8

This started 6am this morning. Incoming mail being bounced by zen.spamhaus.org. Here's one of the lines from my mail.log file.

024-11-04T14:04:43.619803+01:00 enterprise postfix/smtpd[302212]: NOQUEUE: reject: RCPT from mail-lj1-f177.google.com[209.85.208.177]: 554 5.7.1 Service unavailable; Client host [209.85.208.177] blocked using zen.spamhaus.org; Error: open resolver; https://check.spamhaus.org/returnc/pub/2400:cb00:522:1024::ac47:6576/; from=alegitemail@gmail.com to=info@mydomainname.nl proto=ESMTP helo=<mail-lj1-f177.google.com>

I'm not sure what that error ("open resolver") means. A few days ago, I had changed my DNS in /etc/resolv.com from 8.8.8.8 (Google) to 1.1.1.1 (CloudFare) because Google had some DNS issues. Both are open resolvers, but my server is not (I checked with online tools). I changed it back to 8.8.8.8 but that did not resolve the issue.

Also, if there's something wrong on my end, why isn't it blocking all incoming emails? And why did this only start this morning? I've been using 8.8.8.8 for years and never had any problems.

So I'm not sure what's going on here. For now, I completely removed zen.spamhaus.org from smtpd_recipient_restrictions in my main.cf. And that did resolve the issue.

1 Answers1

10

Have you tried googling it? In short: you use 8.8.8.8; so does a lot of other people. Spamhaus thus blocks queries from them. You should send spamhaus lookups from your IP.

This is in fact covered in their FAQ.

Furthermore, you should probably configure your MTA to not reject when faced with that error.

vidarlo
  • 11,723