Articles on this Page
- 01/17/17--23:06: _501 Connection reje...
- 01/18/17--02:25: _Diff between PBE E ...
- 01/18/17--13:50: _ip removal
- 01/18/17--23:29: _501 Connection reje...
- 01/19/17--02:14: _501 Connection reje...
- 01/20/17--01:05: _421 Service Tempora...
- 01/20/17--02:00: _IP removal
- 01/22/17--19:40: _IP Removal - What w...
- 01/23/17--07:23: _IP Blocked.
- 01/23/17--10:03: _What is the root ca...
- 01/23/17--12:23: _The IP address 37.1...
- 01/24/17--07:07: _Blocked IPs
- 01/24/17--18:03: _Mutliple False Spam...
- 01/24/17--22:19: _553-Message filtered
- 01/25/17--07:10: _Our IP has a negati...
- 01/25/17--12:14: _Not able to communi...
- 01/27/17--03:21: _Blocked IP
- 01/27/17--04:40: _Remote host said: 5...
- 01/27/17--04:56: _IP Blacklisted beca...
- 01/27/17--08:14: _WARNING: Someone tr...
- 01/17/17--23:06: 501 Connection rejected by policy [7.7]
- "The IP address you submitted, 18.104.22.168, does not have a negative reputation and therefore cannot be submitted for investigation."
- "The IP address you submitted, 22.214.171.124, does not have a negative reputation and therefore cannot be submitted for investigation."
- 01/18/17--02:25: Diff between PBE E & PBE Z
- 01/18/17--13:50: ip removal
- 01/18/17--23:29: 501 Connection rejected by policy [7.7] 6207
- 01/19/17--02:14: 501 Connection rejected by policy [7.7] 6207
- 01/20/17--01:05: 421 Service Temporarily Unavailable
- 01/20/17--02:00: IP removal
- 01/22/17--19:40: IP Removal - What will it take?
- 01/23/17--07:23: IP Blocked.
- 01/23/17--10:03: What is the root cause of IP in SpamCop list ?
- 01/23/17--12:23: The IP address 126.96.36.199 was found to have a negative reputation.
- 01/24/17--07:07: Blocked IPs
- 01/24/17--18:03: Mutliple False Spam Positives from O365 Sender
- 01/24/17--22:19: 553-Message filtered
- The host has been observed sending spam in a format that is similar to snow shoe spamming techniques.
- 01/27/17--03:21: Blocked IP
- 01/27/17--04:40: Remote host said: 501 Connection rejected by policy [7.7]
- 01/27/17--04:56: IP Blacklisted because of SPAM
I have an email system on IP: 188.8.131.52 and 184.108.40.206
My users and I have been getting some mails returning with: "501 Connection rejected by policy [7.7]"
The IP's mentioned above are not black listed, implement DKIM. The Symantec's ipremoval tool reports:
Could you please check why these addresses are getting blocked?
I just want to know what is the diff between Policy based encryption essential & policy based encryption advance. what features are added in PBE Advance.
appreicate any help
thanks in advance.
Need the following ip removed. It is not listed on any blacklists.
We have emails from our server to your network failing with the below errors. Our IPs doesn't appear to be in any of the major spam database as well. Please review and provide a solution.
This message was created automatically by mail delivery software. A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed: email@example.com host cluster1.ap.messagelabs.com [220.127.116.11] SMTP error from remote mail server after initial connection: 501 Connection rejected by policy [7.7] 6207, please visit www.messagelabs.com/support for more details about this error message.
When we try to delist at http://ipremoval.sms.symantec.com/lookup/ , it says
The IP address you submitted, x.x.x.x, does not have a negative reputation and therefore cannot be submitted for investigation.
We had emails from one of our servers to your network failing with the below errors, but IP is not listed in any of the major spam databases and while testing at http://ipremoval.sms.symantec.com/ it says not listed as well. Can you please provide a solution?
H=cluster1.ap.messagelabs.com [18.104.22.168]: SMTP error from remote mail server after initial connection: 501 Connection rejected by policy [7.7] 6211, please visit www.messagelabs.com/support for more details about this error message.
The IP address you submitted, x.x.x.x, does not have a negative reputation and therefore cannot be submitted for investigation.
A client using my server for emails is having issues sending emails to a client using your service. The errors are:
Connection timed out H=cluster1.eu.messagelabs.com [22.214.171.124]
SMTP error from remote mail server after RCPT TO:<firstname.lastname@example.org>: 421 Service Temporarily Unavailable
Can you see if our IP or their ISP IP has been temporarily blacklisted or why their emails are not getting through please??
server address is 126.96.36.199.
the sender address is as follows:
Sender IP: 188.8.131.52
If it is temporary like your error sugests how long will it take to heal itself?
Thanks in advance for any help/advice it would be much appreciated.
We need removal of 184.108.40.206 - this is an uncompromised ip address.
Currently we are unable to deliver mail.
We are on no other blacklist.
I have requested removal multiple times from the Symantec IP reputation system. Never get a response, never get removed. Our clients are having their email blocked to places that are using Symantec's IP blocklist to filter incoming connections.
1. We have 2 server IP's, neither one is on any blacklist anywhere.
2. We are not an open relay.
3. We use SPF records, only have about 130 email users, and are presenting NO REASON we should be on the negative IP reputation list with Symantec.
As a last resort I have posted here. Can we get some kind of action, even if it's somebody saying "this is what we don't like about your server" so we can address the problem and keep the email flowing?
I'm getting following bounce back while sending mails.
This message was created automatically by mail delivery software. A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed: Ummarah.Javed@britishcouncil.org.pk host cluster3.eu.messagelabs.com [220.127.116.11] SMTP error from remote mail server after initial connection: 501 Connection rejected by policy [7.7] 9016, please visit www.messagelabs.com/support for more details about this error message. Hamza.Salim@britishcouncil.org.pk host cluster3.eu.messagelabs.com [18.104.22.168] SMTP error from remote mail server after initial connection: 501 Connection rejected by policy [7.7] 9016, please visit www.messagelabs.com/support for more details about this error message.
As posted in the ClientNet Service Alerts, there have been several cases where a Symantec IP address is in the SpamCop list.
We have had quite a few internal support cases, because email is rejected when people send email to partners that use SpamCop.
Is there a "root cause" that explains why this is occuring so often recently ?
What steps can be taken to reduce this problem ?
It is a real problem for us.
I am trying to fix the bad reputation my mail server has. I asked for an investigation multiple times on that web page: http://ipremoval.sms.symantec.com/lookup/ But it apparently has no effect.
So I wonder how I could clear my reputation. I am quite confident I never sent spam. My server sends very few emails. Only some user registrations for my web site.
I tried very hard to configure my server well. It is in no blacklist. DNS is well configured. My emails get the best possible score at https://www.mail-tester.com/. I have SPF, DKIM, DMARC, etc.
IP is 22.214.171.124 (www.crazy-sensei.com)
Users report that they can't receive their registration email. gmail is OK. I had to contact hotmail so that they stop blocking me. Many other ISPs seem to be blocking me, too.
I'd appreciate some help.
Is it possible that you could check and clear our IPs from the symantec system or maybe forward this message to a collegue that could take care of this.
We have 2 IP's blocked by the 7.7 policy.
We are a mail provider for our private customers (mail01.manact.net) and we are also hosting mail's servers in our cloud ( eg. cswd15.cswd.be)
Our customers can't send their professional emails to their clients and this situation is really critical for us.
I'm getting false spam positives from MessageLabs when multiple users send emails from their O365 environment to MessageLabs clients. It's not all emails, just some and has only started happening in the past 10 days. This is not happening to users of other email security software/services.
I've checked the SPF and similar configuration on the O365 side and all is fine. I've also checked blacklists and have sent emails to multiple Spam analysis sites and they've reported back that all is OK.
How do I get Symantec/MessageLabs to investigate this and provide me detail on why these emails are being falsely identified?
The problem remains, we can not send emails to our customers (chinatelecomglobal.com, chinatelecomeurope.com, fujitsu.com, vodafone.com, etc)
When sending emails I receive an error:
Remote Server returned '<[126.96.36.199] #5.0.0 smtp; 5.3.0 - Other mail system problem 553-'Message filtered. Refer to the Troubleshooting page at\nhttp://www.symanteccloud.com/troubleshooting for more\ninformation. (#5.7.1)' (delivery attempts: 0)>'
IP addresses of mail servers 188.8.131.52, 184.108.40.206
Several times already sent samples of letters to the address: CLOUDfeedback@feedback-87.brightmail.com
Tell me the reason why our IP addresses are blocked?
We have a server which is hosting several domains. Using this server we cannot send any email to any domain that is behind the email security product.
According to our logs, emails are correctly delivered:
maillog:Jan 25 10:15:26 XXXXXXXX postfix/smtp: EBC616620183: to=<XXXXXX@XXXXXX>, relay=cluster8.eu.messagelabs.com[XX.XX.XX.XX]:25, delay=1.6, delays=0.9/0/0.26/0.46, dsn=2.0.0, status=sent (250 ok 1485335726 qp 29326 server-13.tower-178.messagelabs.com!1485335726!82147396!1)
However, they are never delivered to the user inbox. Some users of the Email Security have told us that they got a warning that spam was being sent and could whitelist one of our domains. Normally, what happens is that emails are not delivered, recipients get get no warning at all and we get no error message in our server's logs so the message is simply lost without anyone noticing it.
I checked the symantec IP Reputation tool and this was the result:
The IP address XX.XX.XX.XX was found to have a negative reputation. Reasons for this assessment include:
We have checked several DNS black lists and the ip is not listed there. We have checked the ougoing email and we are not observing any abnormal email deliveries. Does anybody know why our reputation is negative? I tried to remove the IP using the reputation tool and it worked, but after a few hours it got a negative reputation again.
Hope anyone can help. Thanks in advance,
We run our email on office 365 and we keep getting -
550 5.0.350 Remote server returned an error -> 553 Message filtered. Refer to the Troubleshooting page at;http://www.symanteccloud.com/troubleshooting for more;information. (#5.7.1)
Out clients can't send to us and they get the same error #5.7.1
This just started happening a couple of days ago and has never happened before. This only happens with symantec/messagelabs, every other email provider is fine. SPF and DKIM are fine, no blacklists.
How can we fix this? This is a huge pain and is disrupting our business.
We have our IP (220.127.116.11) blocked by the 7.7 policy:
host cluster3.eu.messagelabs.com [18.104.22.168] SMTP error from remote mail server after initial connection: 501 Connection rejected by policy [7.7] 9208, please visit www.messagelabs.com/support for more details about this error message. host cluster3.eu.messagelabs.com [22.214.171.124] SMTP error from remote mail server after initial connection: 501 Connection rejected by policy [7.7] 9208, please visit www.messagelabs.com/support for more details about this error message.
Could you fix this?
Thank you in advance.
Need help, our email server is getting this message:
Remote host said: 501 Connection rejected by policy [7.7] 9616, please visit www.messagelabs.com/support for more details about this error message.
The IP is : 126.96.36.199, and Testing in Symantec Portal the is not listed.
Is it possible to see why this is happening?
Can this IP set as valid?
Please help. Legitimate emails are blocked by Symantec filters.
We have been assigned a new IP address(1 month ago) from our ISP and this problem arose. This IP 188.8.131.52 belongs to Metriksoft Inc, and it provides email service for pingturk.com brand. It is a Centos machine and relay access is closed.
We are getting the following logs in postfix logs:
Jan 27 15:13:33 mail postfix/smtp: 2CC8260496: XXXX refused to talk to me: 554 5.7.1 You are not allowed to connect. Please refer to http://ipremoval.sms.symantec.com/ for further information.
I made 3 requests to the above Symantec URL for removal of the IP address(It says this machine is doing snowshoe spam which is not the case).
There is no indication of progress or follow-up mechanism for the tickets at this URL. I am not sure someone is investigating or not.
Can you help us to get out of Symantec spam blacklists?
we daily send thousands of mails to our clients with pdf attachment, and some of them receipt that answer :
The Symantec Email Security.cloud service detected a potential virus or unauthorized code (such as a Trojan or Phish) in an email sent to you.
This email will be quarantined for up to 30 days, and will then be destroyed.
Sending server IP address: 184.108.40.206
Date: Fri, 27 Jan 2017 10:51:50 +0100
Message ID: <588B1836.email@example.com>
Virus/Unauthorized code: >>> Possible MalWare 'Exploit/IFrame-0e1f' found in '5248624_2X_PM4_EM8_MH__message.htm'. Heuristics score: 200
Email quarantined on mail server server-16.tower-188.messagelabs.com (Pen ID 78438_1485510729)
Please contact your IT Helpdesk or System Administrator for further assistance.
How can we be removed from your blocklist or recover a good reputation ? Our posts are strictly the same from years, and never contains any malware or trojan...
Can you help us ? Must I send you one of our attachments for analysis ?