Start a conversation

Determining Why the IP DNS Blocklist Spam Filter Blocked or Allowed a Message

Overview

If you are questioning why an email was blocked or allowed by the IP DNS Blocklist spam filter and would like more information, you can find further details in the log file for that filter.

This article provides the procedure to find the log and information regarding your message within the logs. The article also contains examples so that you can interpret why the message was either blocked or allowed.

 


 

Process

  1. Find the Message ID of the email in question by gathering it from the headers of the message itself, or by looking for it in the MailEssentials Dashboard > Logs > Details tab.
  2. Open the ase_dnsbl.gfi_log file in Notepad from ...\GFI\MailEssentials\AntiSpam\DebugLogs.
    • This log is for the IP DNS Blocklist Module and corresponds to Configuration > Anti-Spam > Anti Spam Filters > IP DNS Blocklist and the antispam2_openrelay table in the config.mdb database.
  3. Perform a search for the Message ID from the dashboard or the email headers.

 


 

Examples

NOTE: The Message IDs have been removed from the example log files below. The bolded lines are the important ones in the log files for determining what has happened and why.


The email was allowed by the module:

 

Successfully retrieved Email

InfoRetriever from Propertybag

Getting connecting IP from InfoRetiever
>> SearchInCache
<< SearchInCache
>> PerformLookup
Performing DNS lookups
Performing Lookup: [161.47.171.209.bl.spamcop.net]
Lookup on DNSBL bl.spamcop.net returned: HAM

 

If a sender is on a Blocklist, you are not checking, you can add it in the configuration.

 



The email was blocked by the module:

Successfully retrieved Email

InfoRetriever from Propertybag

Getting connecting IP from InfoRetiever
>> SearchInCache
<< SearchInCache
>> PerformLookup
Performing DNS lookups
Performing Lookup: [161.47.171.209.dul.dnsbl.sorbs.net]
Lookup on DNSBL dul.dnsbl.sorbs.net returned: SPAM

 

If a valid sender is on a Blocklist, they will need to get removed from it. GFI has no control over these Blocklists.

 



The email was blocked by the module due to an entry in the cache:

Successfully retrieved Email

InfoRetriever from Propertybag
Getting connecting IP from InfoRetiever
>> SearchInCache
<< SearchInCache [SPAM]
IP [70.47.43.195] was found in cache: [Open Relay] Setting actions data ...
Spam detected, Stopping ASE Chain [2]...
Setting block report to: 'Sending mail server found on DNS Blocklist cache'

 

If a sender is in the cache but has been removed from the Blocklist, follow the instructions in the article: Clearing MailEssentials DNS Blacklist Cache Manually.

 



Module is disabled:

Open Relay and Dynamic IP check both disabled. Returning

 


 

Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted
  3. Updated

Comments