-1

I recently created a new VPS and installed an email server using Modoboa.

Everything seemed to be working and fine until I sent an email to an @icloud.com address. The iCloud user never got my email, but I got his. Due to this being so soon after installing my mail server (literally 20 minutes) I put it down to that and didn't think much of it.

Days later I got the following email from my mail daemon:


I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<EXAMPLE@icloud.com>: host mx01.mail.icloud.com[17.42.251.10] refused to
    talk to me: 550 5.7.0 Blocked - see
    https://support.proofpoint.com/dnsbl-lookup.cgi?ip=95.217.218.207
Reporting-MTA: dns; mail.eml.pm
X-Postfix-Queue-ID: C5CD042368
X-Postfix-Sender: rfc822; EXAMPLE@eml.pm
Arrival-Date: Mon, 15 Mar 2021 08:36:29 +0100 (CET)

Final-Recipient: rfc822; EXAMPLE@icloud.com
Original-Recipient: rfc822;EXAMPLE@icloud.com
Action: failed
Status: 4.7.0
Remote-MTA: dns; mx01.mail.icloud.com
Diagnostic-Code: smtp; 550 5.7.0 Blocked - see
    https://support.proofpoint.com/dnsbl-lookup.cgi?ip=95.217.218.207

I've sent an email to Proofpoint asking to be unblocked, but I'm not sure if that's how it works.

I've also opened a ticket with my VPS provider asking for a new IP address but they're yet to respond, and I doubt they'll do this for free.

My email is still received just fine by Yahoo! and Gmail (I just tested these two).

I added all mail server ports to be allowed through my firewall so I was sure this wasn't the issue, but just to be super sure I took down my whole firewall for testing and I still get this issue.

My server's IP (https://who.is/dns/mail.eml.pm to get it if you need it - IPV4 and IPV6) is said not to be blacklisted here: https://www.spamhaus.org/query/ip/95.217.218.207.

Does anyone know what's happening and how to fix it? I'm new to email servers, so I'm sorry I couldn't be more helpful in my explanation.

JacobSa
  • 3
  • 2
  • Sending mail from a VPS is a fools errand. You'll never have it working reliably due to the nature of VPS. Some email providers will even blacklist entire subnets from known VPS providers, as it's often not worth the headache to play whack-a-mole with them. You're better off configuring a relay and utilizing a service like Mailgun to handle delivery. – tilleyc Mar 20 '21 at 15:43
  • @tilleyc Can you link me a good tutorial to set this up? Thanks! – JacobSa Mar 21 '21 at 16:26
  • https://www.digitalocean.com/community/tutorials/how-to-set-up-a-mail-relay-with-postfix-and-mailgun-on-ubuntu-16-04 – tilleyc Mar 21 '21 at 16:58

1 Answers1

0

I've sent an email to Proofpoint asking to be unblocked, but I'm not sure if that's how it works.

Yes, your IP was probably on a blacklist from them, but it seems to be removed. You can do a lookup on many blacklists with tools like https://whatismyipaddress.com/blacklist-check - your IP seems to be blocked by dnsbl.spfbl.net aswell, so it would be good to get file a removal request with them aswell.

I've also opened a ticket with my VPS provider asking for a new IP address but they're yet to respond, and I doubt they'll do this for free.

This is not a good idea. Use one IP and stick to that. Your new IP could be blacklisted aswell, for example because a previous user did malicious stuff. And even if it is not blocked, you have to build up a good IP reputation to reach some email providers.

Make sure to set up a SPF and DKIM record for your domain, along with a eventual DMARC record. This will improve deliverability from your domain.

Thom
  • 71
  • 2
  • I managed to get it removed from their blacklist, Hetzner is yet to get back to me. I have configured DKIM and SPF. Thanks! – JacobSa Mar 21 '21 at 16:27
  • When using Hetzner, you might want to use a "floating IP" for sending mail to build up reputation, which you can easily move to a new VM without losing the good sender reputation. – Thom Mar 22 '21 at 21:28
  • I saw this and wondered what it was... I'll look into it. – JacobSa Mar 24 '21 at 21:25