I'm sorry that this is off subject and do not have anything thing to
do with sendmail specifically, but more of a general question as I
have noticed that I do not get mail from all domains, looking at the
firewall logs, I can say the remote side do not even try to connect
to the server.
I have done all I know of, SPF, DMARC, DKIM, but is there something
new that is required nowadays?
On 18.11.2025 10:07 Uhr J.O. Aho wrote:
I'm sorry that this is off subject and do not have anything thing to
do with sendmail specifically, but more of a general question as I
have noticed that I do not get mail from all domains, looking at the
firewall logs, I can say the remote side do not even try to connect
to the server.
Does it affect only special sites?
Can you reach the sending server using ping etc.?
Make sure networking works. If the AS includes a RIPE Atlas probe, try
this to check if that can reach your mailserver.
I have done all I know of, SPF, DMARC, DKIM, but is there something
new that is required nowadays?
For a sender, your DNS SPF/DMARC/DKIM records are irrelevant.
They try to send you the mail and unless you reject it, they are done.
I did create an account and run a traceroute test, 98 failed and 2
wasn't run, all seems to end at the same server on Austria, the route
back from my mail server do take another path. I didn't try ping as
by default the setup do not respond on ping.
for me it looked like many of the sources that RIPE uses seems to be
in the same ip-range and same gateway, of course I haven't checked
every instance, but I was trying to check a handful from different
countries.
On 18.11.2025 14:46 Uhr J.O. Aho wrote:
I did create an account and run a traceroute test, 98 failed and 2
wasn't run, all seems to end at the same server on Austria, the route
back from my mail server do take another path. I didn't try ping as
by default the setup do not respond on ping.
You can use bgp.he.net super traceroute.
Please let us know which probes you used and what your IP is.
Be aware that the probes send UDP packets to a high port, so a firewall
can block them while TCP port 25 is not being blocked.
for me it looked like many of the sources that RIPE uses seems to be
in the same ip-range and same gateway, of course I haven't checked
every instance, but I was trying to check a handful from different
countries.
Use HE supertraceroute, you can select countries and ISPs here.
sendgrid.net had been banned due of specious looking connections from
an ip and a whole large range had then been banned.
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 54 |
| Nodes: | 6 (1 / 5) |
| Uptime: | 20:59:41 |
| Calls: | 742 |
| Files: | 1,218 |
| D/L today: |
6 files (8,794K bytes) |
| Messages: | 185,811 |
| Posted today: | 1 |