Cant send emails since yesterday

rodga

Honorary Master
Joined
May 9, 2007
Messages
11,682
Reaction score
1,680
Location
Gauteng
Hi

We have been getting outgoing mail errors since yesterday. I have contacted the whatsapp help that said it should be resolved by today. I still get the same error:

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed:

[email protected]
host za-smtp-inbound-1.mimecast.co.za [41.74.193.201]
SMTP error from remote mail server after RCPT TO:<[email protected]>:
550 zen.mimecast.org https://www.spamhaus.org/query/ip/154.0.168.251. - https://community.mimecast.com/docs/DOC-1369#550


Today I get this reply from your helpdesk:

Please note that our server IP address is currently blacklisted in an RBL due to which you have received the bounce back error message.
We have now submitted a delist request to remove the IP address from their blocked list. The request will take some time to get processed. Unfortunately, we do not have an exact ETA for this.
Once the delist process gets complete, you will be able to send mails without any issues.
In the meantime, if you are using any email client, then you can make use of your ISPs email server as outgoing server as a temporary solution. Once the IP address is delisted, you can revert back to the normal settings.


Is this a general afrihost problem or am I the only user affected?
When will this be resolved?


PLease assist.
 
No, you will not be the only one affected.
https://www.abuseat.org/lookup.cgi?ip=154.0.168.251
Results of Lookup

154.0.168.251 is listed

This IP address was detected and listed 43 times in the past 28 days, and 8 times in the past 24 hours. The most recent detection was at Tue Apr 17 02:15:00 2018 UTC +/- 5 minutes

This IP address was self-removed 2 times in the past week.

This IP is infected (or NATting for a computer that is infected) with a botnet, most likely eitest.

This IP address is infected with or NATing for an infection of "Eitest". This IP address is probably a web server where one or more virtual hosts have been infected using an exploit kit (eg: angler, empire, RIG) using EItest protocols to download, install and operate malicious code, such as gootkit, dreambot, ramnit, vawtrak, cryptXXX - infostealers, ransomware etc. See the reference links for more details.

Note: As this is a web server compromise, only web administrators will be able to find and fix the infection. If this web site is a virtually hosted web site, please contact your administrators with this information.

For more information on this botnet, and mitigation strategies, please see:

EITest Description and analysis.
Malwarebytes Description and analysis
Securi - how to scan and clean websites

This was detected by observing this IP attempting to make contact to a "eitest" Command and Control server, with contents unique to "eitest" C&C command protocols.

This was detected by a TCP connection from "154.0.168.251" on port "47600" going to IP address "192.42.119.41" (the sinkhole) on port "80".

The botnet command and control domain for this connection was "c84c8098.com".

This detection corresponds to a connection at Tue Apr 17 02:18:44 2018 UTC (this timestamp is believed accurate to within one second).

Looking at VT:
https://www.virustotal.com/#/ip-address/154.0.168.251

Ouch!

Registrant Street: 63 Wessels Rd
Registrant City: Johannesburg
Registrant State/Province: Kwazulu-Natal
Registrant Postal Code: 2128
Registrant Country: ZA
Registrant Phone: +27.116127200
Huh? :confused:
Invalid phone nr, invalid geography.

In other words, trashy registration details. Guess the anti-abuse people worldwide are getting a bit peeved.
 
Hi

We have been getting outgoing mail errors since yesterday. I have contacted the whatsapp help that said it should be resolved by today. I still get the same error:




Today I get this reply from your helpdesk:




Is this a general afrihost problem or am I the only user affected?
When will this be resolved?


PLease assist.

I'm really sorry you're having this poor experience.

The nature of shared hosting is that the server can be affected by the activities of any of the users or domains can affect the listings. We do our best to proactively prevent spam, bulk emailing or any other activities that might cause an IP to be listed. However, this can happen.

Have you considered a dedicated server to ensure you have your own IP?
 
I'm really sorry you're having this poor experience.

The nature of shared hosting is that the server can be affected by the activities of any of the users or domains can affect the listings. We do our best to proactively prevent spam, bulk emailing or any other activities that might cause an IP to be listed. However, this can happen.

Have you considered a dedicated server to ensure you have your own IP?

Do you have a eta on a resolution?
 
A workaround is to use your ISP's SMTP server to send mails - this seems to have worked for me.
Just remember to remove SMTP authentication from your outgoing server while using your ISP's outgoing mail server or else it wont work.

Compliments of Afrihost support, a list of ISP SMTP servers below.

For Afrihost : smtp.afrihost.co.za or smtp.isdsl.net
For Telkom : smtp.dsl.telkomsa.net or smtp.saix.net
For Telkom : smtp.saix.net or smtp.dsl.telkomsa.net
For Mweb : smtp.mweb.co.za or smtp.mweb.net
For 8TA (Eita) : smtp.saix.net
For Vodacom : smtp.vodacom.co.za
For MTN : mail.mtn.co.za
For Cell C : mail.cmobile.co.za
For Iburst : smtp.iburst.co.za
For IS (Internet solutions) : smtp.isdsl.net
For IS (3G) : smtp.isgsm.net or smtp.dial-up.net
For goggaconnect : smtp.vodacom.co.za
For Neotel : smtp.neomail.co.za
For NetActive : smtp.netactive.co.za


Hope this helps
 
I'm really sorry you're having this poor experience.

The nature of shared hosting is that the server can be affected by the activities of any of the users or domains can affect the listings. We do our best to proactively prevent spam, bulk emailing or any other activities that might cause an IP to be listed. However, this can happen.

Have you considered a dedicated server to ensure you have your own IP?

You need to force SPF and DKIM on all your domains/cpanels
 
A workaround is to use your ISP's SMTP server to send mails - this seems to have worked for me.
Just remember to remove SMTP authentication from your outgoing server while using your ISP's outgoing mail server or else it wont work.

Compliments of Afrihost support, a list of ISP SMTP servers below.

For Afrihost : smtp.afrihost.co.za or smtp.isdsl.net
For Telkom : smtp.dsl.telkomsa.net or smtp.saix.net
For Telkom : smtp.saix.net or smtp.dsl.telkomsa.net
For Mweb : smtp.mweb.co.za or smtp.mweb.net
For 8TA (Eita) : smtp.saix.net
For Vodacom : smtp.vodacom.co.za
For MTN : mail.mtn.co.za
For Cell C : mail.cmobile.co.za
For Iburst : smtp.iburst.co.za
For IS (Internet solutions) : smtp.isdsl.net
For IS (3G) : smtp.isgsm.net or smtp.dial-up.net
For goggaconnect : smtp.vodacom.co.za
For Neotel : smtp.neomail.co.za
For NetActive : smtp.netactive.co.za


Hope this helps

thanks
I have changed this earlier and its working for now.
 
thanks
I have changed this earlier and its working for now.

Glad you're getting things going. We have a dedicated team that monitor for listings and try to address them as quickly as possible. The problem is that once the listing is up, it will depend on the authority and how long they take to de-list.
 
Top
Sign up to the MyBroadband newsletter
X