: '1' for domain ''
[2022.09.27] 13:33:54.976 [51025202] Attempting MxRecord Host Name: 'encryptsh201.appriver.com', preference '1', Ip Count: '1' [2022.09.27] 13:33:54.976 [51025202] Initiating connection to 8.31.233.186
[2022.09.27] 13:33:54.976 [51025202] Connecting to 8.31.233.186:25 (Id: 1)
[2022.09.27] 13:33:54.976 [51025202] Binding to local IP 192.168.100.97 (Id: 1)
[2022.09.27] 13:33:54.992 [51025202] Connection to 8.31.233.186:25 from 192.168.100.97:56861 succeeded (Id: 1)
[2022.09.27] 13:33:55.039 [51025202] RSP: 220 ***********************************************************************************
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-DSN
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-SIZE 104857600
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-STARTTLS
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-ETRN
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-XXXA
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-XXXB
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-XXXXXXXXXXXXC
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-XXXD
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-PIPELINING
[2022.09.27] 13:33:55.070 [51025202] RSP: 250-XXXXXXXE
[2022.09.27] 13:33:55.070 [51025202] RSP: 250 XXXF
[2022.09.27] 13:33:55.070 [51025202] CMD: STARTTLS
[2022.09.27] 13:33:55.101 [51025202] RSP: 220 please start a TLS connection
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-DSN
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-SIZE 104857600
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-ETRN
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-TURN
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-ATRN
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-NO-SOLICITING
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-HELP
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-PIPELINING
[2022.09.27] 13:33:55.242 [51025202] RSP: 250-SMTPUTF8
[2022.09.27] 13:33:55.242 [51025202] RSP: 250 EHLO
[2022.09.27] 13:33:55.242 [51025202] CMD: MAIL FROM:<karen.mcneill@ticortitle.com> RET=HDRS ENVID=cc93b316-821c-4fc4-ace2-901dc595452c SIZE=56318 [2022.09.27] 13:33:55.304 [51025202] CMD: DATA
[2022.09.27] 13:33:55.336 [51025202] RSP: 354 Enter mail, end with "." on a line by itself
[2022.09.27] 13:33:55.414 [51025202] RSP: 250 191142352 message accepted for delivery
[2022.09.27] 13:33:55.414 [51025202] CMD: QUIT
[2022.09.27] 13:33:55.445 [51025202] Attempt to ip, '8.31.233.186' success: 'True'
[2022.09.27] 13:33:55.445 [51025202] Removed from RemoteDeliveryQueue (1 queued or processing)
[2022.09.27] 13:33:57.945 [51025202] Removing Spool message: Killed: False, Failed: False, Finished: True