Google blocks receipt of IPv6 email sent by OS X Server

If you are using both IPv4 and IPv6 internet connections and your email users are complaining about not receiving email, especially Google email, read on.
I use a Mac Mini running OS X Server to provide email addresses for officers in our civic association.  Most of the mail was going through but more and more complaints were coming in claiming non-receipt of email.  The mail was not in the recipients spam folder, either.
Postfix on the MacMini would send using either IPv4 or IPv6 connections when forwarding to the recipient email account.  Sending SMTP mail on using either IPv4 or IPv6 to test sites works perfectly.  Google, for some reason, has decided to refuse IPv6 connections that do not resolve with a rPTR record for sending IPv6 address.  Getting a PTR record set for IPv6 isn't always possible and there isn't a good reason why Google needs to be this restrictive.  If the email went to Google using the IPv4 route, messages would arrive in the destination mailboxes just fine since the Google rules on mail sent by IPv4 servers are less restrictive.
Two others have written how to overcome this situation on LINUX servers here http://tanguy.ortolo.eu/blog/article109/google-ipv6-smtp-restrictions and here http://christian.skala.me/blog/gmail-why-are-you-doing-this-to-me/#.VHDsUbnkHYs
These solutions work well on OS X Server's implementation of POSTFIX as long as you change the path names to the files.  So if you run into this problem on your OS X Server here are steps to force all email sent to gmail.com to use IPv4 and mail to all other domains can use wither IPv4 or IPv6.  This is the same process documented in the above links changed to work with the file paths used by POSTFIX in OS X Server
Edit /Library/Server/Mail/Config/postfix/transport using your favorite text editor (I use BBEdit) and add these lines:
Limit gmail.com to IPv4                                                             
gmail.com smtp-ipv4:
Edit /Library/Server/Mail/Config/postfix/master.cf and add these lines:
Limit gmail.com to IPv4 
smtp-ipv4 unix -       -       -       -       -       smtp -o inet_protocols=ipv4
Using terminal turn the transport file into a database POSTFIX can use:
sudo postmap /Library/Server/Mail/Config/postfix/transport
Edit /Library/Server/Mail/Config/postfix/main.cf and add these lines:
Limit gmail.com to IPv4
transport_maps = hash:/Library/Server/Mail/Config/postfix/transport
Use terminal to reload POSTFIX so the changes take place:
sudo postfix reload
You should now be able to send email messages consistently to people with [email protected] addresses and they will always use the IPv4 route while email to other domains will take either IPv4 or IPv6 routes, depending on what is optimally available at the time.

It is increasingly common for (receiving) mail servers to want to check the IP address of a sending mail server matches the authorised listed mail server for a domain, there are various different ways this is done and I don't know whether a simple DNS forward/reverse comparison is one of them. One I do know Google use is SPF (Sender Policy Framework). This uses the addition of a txt record in your domain to list which mail servers are authorised for sending emails for your domain. The SPF rule can be set to be a 'hard' fail which means an unauthorised server is always blocked, or a 'soft' fail in which case it merely increases the spam score making it more likely to be marked as spam. There are other schemes as I mentioned like domain-records/domain-eys and so on.
To check to see if your domain has one of these records try the following in Terminal.app
nslookup -query=txt domain.com
where domain.com is your domain name as used in your email address
Here is the relevant line resulting from checking google.com
google.com text = "v=spf1 include:_spf.google.com ip4:216.73.93.70/31 ip4:216.73.93.72/31 ~all"
The ~all entry means 'soft' fail a -all would mean 'hard' fail. The rest of that line defines a group of hostnames to allow, and two IP address ranges to allow.
For domain keys try
nslookup -query=txt mail._domainkey.domain.com
There are other schemes but those are the ones I have used. These are all aimed at trying to filter out fake aka. spam emails, a lot of spam uses fake from email addresses.
One could also argue that at this stage one should have a valid IPv4 address (and reverse PTR) for a mail server so as to allow other IPv4 only connected mail servers to reach you. IPv6 is still not widely adopted unfortunately. It is possible to have DNS records for both IPv4 (an A record) and IPv6 (and AAAA record) and similarly both types of reverse PTR. If your ISP is giving you true IPv6 connectivity and you are running a mail server then I would expect such an ISP to be able to define PTR records. You may need to speak to your ISP about this. The need for a valid reverse PTR is equally valid for both IPv4 and IPv6 and an ISP should be able to do both.

Similar Messages

  • Read Receipts generated for emails sent. ( SOST / SOSG )

    Hi,
    With the current settings, whenever the email sent is read , "<b>Read Receipt</b>" is sent to the user. Looks like the SOST / SOSG needs to be set accordingly. Could any one has info, how to set this, to avoid this happening.
    I could also see, SU01 has parameter SOST.
    Thanks,
    Sam

    There is a setting in SCOT --> confirmation of receipts --> set as receipt not expected.
    This will resolve the issue.
    Thanks,
    Sam

  • "Not Read" receipt received from sender for all emails sent.

    We recently migrated from Exchange 2010 to Exchange 2013 and I've got one user that started having a strange problem after the migration.  She has Outlook set to request a read receipt for all emails that she sends and that works fine except that
    for every email she sends, she gets a "Not Read" receipt back and this not read receipt comes from her as if she sent the email to herself and didn't read it.  She also get the not read receipt if she deletes emails that are in her sent box
    and again, the not read receipt comes from her.  
    This user is using Outlook 2007 SP3 with all available updates installed.  We've tried a new profile and we've also tried on a different computer with the same results.  She doesn't have any rules set up except for the one for clearing categories
    that I believe is a default rule.  I've checked the settings of the rule and there is nothing there that would be causing this.  The other strange thing is that these not read receipts seem to come in batches.  If she sends one email the the
    not read receipt doesn't show up or at least not immediately.  If she sends 2 or 3 messages then she'll get all of the not read receipts for those 2 or 3 messages at the same time.

    Hi
    Please check this thread
    http://social.technet.microsoft.com/Forums/en-US/2dbf0122-8d63-4375-91b4-6ba2cf52ed2e/not-read-receipt-to-senders
    Tell the senders to stop sending messages with read receipts and it wont be a problem
    And to To determine the problem, Please test the feature on local side to check whether the symptom occurs. Meanwhile, you can let the sender in remote domain send message to other domain to
    check the result.
    Cheers 
    Zi Feng
    TechNet Community Support

  • NDR for emails sent from Exchange Server where domain was recently moved to Google Apps for Education

    We have an exchange server that has several accepted domains.  One of those domains, littleflowerparish.org, has been moved to Google Apps for Education.  Emails that are sent from other schools on the exchange server are receiving NDR messages,
    Diagnostic information is below.  The exchange server is housed at a seperate school, which is where the generating server is coming from.  Do I need to remove a setting from the DNS area of spnserver?
    I have removed the domain littleflowerparish.org from any address policies it was in, and have removed it from the accepted domain list.  The user accounts are still on the server as users need access to them for some time.
    Thoughts?
    Diagnostic information for administrators:
    Generating server: spnserver.stphilipindy.org
    [email protected]
    #< #5.5.0 smtp;553 The sender must not be from a protected domain as the sender's IP is in the Inbound Mail Relay list.> #SMTP#
    Original message headers:
    Received: from EXCHSRVR.exchange.local ([192.168.40.6]) by
    spnserver.stphilipindy.org with Microsoft SMTPSVC(7.5.7601.17514); Thu, 13
    Feb 2014 09:29:20 -0500
    Received: from EXCHSRVR.exchange.local ([fe80::b534:8a58:7ba7:269b]) by
    EXCHSRVR.exchange.local ([fe80::b534:8a58:7ba7:269b%11]) with mapi id
    14.02.0318.004; Thu, 13 Feb 2014 09:28:21 -0500
    From: Test User <[email protected]>
    To: "[email protected]" <[email protected]>
    Subject: Today
    Thread-Topic: Today
    Thread-Index: Ac8ox9hIsit0063lRoaDqvGnRWbrjQ==
    Date: Thu, 13 Feb 2014 14:28:20 +0000
    Message-ID: <[email protected]>
    Accept-Language: en-US
    Content-Language: en-US
    X-MS-Has-Attach:
    X-MS-TNEF-Correlator:
    x-originating-ip: [192.168.40.5]
    Content-Type: multipart/alternative;
    boundary="_000_B6E5970F75447C4B8ED1982593F4C7250E4F6A6AEXCHSRVRexchang_"
    MIME-Version: 1.0
    Return-Path: [email protected]
    X-OriginalArrivalTime: 13 Feb 2014 14:29:20.0949 (UTC) FILETIME=[FC0F2E50:01CF28C7]

    Hi Justin,
    According to the error code from NDR, #5.5.0 smtp;553, it seems the Exchange server treats the eamil as a spam.
    Please check the server spnserver.stphilipindy.org just as Ed said.
    Thanks
    Mavis
    Mavis Huang
    TechNet Community Support

  • All Emails Sent to Verizon Email Addresses Are Blocked - Please Help

    Hello,
    Email messages that our company sends to Verizon recipients are being blocked by the anti-spam system. I have copied a sample failure message below. I have submitted whitelist requests several times, but get automated messages in return saying the IP is dynamically assigned (see below). Our IP address is static, not dynamically assigned. No spam is going out from the system, and we are not on any of the blacklists. Our emails to [email protected] and [email protected] are also being blocked, so I have found nowhere else to turn for assistance.
    Can you please help or assign an agent to help us in this matter? We have many customers who are not receiving their online purchases or responses to their requests for assistance from us because Verizon is blocking all emails to them from our servers. We certainly don't want to have to post to our online store that we cannot sell to or assist anyone with a Verizon email address.
    The mail server in question is: *******
    IP address: ******
    Your help would be greatly appreciated.
    Thank you,
    TraciG
    MailEnable: Message Delivery Failure.
    Reason: ME-E0193: [629A7226243B4A9D90F818B13EEF69C2.MAI] Message Delivery Failure.
    Your message addressed to the target domain (verizon.net) could not be delivered because the mail server responsible for this domain returned a permanent error.
    The server returned:
    571 Email from ****** is currently blocked by Verizon Online's anti-spam system. The email sender or Email Service Provider may visit http://www.verizon.net/whitelist and request removal of the block. 141223
    After investigation, Verizon Online Security has determined that e-mail from your IP address will not be allowed access to the Verizon Online e-mail domain due to one or more of the following reasons:
    Your IP has been blocked because of spam issues or because your ISP indicates that it is dynamically assigned
    Once you have addressed any security-related issues on your network, you should  contact Verizon Online Security via this form. At that time, we will work with you to restore normal e-mail traffic or to take other action as we deem appropriate.
    Sincerely,
    Verizon Online Security
    http://www2.verizon.net/policies
    [email protected]
    Solved!
    Go to Solution.

    Hi TraciG,
    Your issue has been escalated to a Verizon agent. Before the agent can begin assisting you, they will need to collect further information from you. Please go to your profile page for the forum and look at the top of the middle column where you will find an area titled "My Support Cases". You can reach your profile page by clicking on your name beside your post, or at the top left of this page underneath the title of the board.
    Under "My Support Cases" you will find a link to the private board where you and the agent may exchange information. The title of your post is the link. This should be checked on a frequent basis, as the agent may be waiting for information from you before they can proceed with any actions. To ensure you know when they have responded to you, at the top of your support case there is a drop down menu for support case options. Open that and choose "subscribe". Please keep all correspondence regarding your issue in the private support portal.

  • Hotmail blocking emails from iMS5.2 relay server???

    Hi all, lately we have started experiencing problems sending emails from our iMS5.2 environment to hotmail.
    In our iMS5.2 environment, we have two mail relays/gateways. Today I tried manually sending emails to hotmail using telnet. I found that I was able to send an email from one gateway (gw2) but not the other (gw1). On the mail gateway that I can't send an email, gw1, using telnet, I get the following error:
    550 Your e-mail was rejected for policy reasons on this gateway. Reasons for rejection may be related to content such as obscene language, graphics, or spam-like characteristics (or) other reputation problems. For sender troubleshooting information, please go to http://postmaster.msn.com. Please note: if you are an end-user please contact your E-mail/Internet Service Provider for assistance.
    A search on Google reveals this blocking is quite common with hotmail.
    Emails sent to yahoo, gmail work fine.
    Am I right is thinking that hotmail is blocking emails that originate from iMS5.2 mail gateway gw1? And if so, what can be done to remedy the situation?
    Thanks in advance,
    Stewart

    This isn't so much a iMS5.2 question as a simple SMTP Host question. HotMail is likely blocking your site by IP address. You could change the IP address of the host, but this might be a symptom to a larger problem of abuse.
    My advice is to go through the mail.log files to identify when those emails were originally sent to Hotmail. It might reveal a potential problem which might be an internal spammer.

  • TS3276 An email sent from my iMac has a button linked to a clip hosted on Vimeo. When received, the link functions on iMac and iPad, but opens a window of app icons on iPhone and iPod touch. Any ideas what's wrong?

    An email sent from my iMac has a button linked to a clip hosted on Vimeo. When received, the link functions on iMac and iPad, but opens a window of app icons on iPhone and iPod touch. Any ideas what's wrong?

    For anyone else reading this thread, it is worth knowing that sometimes an email is, or can be, corrupted thereby jamming the works. The solution above is good, but I just wanted to suggest another one.
    If the problem arises, go to an online mail access service, such as Mail2Web.com and login to you mail account there and delete the offending message.
    Problem solved.
    And George, as this is all entirely voluntary, whinging about no takers may not endear people to you. Besides which, a few minutes of searching on Google would have found you a number of solutions.

  • Clicking on links in emails sent to me, does not open into my browser

    Hi,
    Hopefully I am just missing something, but when I click on a link from within an email sent to me it will GO to my browser, but not do anything else. It just goes to Firefox, but keeps the window I was already in, it doesn't change to the content of the link clicked. Does that make any sense?
    I just got a new iMac about a month ago, I'm not sure if this was always a problem or it just started. I tried looking through the preferences and couldn't find anything. Any ideas??
    TIA!!

    Okay... don't laugh, but I just restarted Firefox and it's fine. I'm not sure why it was blocked.
    Problem solved... for now LOL.
    Thanks anyway.

  • Attachments in a group email sent from outlook 2007 do not show in the message

    iPad doesn't show attachments in a group email sent from a Windows 7 PC using outlook 2007. Doesn't matter what the attachment is, if it is sent to a group created in Outlook the attachments do not come through. Is this a bug in iOS? My Google Nexus 4 phone handles the attachments just fine.

    ''Toad-Hall [[#answer-670403|said]]''
    <blockquote>
    Is the 'in the clear' bar code number part of an image, it may be not shown because it was remote content?
    What happens if you read the email using 'PlainText view' ?
    'View' > 'Message body as' > 'Plain text'
    Do you have anti-virus software scanning emails?
    If yes, then switch it off to see if it is effecting the emails when it downloads.
    </blockquote>
    Thank you very much Toad-Hall. That is the information I needed. Perfect!

  • When I create an email signature, the text I type is repeated twice in the actual email sent (above and below a line).  How can I avoid this?

    When I create an email signature, the text I type is repeated twice in the actual email sent (above and below a line).  How can I avoid this?

    Try validating your installed fonts and fixing any errors that show up. To do this see this article: http://reviews.cnet.com/8301-13727_7-20085570-263/safari-in-os-x-lion-replacing- text-with-block-a-characters/

  • How to ask a receipt acknowledgement to a sent mail

    Is an option for mails to get an automatic receipt acknowledgement to a sent mail (when it is read by the recipient) ?

    That depends on which webmail service you're using. Many don't offer the option to request a read receipt (e.g. Outlook.com, Yahoo! Mail, [https://support.google.com/mail/answer/1385059?hl=en Gmail]).
    You can request read receipts if you use an e-mail client like [http://www.mozilla.org/thunderbird/ Thunderbird].
    * [[Configuration Options for Sending Messages]]

  • Google blocking attempted sign-in ONLY after upgrade to 10.10.3

    On Apple Mail, I am getting a sporadic message via Apple Mail email (ironically) telling me that Google blocked an attempt to sign-in to one of my gmail accounts.  I've had these gmail accounts working just fine with Apple Mail for quite a long time and ONLY since recently upgrading to 10.10.3 did these messages start coming in once in a while.  I've gotten a total of 4 such messages even though Apple Mail has since checked mail many, many times.  So it's not often and from what I can gather by looking at the details of what/who is attempting to log on, it's ME.  Meaning, it's Apple Mail through my MacBook Pro logging on like it's done a zillion times before but now it's once in a great while running into a problem..
    Anyone else having this issue and any idea of how to fix this???
    thanks...  bob

    Same thing is happening to me. Has happened twice now, several days apart. And each incident usually results in 2-3 email warnings from Google. Google thinks someone has tried to log into my account in a suspicious way, but it is always me. The weird thing is that it is only happening on one of my gmail email accounts. I have three. So go figure. This also only started happening when I upgraded to the new OS X. I too am using Apple Mail.
    Tomas
    MacBook Pro 13" with Retina, early 2013, OS X 10.10.3

  • I have several email account setup on iphone.  for one of them can receive from/to emails from phone, but emails sent from computer not received on phone.  phone shows receiving but does not come thru

    I have iphone 4s with several email accounts set up.  For one of these accounts, and only one, test emails sent from phone come thru fine.  But computer generated mail doesn't come to phone.  For test messages phone shows "receiving" but nothing comes to inbox.  External sent mail does not  come to phone inbox, but does to outlook on computer.  Have checked settings and these seem correct.  What's up?  Four other accounts work fine.

    If you can send e-mail when on WiFi from home, but not when on 3G, that indicates your email provider is blocking e-mail being sent from outside their network. This is done to control Spam. ISPs who do this will usually have a separate SMTP server that should be used when using a mobile device. Check with them again.

  • Emails sent from Thunderbird are not getting received when signature attached

    Emails sent from Thunderbird aren't being received by my yahoo and gmail accounts when I have the signature attached.
    It's a business email account, and I really need to have a professional signature.
    Thank you
    Susan

    There is a reason we suggest only composing HTML signature in the composer and saving the file. However, could you email me to see what that signature actually looks like (It might bounce we will see how google likes it.) this forum really messes up HTML source
    Click on my name beside the response on the forum for my email address.

  • Why is gmail blocking me from sending email with a "pages" document attached?

    Why is gmail blocking me from sending email with a "pages" document attached? I've checked the document for viruses with "MacKeeper" and it's clean.

    Google reads your emails, in case you did not know that. Unless you are sending an email containing content Google can extract and add to its vast database of personal information, Google has no use for it.
    Google Mail is becoming progressively useless. It won't accept .zip attachments, at least not the last time I tried, it will eventually prevent you from using an email client unless you visit their web mail interface, and it will disable your account if you attempt to log in from someplace Google deems is not where Google thinks you ought to be.
    Gmail is worth every cent you paid.
    Get rid of MacKeeper. It is capable of doing nothing beneficial and will only cause problems.

Maybe you are looking for

  • AT&T microcell and internet sharing

    I have an Airport Extreme connected to my cable modem, with an iMac 10.6 connected though the Airport. I just got an AT&T microcell which normally connects to the Airport ethernet port giving me better iPhone calling. I want to instead connect the mi

  • Socket Stream Communication Problem

    [My Server code]: import java.io.*; import java.net.*; import java.util.*; public class testserv { public testserv() { public static void main(String[] args) { try { ServerSocket ss = new ServerSocket(8999); Socket so = ss.accept(); System.out.printl

  • TS3694 Why can't I activate my iPhone 3Gs after set up ?

    Why can't I activate my iPhone 3Gs after set up ?

  • Twitter - talk to me...

    The only reasons I use Twitter nowadays are to complain at companies when their customer service sucks, ask companies questions when their customer service sucks and can't answer them, and tweeting or retweeting things to enter contests or win stuff.

  • Is there a way to exclude files from source paths using patterns

    Hi Does anyone know of any way to exclude files from source paths using patters rather than individually selecting the files? UI doesn't allow to specify any pattern. But if you look at the jpr file there are other places where patterns are allowed.