We have only one server running - mdaemon, port 25 is directed to this local server only on firewall. Before they sent last test we had rdns set incorrectly, could it be reason behind it?
Thank you for contacting Spamhaus CSS Removals,
Please use https://translate.google.com/ for language, if needed.
188.39.253.*** is making SMTP connections which indicate that it is misconfigured. Some elements of your existing configuration create message characteristics identical to previously identified spam messages.
Please align the ma l server's HELO/EHLO 'localhost.localdomain' with proper DNS (forward and reverse) values for a mail server. Here is an example:
Correct HELO/DNS/rDNS alignment for domain example.com:
- Mail server HELO: mail.example.com
- Mail server IP: 192.0.2.12
- Forward DNS: mail.example.com -> 192.0.2.12
- Reverse DNS: 192.0.2.12 -> mail.example.com
Correcting an invalid HELO or a HELO/forward DNS lookup mismatch will stop the IP from being listed again.
Points to consider:
* Alignment: it is strongly recommended that the forward DNS lookup (domain name to IP address) and rDNS (IP to domain) of your IP should match the HELO value set in your server, if possible
* The IP and the HELO value should both have forward and rDNS, and should resolve in public DNS
* Ensure that the domain used in HELO actually exists!
Additional points:
* According to RFC, the HELO must be a fully qualified domain name (FQDN): "hostname.example.com" is an FQDN and "example.com" is not an FQDN.
* The domain used should belong to your organisation.
* HELO is commonly a server setting, not DNS.
Contact your hosting provider for assistance if needed.
You can test a server's HELO configuration by sending an email from it to helocheck@abuseat.org. A bounce that contains the required information will be returned immediately. It will look like an error, it is not. Please examine the contents of this email.
If all settings are correct, you have a different problem, probably malware/spambot. Again, the HELO we are seeing is 'localhost.localdomain'. The last detection was at 2023-05-30 07:35:00 (UTC).
For information on misconfigured or hacked SMTP servers and networks, please see this FAQ: https://www.spamhaus.org/faq/section/Hacked...%20Here's%20help#539
CSS listings expire a few days after last detection. You can always open a ticket (or update an existing one) to inform us when and how the situation was been secured.