cancel
Showing results for 
Search instead for 
Did you mean: 

UK2Net - Emails Forward From - Again

JamesG
Newbie
Posts: 4
Registered: ‎04-09-2008

UK2Net - Emails Forward From - Again

Last summer's problems are back again.
Sometimes emails from a Yahoo discussion group, sent to me via a UK2Net registered domain arrive, and sometimes they don't.
Last summer I introduced all the possible filters imaginable, especially limiting the number of allowable email names in front of my domain name.  Since then I've not received a single spam email.
What annoys me is that all the earlier spams I received resulted from the "leaking" of my unused Plusnet email address, rather than via my UK2Net domain name.  I.e. UK2Net Angry had absolutely nothing to do with the  "volume of emails received by Plusnet fromUK2net"
Surely it must be possible to filter inbound emails from UH2Net according to their plusnet user recipent, and allow through those which are addressed to users who've taken the trouble to restrict the number of acceptable inbound email addresses. 
How does Plusnet's parent, BT handle the problem of emails forwarded by UK2Net????
4 REPLIES 4
bobpullen
Community Gaffer
Community Gaffer
Posts: 16,887
Thanks: 4,979
Fixes: 316
Registered: ‎04-04-2007

Re: UK2Net - Emails Forward From - Again

Have you seen the Service Status post here?
We're hoping to have this fixed today but to put a bit of context into the situation...
Here's a snapshot from one of our IronPort mail servers that was taken yesterday -
IP Address Hostname Total Attempted Stopped by Reputation Filtering Stopped as Invalid Recipients Spam Detected Virus Detected Stopped by Content Filter Total Threat Clean arrow
83.170.81.182 smtp2.uk2.net 4,545 3,155 8 935 0 0 4,098 447

What this shows is that 3155 emails out of the 4545 send to the server from uk2.net were rejected. Of the 1390 that got through, 935 were identified as spam before being delivered to our customers. Because uk2net are consistently sending more than 50% spam at our IronPorts, their reputation is getting pushed down to the level where the IronPorts start outright refusing to accept messages from them. As soon as their reputation level gets better, mail starts getting accepted but it's not long before the same things happens again.
Given the fact that the overall volume of mail from uk2.net is relatively low then we're probably going to end up having to add an exception to our system to blindly accept email from uk2.net's forwarding servers. This isn't an ideal solution at all but it's better than continuing to inconvenience our customers. It's worth noting that it might also reduce the effectiveness of our spam filtering for anybody who is using uk2.net to forward emails like this.
I've suggested on numerous occasions that uk2.net investigate this at their side as we're not the only large ISP to use IronPort for spam filtering (and exactly the same thing happened with Postini). Unfortunately they don't seem to be interested in pursuing this.

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

bobpullen
Community Gaffer
Community Gaffer
Posts: 16,887
Thanks: 4,979
Fixes: 316
Registered: ‎04-04-2007

Re: UK2Net - Emails Forward From - Again

This should now be sorted so please let me know if you continue to have difficulties.
Whilst we will now accept all email from uk2.net, a quick glance at the logs suggests that a lot of this is going to get marked as spam. If you have Edge Protection switched on then the email may also get silently dropped as spam without a rejection message. To avoid this happening you may need to switch Edge Protection off using the 'Spam' tab of the Manage My Mail controls in the Member Centre.
Failing that, you could always turn spam filtering off entirely but that will result in everything getting through to you, none of which will be marked as spam.
Final option is to transfer your domain to Plusnet for hosting so the messages are sent directly to the IronPorts without having to go via uk2.net first.
Wed Dec 10 14:13:35 2008 Info: New SMTP ICID 78734693 interface Data 1 (212.159.7.97) address 83.170.81.181 reverse dns host smtp1.uk2.net verified yes
Wed Dec 10 14:13:35 2008 Info: ICID 78734693 ACCEPT SG WHITELIST match smtp1.uk2.net SBRS 2.9
Wed Dec 10 14:13:35 2008 Info: Start MID 4824554 ICID 78734693
Wed Dec 10 14:13:35 2008 Info: MID 4824554 ICID 78734693 From: <me@privacy.net>
Wed Dec 10 14:13:35 2008 Info: MID 4824554 ICID 78734693 RID 0 To: <me@privacy.net>
Wed Dec 10 14:13:35 2008 Info: MID 4824554 using engine: SPF Verdict Cache using cached verdict
Wed Dec 10 14:13:35 2008 Info: MID 4824554 SPF: helo identity postmaster@smtp1.uk2.net None
Wed Dec 10 14:13:35 2008 Info: MID 4824554 SPF: mailfrom identity me@privacy.net None
Wed Dec 10 14:13:35 2008 Info: MID 4824554 SPF: pra identity me@privacy.net None headers from
Wed Dec 10 14:13:35 2008 Info: MID 4824554 Subject 'Delivery Status Notification'
Wed Dec 10 14:13:35 2008 Info: MID 4824554 ready 2124 bytes from <me@privacy.net>
Wed Dec 10 14:13:35 2008 Info: ICID 78734693 close
Wed Dec 10 14:13:36 2008 Info: MID 4824554 matched all recipients for per-recipient policy BSB_Level1 in the inbound table
Wed Dec 10 14:13:36 2008 Info: MID 4824554 interim verdict using engine: CASE spam positive
Wed Dec 10 14:13:36 2008 Info: MID 4824554 using engine: CASE spam positive
Wed Dec 10 14:13:36 2008 Info: Message aborted MID 4824554 Dropped by CASE
Wed Dec 10 14:13:36 2008 Info: Message finished MID 4824554 done

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

JamesG
Newbie
Posts: 4
Registered: ‎04-09-2008

Re: UK2Net - Emails Forward From - Again

Thanks Bob for changing the Plusnet settings about accepting inbound emails from UK2Net.  The expected emails are now arriving.  I've also disabled edge protection as recommended, though the technical ramifications of this are above me.
It would be good if you could alert me (not sure if you've got my email) and other users to any future changes in the IronPort settings for inbound UK2Net emails, as I suspect you'd have to look at the settings again if there was a sudden increase in the volumes of emails being forwarded from UK2Net.
Thanks again,
James
pd
Grafter
Posts: 235
Registered: ‎09-05-2008

Re: UK2Net - Emails Forward From - Again

I have a feeling that uk2 got hacked last year, although they flatly deny it.  I had a uk2 email address which was never made public and which you would never guess as it consisted of random characters.  I used to forward mail to it from several domains and just pick up from uk2 and then suddenly it started getting 3-400 spams a day.  I just moved on, and have since moved three domains which were hosted on uk2 for the same reason.
pd