Blacklisted By Local Policy
FIXED- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- :
- Re: Blacklisted By Local Policy
on
20-02-2026
1:50 PM
- last edited on
20-02-2026
3:39 PM
by
Baldrick1
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Good day,
I am hoping someone can help me. PlusNet host my domain and email. I raised the following case on Jan 23rd - 252647531. I am able receive email but unable to send any email. I tested with webmail, iphone, outlook on my personal computer and got the same error message.
<redacted>@r<redacted>.co.uk - sending report error (0x800CCC78). Cannot send the message. Verify the email address in your account properties. The server responded 550, <redacted@<redacted>.co.uk, sender rejected (blacklisted by local policy).
I've confirmed my email address is not blacklisted and that I do not have a virus on any of the devices I am testing with. I have been following up with PlusNet regularly and passed this information on to them. The case gets closed for reasons I do not fully understand and I get it reopened or new ones created -
252763612
252799748
252960043
The latest update I received today was the case was closed and to check for a virus on my pc, confirm I am not sending a large amount of emails in short period of time and change my password. I rechecked that I am not blacklisted, which came back clear, did the virus check again, and have changed my password recently.
Regards,
Andy
Personal information removed from a public forum (to an area that staff can see).
Fixed! Go to the fix.
Re: Blacklisted By Local Policy
20-02-2026 3:36 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Post released from the automatic Spam Filter.
Moderator and Customer
If this helped - select the Thumb
If it fixed it, help others - select 'This Fixed My Problem'
Re: Blacklisted By Local Policy
20-02-2026 4:45 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@plusnettony any chance you could assist here please ? , the OP doesnt seem to be getting anywhere with the normal channels
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
23-02-2026 2:02 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Blacklisted By Local Policy
23-02-2026 3:32 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@plusnettony wrote:
Should be sorted.
Any chance you could fix ours please? Or is this a different problem?
Reporting-MTA: dns; avasout-peh-001 [212.159.14.17]
Received-From-MTA: dns; smtpclient.apple [xxx.xxx.xx.xxx]
Arrival-Date: Mon, 23 Feb 2026 14:39:05 +0000
Final-recipient: rfc822; XXXXXXXXXXXX@live.co.uk
Diagnostic-Code: smtp; 550 5.7.1 Unfortunately, messages from [212.159.14.17] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3140). You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors. [Name=Protocol Filter Agent][AGT=PFA][MxId=11BCD72FD8B2C488] [DU2PEPF00028D00.eurprd03.prod.outlook.com 2026-02-23T14:39:05.964Z 08DE6B97F8B7232A]
Last-attempt-Date: Mon, 23 Feb 2026 14:39:05 +0000
“You will do foolish things, but do them with enthusiasm.” - Colette
Re: Blacklisted By Local Policy
23-02-2026 4:22 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Or is this a different problem?
Yes
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Blacklisted By Local Policy
28-02-2026 8:45 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thanks you @plusnettony I am now able to send email. Much appreciate your help in getting this resolved.
Re: Blacklisted By Local Policy
03-03-2026 10:44 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Hi @plusnettony
I've been blacklisted again -
Task <redacted>@r<redacted>.co.uk - Sending' reported error (0x800CCC78) : 'Cannot send the message. Verify the email address in your account properties. The server responded: 550 <redacted>@r<redacted>.co.uksender rejected (blacklisted by local policy)'
It looks like someone is spoofing my email domain. I sent an email to 'abuse@enixltd.com'; 'abuse@enmail.co', 'abuse@plus.net' on 24 Feb -
I am the registered owner of the domain <redacted>@r<redacted>.co.uk.
I am formally reporting a high-volume, coordinated spam campaign originating from your network (IP: 91.204.208.8 / mail.enmail.co) that is illegally spoofing my domain to distribute pharmaceutical "Pharmacy/ED" spam.
Between on Feb 24, 2026, your server attempted to send multiple waves of spam to Gmail, Hotmail, and Freenet.de using my domain name as the envelope sender. This activity is causing my domain being flagged on major provider blocklists (e.g., Microsoft S3140).
Evidence of Coordinated Attack Logs:
- Target: Hotmail/Microsoft
- Time: 01:09:38 UTC
- Header Signature:
Plaintext
Received: from mail.enmail.co ([91.204.208.8]) by smtp with ESMTP id ugvgvTrfwWlIOugvhvL0V5; Tue, 24 Feb 2026 01:09:38 +0000
Message-ID: <redacted>@r<redacted>.co.uk
From: Your Medication Shop <a@xyz.co.uk>
Subject: A new message is calling your name, rochetnath98
Diagnostic-Code: smtp; 550 5.7.1 Unfortunately, messages from [212.159.14.17] weren't sent. Block list (S3140).
- Target: Freenet.de
- Time: 01:45:07 UTC
- Header Signature:
Plaintext
Received: from mail.enmail.co ([91.204.208.8]) by smtp with ESMTP id uhTzvTzytWlIOuhU1vL6Uu; Tue, 24 Feb 2026 01:45:07 +0000
X-Clacks-Overhead: "GNU Terry Pratchett"
Message-ID: <redacted>@r<redacted>.co.uk
From: ED online Shop <redacted>@r<redacted>.co.uk
Subject: New message — don’t keep them waiting
Diagnostic-Code: smtp; 550 Spam message rejected
- Target: Gmail/Google
- Time: 03:07:54 UTC
- Header Signature:
Plaintext
Received: from mail.enmail.co ([91.204.208.8]) by smtp with ESMTP id uim6vUCmAWlIOuim7vLHfQ; Tue, 24 Feb 2026 03:07:54 +0000
Message-ID: <redacted>@r<redacted>.co.uk
From: Viagra Online Shop <redacted>@r<redacted>.co.uk
Subject: Viagra Online Shop...
Diagnostic-Code: smtp; 550-5.7.1 Gmail has detected that this message is likely suspicious
All messages share the same Message-ID domain and the "X-Clacks-Overhead" header, originating directly from your MTA: 91.204.208.8.
I request that you immediately identify the user/account responsible for this SMTP injection and terminate their access to prevent further abuse of my domain. Please provide a confirmation once this source has been mitigated.
I sent a follow up email to 'abuse@enixltd.com'; 'abuse@enmail.co', 'abuse@plus.net' on the 28 Feb -
I am the registered owner of the domain <redacted>@r<redacted>.co.uk. I am filing a second formal report regarding a high-volume, coordinated spam campaign originating from your network (IP: 91.204.208.8 / mail.enmail.co) that is spoofing my domain.
Despite my initial report on February 24th, this activity has continued and evolved. The campaign has shifted from "Pharmacy" content to "Dating" spam, but the technical signature—including the X-Clacks-Overhead: "GNU Terry Pratchett" header—remains identical.
Evidence of Coordinated Attack Logs
Phase 1: Pharmacy/ED Spam (Reported Feb 24, 2026)
- Target: rochetnath@hotmail.com | Time: 01:09:38 UTC | Message-ID: <redacted>@r<redacted>.co.uk
- Target: dummesinternet@freenet.de | Time: 01:45:07 UTC | Message-ID: <redacted>@r<redacted>.co.uk
- Target: dh7310101@gmail.com | Time: 03:07:54 UTC | Message-ID: <redacted>@r<redacted>.co.uk
Phase 2: Dating/Phishing Spam (Current - Feb 28, 2026)
- Target: daveemo1977@hotmail.com
- Time: 18:22:02 UTC
- Message-ID: <redacted>@r<redacted>.co.uk
- Diagnostic: 550 5.7.1 Block list (S3140)
- Target: josmpson67867@outlook.com
- Time: 18:22:10 UTC
- Message-ID: <redacted>@r<redacted>.co.uk
- Diagnostic: 550 5.7.1 Block list (S3140)
- Target: hansjg57@freenet.de
- Time: 18:32:12 UTC
- Message-ID: <redacted>@r<redacted>.co.uk
- Diagnostic: 550 Spam message rejected
Required Action
Your server's failure to prevent this SMTP injection has caused my domain to be blacklisted by Microsoft (Error S3140). I request that you:
- Immediately terminate the account/user responsible for injecting these messages into your MTA (204.208.8).
- Provide a confirmation of the steps taken to mitigate this abuse.
On further investigation it looks like 91.204.208.8 is an IP address belonging to Enix Ltd, the data center infrastructure that powers the Enmail/Greenby service.
Is there anything you can do here?
Thanks,
Andy
Re: Blacklisted By Local Policy
10-03-2026 12:29 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Hi @AMH1970
It seems like you may have hit the outgoing mail limit and been blacklisted.
Could you run through the normal steps, to try and fix this please? Change your password again and run through malware & anti-virus scans.
Once the issue is fixed, we can look to un-blacklist.
Thanks
Chris
Re: Blacklisted By Local Policy
11-03-2026 1:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Hi @Christopher_G ,
I've run the malware & anti-virus scans and it has come back clean and changed my password.
Thanks,
Andy
Re: Blacklisted By Local Policy
11-03-2026 2:02 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Blacklisted By Local Policy
11-03-2026 11:24 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thank you @Christopher_G
Re: Blacklisted By Local Policy
17-03-2026 8:56 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Hi @Christopher_G,
I'm still unable to send emails. Anything you can do to get this resolved is greatly appreciated.
Thanks,
Andy
Re: Blacklisted By Local Policy
18-03-2026 8:47 AM - edited 18-03-2026 8:54 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Good morning @AMH1970.
I can absolutely double check to see what else we can do here.
Please don't share this in public, but am I correct in thinking the affected email address is the same one that you have registered here on the Community?
Also how many emails will you typically send in a day, and has this increased recently?
Peter
Re: Blacklisted By Local Policy
19-03-2026 1:00 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thank you @Peter_JW . Correct. The email I have registered here is the one I am having the issues with sending emails. Last time this happened it went on for a while and then plusnettony was able to get this resolved.
I send several emails a day but the issue looks to be someone is spoofing my email and not that my email credentials are known -
1. The "Received" Header (The Digital Postmark)
Every email has a "Received" chain that acts like postmarks on an envelope.
-
In your logs: The mail is coming from
mail.enmail.co ([91.204.208.8]). -
If you were hacked: The "Received" header would show the email originating from your actual email provider’s servers (e.g., Microsoft/Outlook or your personal host) because the hacker would be logged into your account.
-
The Verdict: The fact that the mail is originating from an Enix Ltd IP address while claiming to be "From" your domain is the definition of spoofing.
2. The SMTP Error 550 (Blacklisted by Local Policy)
The error you received when trying to send your own mail is the most telling sign.
-
How it works: When you tried to send an email, the receiving server looked at your "From" address and then checked its internal "reputation" database.
-
The Conflict: Because the spoofers at
91.204.208.8sent so much "Pharmacy" and "Dating" spam using your name, the receiving server now thinks anyone claiming to be you is a spammer. -
The Verdict: If a hacker had your credentials, they would likely be sending mail through your legitimate server, which might have avoided this specific "local policy" block for a longer period.
3. The "X-Clacks-Overhead" Signature
This is a custom header (GNU Terry Pratchett) added by the mail server software (MTA) at the source.
-
The Origin: This header is configured at the server level on the Enix Ltd infrastructure.
-
The Verdict: Unless you specifically configured your own email client or server to include this "Discworld" tribute header, its presence proves the mail is being generated by a third-party system that you do not control.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page