cancel
Showing results for 
Search instead for 
Did you mean: 

Contact AUP team

JulianMHall
Dialled in

Hi All,

My IP address is blacklisted on Spamhaus (used by many including my local authority to vet emails). Undoubtedly Virgin's fault as the last time they alleged a device on /my/ system was sending spam it turned out to be /their/ webmail - which I never use as I have my own domain.

How do I contact the AUP team //directly//? I've tried making a complaint but all I got was a standard, totally irrelevant, reply.

Kind regards,

Julian

74 REPLIES 74

ravenstar68
Very Insightful Person
Very Insightful Person

@JulianMHall 

The IP address in your bounce message is definitely NOT one of Virgin Media's email servers, they used to have two sets of servers at Knowsley but have since changed them to use SMTP servers based in the Netherlands.

When I do a dig -x command it resolves back to a residential Virgin Media address near or in Barry  (based on VM's IP naming conventions).

Somethings not adding up here.

What email client are you using to send your mails?
If you are using EasySpaces servers to send your mail, confirm the outbound mail settings.

 

I'm a Very Insightful Person, I'm here to share knowledge, I don't work for Virgin Media. Learn more

Have I helped? Click Mark as Helpful Answer or use Kudos to say thanks

Hi Coenoby,

Yes I'm assuming that IP is a VM mail server, especially as the contact detail is their NMC in Guildford, and the abuse email address is also theirs. I didn't know about Ziggo and Vodafone. Curious.

Kind regards,

Julian

Hi Tim,

The reason I don't think it's rejected until after I send it is that it sends OK and only bounces back rejected a few minutes later.

Kind regards,

Julian

Hi Tim,

I'm using smtp.ntlworld.com, port 25, no authentication, as the SMTP server and that's been working fine for years. Presumably VM alias the ntlworld domain name to theirs and have never changed it. Email client is Thunderbird, again not changed in decades. I live in Barry, so that at least makes some sense.

Kind regards,

Julian

ravenstar68
Very Insightful Person
Very Insightful Person

Quite frankly no one should be using port 25 for sending emails now, authenticated or otherwise your email is sent unencrypted across the net.  Also if easy space are hosting your email, why don't you use their smtp servers?

Tim

I'm a Very Insightful Person, I'm here to share knowledge, I don't work for Virgin Media. Learn more

Have I helped? Click Mark as Helpful Answer or use Kudos to say thanks

JulianMHall
Dialled in

Hi Tim,

Many thanks for your help, and PM.. I've emailed you directly.

TBH I don't remember why I don't use Easyspace for SMTP, although I have tried. I have a feeling it wouldn't send for some reason, and as the current setup was working I figured 'if it's not broken don't fix it'.

Kind regards,

Julian

Hi JulianMHall,

Thanks for using the Community Forums to get this issue with your email and IP address looked into, I am sorry if this has been causing some frustration 😥 

I can see you and @ravenstar68 are working together on this, our Community of VIP's are incredibly knowledgeable and helpful so you are in good hands. 

If you need further help from ourselves once you've spoken with Ravenstar68, please let us know and we will gladly continue to help 😊 

Thanks,

Megan_L

JulianMHall
Dialled in

Hi Megan,

It now looks as though Spamhaus has blacklisted my public IP address. No idea why as it has never spammed or flooded another user. I've emailed the NMC in Guildford - abuse@virginmedia.com - as the IP resolves to that on a Whois lookup.

Kind regards,

Julian

Thanks for coming back to me JulianMHall, sorry that the rabbit hole continues to go deeper with this IP address issue! 

Please let us know how you get on with the NMC in Guildford.

Thanks,

Megan_L

ravenstar68
Very Insightful Person
Very Insightful Person

@Megan_L @JulianMHall 

I'm not going to pull any punches here, so if I offend, I apologise.

Although I don't post as much as I used to, and I'm no longer a Virgin Media customer, I have retained a good working understanding of VM's email system and its history.  I also have a good understanding of email in general, not least because I run my own email server, albeit one that's been put together by teams of people who've made it easy for people to install a working email setup on a VPS (first Mailinabox and lately iRedmail).

I would also point out that I spent some months disabusing the Forum Team back in Swansea of the idea that users needed to check their home IP addresses are on a blacklist if they are having issues with mails being bounced due to blacklisting go VM's servers.

There is no rabbit hole as far as IP blacklists go.  Blacklists are not designed to stop end users sending mail through an email providers outbound mail system, they are designed for inbound mail systems (mail exchangers) to vet the IP address that is connected directly to it.  The fact that Julian's IP address is coming up makes me wonder if there is something we are not being told.

Sometimes the worst people to help on here is IT professionals, because they think they know everything, (it's a bit like doctors making the worst patients 😉 lol).  I've not been an IT professional until recently (I have started working for a well known IT company, but still learn new things).  If you don't work in a specific field, it easy to get led down the rabbit hole, as there is a lot of bad advice on the net.

How do I know I'm right, because I spend time making sure my server is NOT on any major blacklists. I also earned a damn good reputation with the former forum team for solving email issues.

What Julian was told about is correct, there are actually a number of blacklists that lists DHCP addresses, this is because addresses that have been allocated by DHCP should not be hosting mail servers and therefore should not be talking DIRECTLY to mail exchangers.  Three that I know of are:

Spamhaus PBL - (Policy Block List)
SORBS DUHL (Dynamic User and Host List)
SpamRats Dyna

All these specify IP addresses that are allocated using DHCP -Rather than IP addresses that have been seen spamming. If you are on Spamhaus' SBL that MIGHT be a different matter, but in reality even being on these lists shouldn't stop you sending mail using an email client (except that VM do use a specific element of the SBL - The CSS, to vet mails being sent via clients.  But if you were on the CSS we'd be having a whole different conversation!

So lets deal with some facts.

1.  The IP address posted in the bounce message IS your public IP address (as I guessed it would be). I know this much from the email you sent me (I checked the headers).

2.  You're not going to get taken off the PBL - your public IP address is meant to be there.

3. The fact that email to your local authority appears to be sent directly from your email address is a mystery, I saw exactly what I expected to see in the email headers, no email server I know to checks to see if the originating address of the mail is blacklisted, they merely check the blacklist status of the IP address that us connecting directly to them.  I know this as I've spent time in the past flagging posts that indicated one or more of VM's mail server IP's were blacklisted so the security team can deal.

IP addresses that are flagged on ANY of Spamhaus' blacklists show up in Spamhaus Zen (with a specific IP address in the lookup indicating which blacklist).

Checking Spamhaus confirms the IP address is in the PBL - which as already advised is expected.

Checking the headers - I see this

 

 

Return-Path: <j*********@kaotic.co.uk>
Delivered-To: t********@timothydutton.co.uk
Received: from mail.timothydutton.co.uk (mail.timothydutton.co.uk [127.0.0.1])
	by mail.timothydutton.co.uk (Postfix) with ESMTP id 4QmHcL2ZFPz4w2c
	for <t*******@timothydutton.co.uk>; Wed, 21 Jun 2023 09:04:02 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at mail.timothydutton.co.uk
Received: from mail.timothydutton.co.uk ([127.0.0.1])
	by mail.timothydutton.co.uk (mail.timothydutton.co.uk [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id gMnL-xOsnlBb for <tim@timothydutton.co.uk>;
	Wed, 21 Jun 2023 09:04:01 +0000 (UTC)
Received: from smtpq4.tb.ukmail.iss.as9143.net (smtpq4.tb.ukmail.iss.as9143.net [212.54.57.99])
	by mail.timothydutton.co.uk (Postfix) with ESMTPS id 4QmHcK5Vfmz4vyF
	for <t********@timothydutton.co.uk>; Wed, 21 Jun 2023 09:04:01 +0000 (UTC)
Received: from [212.54.57.97] (helo=smtpq2.tb.ukmail.iss.as9143.net)
	by smtpq4.tb.ukmail.iss.as9143.net with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
	(Exim 4.90_1)
	(envelope-from <j*********@kaotic.co.uk>)
	id 1qBtMk-0004Lq-Jg
	for t*********@timothydutton.co.uk; Wed, 21 Jun 2023 10:39:02 +0200
Received: from [212.54.57.109] (helo=csmtp5.tb.ukmail.iss.as9143.net)
	by smtpq2.tb.ukmail.iss.as9143.net with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
	(Exim 4.90_1)
	(envelope-from <*********@kaotic.co.uk>)
	id 1qBtMd-0000WI-Uj
	for t********@timothydutton.co.uk; Wed, 21 Jun 2023 10:38:55 +0200
Received: from [192.168.1.2] ([81.96.113.228])
	by cmsmtp with ESMTP
	id BtMdqyyzmVXvvBtMdq9145; Wed, 21 Jun 2023 10:38:55 +0200
X-SourceIP: 81.96.113.228
X-Authenticated-Sender: 
X-Spam: 0
X-Authority: v=2.4 cv=Z4gqXldA c=1 sm=1 tr=0 ts=6492b71f cx=a_exe

 

 

So it makes me wonder if you've got something more than just Thunderbird - one wonders if you have an exchange server and for some reason the server is sending mail directly to your local authority rather than through VM's servers due to some quirk of the mail connector.

I think we need to stop looking at the blacklisting and start troubleshooting the send.

Are you able to email me one of the bounce emails - AS AN ATTACHMENT - do not use inline forwarding. I need to see the whole bounce email including any headers.

Tim

I'm a Very Insightful Person, I'm here to share knowledge, I don't work for Virgin Media. Learn more

Have I helped? Click Mark as Helpful Answer or use Kudos to say thanks