RBL servers Adrian
    RBL servers Synametrics Support
        RBL servers Adrian

From: Adrian
Date: 4/17/25 8:01 AM
Topic: RBL servers
Type: General Discussions
Post a follow up

hello,

I get thousands of failed login attempts from nefarious IPs all over the world -invariably they appear on blacklists, such as spamcop. 

I have the server setup to block for 999 minutes, but there are so many fresh each time it doesn't do much (about 8 per minute).

My question is, could we attach logins to RBLs so they are denied in the first instance? I know this wouldn't stop spoofing necessarily, but surely would stop the low hanging fruit?

thanks,

adrian

Top

From: Synametrics Support
Date: 4/24/25 8:05 AM
Topic: RBL servers
Type: General Discussions
Post a follow up

Adrian,

I will submit a request to perform an RBL check. However, since many dynamic IP addresses appear in RBL servers, I think that will end up blocking many legitimate addresses.

A better approach is to disable SMTP Authentication on port 25 and only allow your in-house users on port 587. Block port 587 from the Internet if possible, provided your in-house users are inside your LAN. Please refer to https://www.xeams.com/best-practices-prevent-password-hacks.htm for tips.

 

Top

From: Adrian
Date: 4/24/25 10:24 AM
Topic: RBL servers
Type: General Discussions
Post a follow up

but as this is a login to Xeams, surely that's ok? The most recent ones I have are all listed on spamcop -presumably it's hackers trying to gain access to mail servers and then sending spam when they do

Recent ones:

49.124.148.2
223.245.218.51     (not in spamcop yet)
2.54.83.22
187.93.153.166   (not in spamcop yet)
73.229.65.253
95.59.101.248
98.102.148.242
218.25.233.22
203.198.129.123

Top