Messaging Gateway

 View Only
  • 1.  Bounce attack validation - what am I missing?

    Posted Aug 23, 2016 10:24 AM

    One of my users had to send 1,000 Emails, using mail merge.

    Obviously, when you send such a large quantity of Emails at once, some will bounce back, for multiple reasons.

    However, this is what I am seeing in SMG Message Audit Logs:

    Untitled.png

    The list goes on, but with similar results - the bounce is either intended for prvs=XXXXXX=csylvie@domain.com and then it is rejected as All recipients are invalid, or it is intended for csylvie@domain.com and then it is rejected for failing bonce attack validation.

    Can someone please clarify?



  • 2.  RE: Bounce attack validation - what am I missing?

    Posted Aug 24, 2016 12:55 AM

    Hi,

    Is csylvie@domain.com a legitim mail address?

    If yes - there's something wrong with your batv config - take a look at the CC-help, search for "About defending against bounce attacks"

    Also check the policy group domain.com belongs to, spam, is "Enable bounce attack prevention for this policy group" activated and which content rule?

    If no - error at creating mails using mail merge. Catch one of the mime-mails and look for reply-to, errors-to, etc fields in the out mail

     

    Regards

    Thomas



  • 3.  RE: Bounce attack validation - what am I missing?

    Posted Aug 24, 2016 04:25 AM

    Hi Thomas,

    Thanks for your reply.

    CSylvie is a valid address, I have double-checked my config but can't find anything wrong with it - is it possible that mail merge and/or user's actions somehow breaks this functionality?

    Bounce attack prevention seed:

    CaptureA.PNG

    Enable bounce attack prevention for policy group:

    CaptureB.PNG

     



  • 4.  RE: Bounce attack validation - what am I missing?

    Posted Aug 24, 2016 07:30 AM

    Hi,

    Looks ok so far, does batv work if you're using your mail client and is only not working if the mail is sent via mail merge?

    If thats the case catch one of each kind and compare mime-header field sender, reply-to, errors-to

    Thomas



  • 5.  RE: Bounce attack validation - what am I missing?

    Posted Aug 25, 2016 02:01 AM

    Will do, thanks Thomas!