More hard bounce for invalid user from mail server

Hi guys,
this is my first post, but i have reade more post in this forum.
my questions is:
i have a domain into my ironport that receive more invalid recipient but the hard bouns are generate from mail server after the incoming mail pass trhough ironport.
I don't have a ldap server
you can help me for find a solution for block the invalid recipients?
this is my idea:
create a new dictionary with into all host of the domain and i apply a policy for control this dictionary.
thi solutio have a problem that i must inser in dictionary every new user create in the mail server.
regards
Michele

This would really be much easier if you had LDAP. If there is any way you could get LDAP to work in your environment, then that would make the IronPort end of things much easier. But if not, then you can do other things.
Using a dictionary as you suggest would work, but it would mean accepting the bad messages and then bouncing them. This is because you can't consult a dictionary during the SMTP conversation. A better solution would be to put the allowable recipients directly into the RAT. That would cause the invalid recipients to be rejected during the SMTP conversation, which will reduce the amount of backscatter you generate.

Similar Messages

  • HT3728 do i have to do separate backup to hard drive for each user?

    Do i have to do separate backup to hard drive for each user?

    Sorry, I am not understanding what you are trying to say.
    Time Machine is software on your Mac that allows it to back up to another hard drive.
    A Time Capsule is an Apple wireless router with a built in hard drive that can be used to store Time Machine backups from one or more Mac computers.

  • Mac mail - SSL option for the SMTP outgoing mail server - Help!

    Mac mail (Version 6.3 (1503)) will not let me "uncheck" the SSL option for the SMTP outgoing mail server - Help!
    Thanks!

    Problems such as yours are sometimes caused by files that should belong to you but are locked or have wrong permissions. This procedure will check for such files. It makes no changes and therefore will not, in itself, solve your problem.
    First, empty the Trash.
    Triple-click the line below to select it, then copy the selected text to the Clipboard (command-C):
    find ~ $TMPDIR.. \( -flags +sappnd,schg,uappnd,uchg -o ! -user $UID -o ! -perm -600 -o -acl \) 2> /dev/null | wc -l
    Launch the Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Terminal in the icon grid.
    Paste into the Terminal window (command-V). The command may take a noticeable amount of time to run. Wait for a new line ending in a dollar sign (“$”) to appear.
    The output of this command, on a line directly below what you entered, will be a number such as "41." Please post it in a reply.

  • T-code for delete file from application server

    Hi all!
    Please, has any t-code for delete file from application server? For upload exist CG3Z, for download has CG3Y. And for delete? Has anyone?
    I need to delete file from application server in QA system and i don't want to create a program for this because i will need to transport a request from DEV to QA.

    I don't have contact with basis team.
    The FM EPS_DELETE_FILE support directory name with max 60 char. My dir. has more than that. I need a transaction for this.
    Anybody know if this transaction exist?

  • Options of fetching mails from mail server into PI and also from oracle system

    hi All,
    Pls extend your help in looking out the possiblity of fetching mails from mail server into SAP PI
    and also from oracle system into PI ,earliest help would be appreciated.
    and also the types of sources for both the scenarios.
    Regards
    Vidya Sagar Manda

    Hi Vidya,
    you can use the email adapter to read/pick up email from mail box.
    and use JDBC adapter to read data from table of any database. Please refer the links given to your old thread
    Fetch Mails From MailServer using PI and integrate the message into BPM
    regards,
    Harish

  • How can i get all the users from weblogic server?

    how can i get all the users from weblogic server?
    i have configurated a LDAP server using iPlanet and
    in weblogic server console i see those users from LDAP
    server. but how can i get all the users in my program
    from weblogic server instead of LDAP server?
    BTW,how to configure a RDBMSAuthenticator and what should i do
    in Oracle? which tables should i create? and how are their architectures?
    Thanks
    Daniel

    BTW, i use weblogic platform 8.1
    "Daniel" <[email protected]> дÈëÓʼþ
    news:[email protected]..
    how can i get all the users from weblogic server?
    i have configurated a LDAP server using iPlanet and
    in weblogic server console i see those users from LDAP
    server. but how can i get all the users in my program
    from weblogic server instead of LDAP server?
    BTW,how to configure a RDBMSAuthenticator and what should i do
    in Oracle? which tables should i create? and how are their architectures?
    Thanks
    Daniel

  • Error adding new users from local server

    Hello, BPC Gurus,
    We use BPC 7.0 MS SP4, MS SQL 2008 (Server name - BPCP01)
    In Administration Console we're trying to add user from local server (server with SQL Database), and warning window is appeared with message "The Server Is Not Operational [BPBCP01]"
    I checked Logging folder and found message:
    ==============[System Error Tracing]==============
    [System  Name] : OSoftAdminSecurity
    [Job Name]     : frmManageUser::GetAllObjectsFromDomainServer
    [DateTime]     : 2010-12-06 16:58:43
    [Exception]
        DetailMsg  : {System.Exception: The server is not operational [BPCP01]
       at Microsoft.VisualBasic.CompilerServices.LateBinding.LateGet(Object o, Type objType, String name, Object[] args, String[] paramnames, Boolean[] CopyBack)
       at OSoft.Consumers.Admin.Security50.ManageDataSet.GetAllObjectsFromDomainServer(String pDomainName, String pLDAPFullPath, Int32 pDomainObjectType, String pObjectValue, String pDomainType)
       at OSoft.Consumers.Admin.Security50.frmManageUser.GetAllObjectsFromDomainServer(String pDomainName, FILTER_TYPE pOptionType, String pOptionValue, String pDomainType)}
    ===========[System Error Tracing  End ]===========
    Any ideas?

    The installation was done with a local user or with a domain user?
    You know that BPC server can not be in the same time also domain controler.
    Are you using Windows authentication or CMS authentication.
    If you are using CMS authentication then again you can not add local users.
    If you are using Windows authentication then you have to go into server Manager
    Options - Define System User Groups
    Domain Type - Local Windows
    System User Group Name - Local Users.
    If you are using Windows 2008 make sure you addrole to have compatibility with IIS 6.because using this module bpc is adding new users.
    Regards
    Sorin Radulescu

  • Campaigns - Hard bounces for valid email addresses

    I am getting hard bounces with 'Bad Mailbox Destination Address' for valid email addresses that everybody internally and externally can email without problem.
    Doesn't instill me with much faith for sending out 10,000 emails next week!

    If you can email that address manually from a regular email address and it goes through fine then it's likely you might be getting blocked by spam filters although usually that would be indicated in your bounce message.
    Is your site fully hosted on BC (ie - with BC's nameservers) or is your domain hosted via an A record to point to BC?  If you are being blocked by spam filters then you are likely using the A record because fully hosted sites on BC have the SPF records in place.
    If you are using an A record to point to BC's servers for your domain and manage your DNS records somwehere then you need to add a TXT record with the SPF data.  Goto your domain registrar and manage your DNS entries.  You'll want to add a TXT record with the following info:
    Record name: @
    Record type: TXT
    Record value: v=spf1 mx include:worldsecuresystems.com ~all
    Record TTL: 86400
    You can only have one SPF record on your domain so if you already have a TXT record with SPF data in it for other email services your domain uses (like gmail) you just need to update your TXT SPF record and add "include:worldsecuresystems.com" after the first "include" statement in the TXT record the TXT value would look like:
    "v=spf1 mx include:_spf.google.com include:worldsecuresystems.com ~all"
    If your problem is that your emails are blocked by spam filters that should fix it but I'm pretty sure 'Bad Mailbox Destination Address' usually indicates a non-existent or malformatted username in your email address (ie - the part before the "@").  I would also double check your subscribers list and make sure there are no spaces or any other invalid character in the email addresses for the customers that are getting bounced back.
    Here's more information about your specific error from http://technet.microsoft.com/en-us/library/bb232118(v=exchg.80).aspx which has to do with MS Exchange server specifically but still provides a good explanation:
    5.1.1
    Bad destination mailbox address
    This failure may be caused by the following conditions:
    The recipient e-mail address was entered incorrectly by the sender.
    No recipient exists in the destination e-mail system.
    The recipient mailbox has been moved and the Microsoft Office Outlook recipient cache on the sender's computer has not updated.
    An invalid legacy domain name (DN) exists for the recipient mailbox Active Directory.
    This error typically occurs when the sender of the message incorrectly enters the e-mail address of the recipient. The sender should check the recipient's e-mail address and send again. This error can also occur if the recipient e-mail address was correct in the past but has changed or has been removed from the destination e-mail system.
    If the sender of the message is in the same Exchange organization as the recipient, and the recipient mailbox still exists, determine whether the recipient mailbox has been relocated to a new e-mail server. If this is the case, Outlook may not have updated the recipient cache correctly. Instruct the sender to remove the recipient address from sender's Outlook recipient cache and then create a new message. Resending the original message will result in the same failure.
    Other issues may cause this error, such as an invalid legacy distinguished name (DN) in Active Directory. Examine and correct the legacy DN of the recipient's mailbox. Then instruct the sender to remove the recipient address from sender's Outlook recipient cache and then create a new message. Resending the original message will result in the same failure.

  • Getting mail authentication errors for outlook user sending mail

    When Outlook 2010 user attempts to use port 587 to send mail (to himself at this point), we see the following in the server logs:
    (User in question can attach to file shares on the same server just fine from his Windows laptop)
    Outlook config for outbound server is "port: 587, encryption TLS"
    When we connect, we get "connection interrupted by server"
    Tried other encryption methods - outlook 2010 states that server does not support the other methods (None, SSL)
    SMTPD Logs
    Jul 29 22:22:58 <servername>.l-n-l.com postfix/smtpd[2306]: connect from <Outlook Client Name>[<Outlook ClientAddr>]
    Jul 29 22:22:58 <servername>.l-n-l.com postfix/smtpd[2306]: error: validate response: error: Authentication server failed to complete the requested operation.
    Jul 29 22:22:58 <servername>.l-n-l.com postfix/smtpd[2306]: error: validate response: authentication failed for user=colin (method=DIGEST-MD5)
    Jul 29 22:22:58 <servername>.l-n-l.com postfix/master[1407]: warning: process /usr/libexec/postfix/smtpd pid 2306 killed by signal 6
    Jul 29 22:22:58 <servername>.l-n-l.com postfix/master[1407]: warning: /usr/libexec/postfix/smtpd: bad command startup -- throttling
    Jul 29 22:24:12 <servername>.l-n-l.com postfix/smtpd[2270]: timeout after END-OF-MESSAGE from localhost[127.0.0.1]
    Jul 29 22:24:12 <servername>.l-n-l.com postfix/smtpd[2270]: disconnect from localhost[127.0.0.1]
    Meanwhile: Mac clients are able to connect to smptd submission port to send mail with no problems. Based on what the logs say, it appears that the Mac mail is using a different authentication mechanism.
    Client config for outbound server is "use custom port: 587, Use SSL:Checked, Authentication: MD5 Challenge-Response"
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/smtpd[2261]: connect from <Mac Client Name>[<MacClientAddr>]
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/smtpd[2261]: 721FCEC991: client=<Mac Client Name>[<MacClientAddr>], sasl_method=CRAM-MD5, sasl_username=<username>@l-n-l.com
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/cleanup[2267]: 721FCEC991: message-id=<[email protected]>
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/qmgr[1800]: 721FCEC991: from=<[email protected]>, size=573, nrcpt=1 (queue active)
    Jul 29 22:19:12 <servername>.l-n-l.compostfix/smtpd[2270]: connect from localhost[127.0.0.1]
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/smtpd[2270]: E722AEC9A0: client=localhost[127.0.0.1]
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/cleanup[2267]: E722AEC9A0: message-id=<[email protected]>
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/qmgr[1800]: E722AEC9A0: from=<[email protected]>, size=994, nrcpt=1 (queue active)
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/smtp[2268]: 721FCEC991: to=<[email protected]>, relay=127.0.0.1[127.0.0.1]:10024, delay=0.55, delays=0.06/0.01/0.01/0.48, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as E722AEC9A0)
    Jul 29 22:19:12 <servername>.l-n-l.com postfix/qmgr[1800]: 721FCEC991: removed
    Jul 29 22:19:13 <servername>.l-n-l.com postfix/pipe[2273]: E722AEC9A0: to=<[email protected]>, relay=dovecot, delay=0.13, delays=0/0.01/0/0.12, dsn=2.0.0, status=sent (delivered via dovecot service)
    Jul 29 22:19:13 <servername>.l-n-l.com postfix/qmgr[1800]: E722AEC9A0: removed
    Jul 29 22:20:12 <servername>.l-n-l.com postfix/smtpd[2261]: disconnect from <Mac Client Name>[<MacClientAddr>]
    Running OS X 10.8.4 with Server 2.2.1.
    Any thoughts on what I need to do to make OSX Server mail play nice with Outlook over the submission port?
    Thanks in advance!!

    Ok - so I think I have it almost all sussed. So for all 3 of you who might be reading this, here is what is going on.
    1) As I expected, this has nothing to do with the FQDN/Outlook problem. I actually rejoiced when I finally got far enough to have that problem with my Outlook 2007 and 2010 clients. And I don't like the recommended fix for that either. There is another way - more on that in a minute.
    2) This problem was all about authentication methods. At present, I have OS X Mail Server set for plain text and APOP only. I will be working to fix this soon - but at present I am unable to find any other combination that permits both Mac Mail and Outlook clients to authenticate properly. Mac Mail wants to use CRAM-MD5 by default. Outlook is so incompatible with CRAM-MD5 that even when there are other authentication methods available on the mail server, if CRAM-MD5 is selected on the Server then Outlook fails miserably no matter how you configure the Outlook client. Caveat: this is my own observation and I still have some experimenting to do. If you know otherwise (or can confirm more definitively), then please speak up!
    So here is the working configuration at present:
       A) Mail Server authentication set to Custom with PlainText and APOP selected, all others blank.
       B) Firewall permits inbound from ports 25 (for mail from "outside"), 587 (submission for authenticated users, TLS) 993 (SSL IMAP), and 995 (SSL POP).
       C) Mac POP Clients:
          i) For retrieval (POP) In advanced settings, use Port 995, Check "Use SSL", Select APOP for authentication.
          ii) For submission (SMTP) : Set port 587 (only), Set Authentication to "Password"
        D) Outlook 2007,2010,2013 clients
           i) For retrieval (POP), Set "Require secure logon using SPA"
          ii) In "More Settings/Outgoing Server" set it to require authentication with same credentials as inbound
         iii) In "More Settings/Advanced"
             a) Turn on Encryption for the POP3, this should change the port to 995 automatically. If it does not, fix that too.
             b) Set outgoing server to 587
             c) Set TLS for the encryption type (nothing else will work here)
    Once you do 2.A, 2.B, 2.D, you will THEN, finally encounter the FQDN problem.
    3) So Apple and a lot of folks here in the forums resolve the FQDN problem by removing one of the restrictions:
        Remove "reject_non_fqdn_helo_hostname" from "smtpd_helo_restrictions" in your postfix main.cf file.
    I have at least 2 problems with this:
       A) It removes yet another little bit of security from the setup
       B) It involves non-GUI changes to the config...which is dangerous if you use the GUI, as changes within the GUI will often result in overwrites to your changes outside the GUI. So you can easily lose this fix without being aware of it until one of your Outlook users starts screaming.
    The problem is really with Outlook and Windows not sending the FQDN in the first place. So how about we force them to do that instead? It turns out not to be too hard. I found a thread somewhere that goes into this and it works. Further, the solution remains on through reboots AND also can be made part of an automated deployment of a standard config. The only gotcha is you have to edit the registry...so you have to be careful. You only need to do this ONCE though, and the two entries are easy to find.
      C) Under HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/services/Tcpip/Parameters
           i) Set Hostname to the FQDN of your host (replace HOST with HOST.domain.com - or .net, or whatever)
          ii) Set NV Hostname to the FQDN of your host
          iii) Close Regedit and Reboot to have the changes take effect
    Once you do this, the FQDN problem for Outlook users goes away.
    So I am looking for suggestions to make the SMTP submission more secure. Aside from that, things are working - and I have had to make ZERO changes to config files outside of the Server GUI - a plus as far as I am concerned.

  • Personal quarantine for invalid users

    Hello, 
    1) how to prohibit on ironport to create personal Spam Quarantine for users who are invalid (nonexistent users of my domain and users from other email service (gmail.com)) and can i configure to drop messages for nonexistent users of my domain?
    2) how to configure to see my outgoing messages that were put in Spam Quarantine in my personal quarantine?
    Thanks.

    Hey Alibek,
    From my testing on my lab environment, i was able to manipulate the email in the way so it forces the email to be sent to the spam quarantine of the sender address rather than recipient (which is the design).
    However to do so, it requires altering of the actual email in the event the email is seen as positive spam you'll re-write the recipient so that it goes into the sender mail box, but by doing so when the email is released it will not release back to the original recipient but to the actual sender.
    This type of behaviour is not with the system design so I went forward with mail manipulation to achieve the results desired (to an extent)
    What this means is, for testing purposes (before you decide if you want to put this into production)
    Create an outgoing mail policy for your test address to be using where sender is your address.
    On the anti-spam settings, change positive/suspected spam to 'deliver' but add a custom header like X-IP-Spam or so.
    Create a content filter where it will look for this header, and if the header exists.
    Action would be
    Change recipient to -> The sender address
    Change mail destination host -> 'the.euq.queue'
    Then enable this content filter.
    What this filter does is, it will re-write the original intended recipient to the sender address when emails are seen as spam and will send it to the rewritten 'recipient' spam quarantine.
    Thus will go into the spam notifications when generated.
    Note: When you release this email, it will release to the rewritten recipient and not the intended recipient.

  • Has the bounce facility been removed from mail?

    I want to Bounce an email back to the sender but can't find the command in Mail 5.3.
    Has this feature been removed since the previous version of mail?

    Yes. That feature is no more available.
    For alternatives:
    http://support.apple.com/kb/TS3498

  • 3rd party for archiving emails from MAIL 2

    I am having problem with archiving email from Mail 2.
    My mailbox is quite big (>3GB). It takes more time to open.
    Do you know anyway to archive old emails to other location, then we just open old mails from that location?
    I tried with Mail Scripts, unfortunately after archiving, I can't restore to original location.
    Thanks,

    Yes, there really is only one piece of software to consider: the excellent MailSteward.
    It's robust, flexible, well-priced, versatile, quick and extremely well supported. It'll allow you to set a variety of criteria against which to export emails, which they become fully visible, searchable and you can even reply to an archived message.
    Attachments can be searched and emails re-imported back into Mail if you ever so need.
    Really an outstanding piece of work! Good luck.
    (I'm a user; have no connection with the developers; just very impressed with them.)
    G5 DP 2 GHz   Mac OS X (10.4.8)   No Haxies; permissions frequently repaired etc

  • Time machine hard drive for transfering files from 2010 MBP to rMBP

    Hello!
    I have a couple of questions here!
    I will be getting the rMBP in the next few weeks so want to do a bit of housekeeping before transferring across.
    1) What is the best way to clear my current MBP of files and applications that i dont use and are just taking up space? I currently have a 256GB hard drive with 8GB free - there should be no reason for this as my large audio/ Raw photo/ video editing files are on an external hard drive. So i think there must be a lot of flotsam and jetsam on there that needs to be removed as i don't want to carry that from computer to computer!
    2) Is Time machine the best option for this kind of service?
    3) Can anyone recommend an external hard drive for the job? I don't want to rely on thunderbolt ones at the moment so would it just be any usb hard drive seeing as Apple has sodded of firewire?
    Cheers
    K*

    OK, I'll bite:
    1) you can just delete the documents that you don't use by throwing them in the Trash. To delete apps and all associated files (and some will disagree with me or suggest another application) I recommend using AppDelete. I believe it's $13 or so but I have used AppZapper and AppCleaner as well but find that AppDelete finds all associated files.
    2) After you've rid yourself of your 'junk' files, I recommend using Time Machine on a dedicated or partitioned hard drive for backups. When you get your new machine, you can just use Time Machine to restore all of your settings, apps, documents, etc. For everything you ever wanted to know about Time Machine, see  http://pondini.org/TM/FAQ.html.
    3) A USB drive is definitely the way to go. I would recommend the G-Drive series from Hitachi here. They have all sorts of connections, including USB 2.0 and Firewire 800. When Apple (finally) releases their Thunderbolt>FW800 adapter, you'll be ready. Others might recommend USB 3.0 drives for the speed but I've seen too many posts of, in particular, Western Digital USB 3.0 drives that have problems with the 2012 Macs to go the USB 3.0 route right now. Maybe someone will jump in and recommend a USB 3.0 drive that they actually have working on a 2012 MBP?
    Good luck,
    Clinton

  • How to unlock internal Hard drive for other user

    i have fast user switching set, and i can log on to that user's desktop.  however, when i try to start iTunes, i get a message that says the hard disk is locked.  So iTunes won't open.  I had set a whole bunch of songs for this user, but now can't seem to open itunes.  It's a power PC (not intel), and software is all up to date (it was after the last upgrade that this may have happened. 
    BTW, onthe get info pop up, i unlocked the drive and set the priveledges for the HD  to read and write, but still get the locked HD message when opeing iTunes.
    Any suggestions? 

    Well i appreciate your help.  Two followups to report.
    1.  i just made a new account and imported the old itunes music. This worked, so i deleted the old account.
    2.  now for the bad news.  When i tried to restart the computer, it just freezes after lighting up the screen.  then after about 3 min, the fan starts blowing full steam.  Sounds bad based on past experience.   So i'm off to the genius bar tonite and hope the HD and backup HD are still OK. 
    Thanks again.

  • How to grant access to sharepoint for the user from different Domain

    Hi All
        I need to grant access to user from different domain. 
        Where I can able to view the users in people picker (different domain).
    Thanks in Advance.
    Raj

     Hi
    Trevor Seward
    Sorry to disturb
    you again.
      I am trying to restrict user from search from other domain, say we have domain A and Domain B, where I am trying to restrict all the user from domain B (Search users)for a site collection. I have found couple of stsadmin command to do so. but none
    of them works. Below are the commands I have tried
    STSADM.exe -o setproperty -pn peoplepicker-searchadforests -pv "domain:<Name>.domain" -url "http://Site URL"
    stsadm -o setproperty -pn peoplepicker-searchadcustomquery -pv “(canonicalName=<Name>.domain*)” -url "Site URL"
    we have two way trust.
    Can you suggest any solution.
    Thanks 
    Raj

Maybe you are looking for

  • [CS3][JS] How to place multipage Indesign-file

    Hi, Can anyone please help me? How do I place every page of an external Indesign-file into my current document [JS]? How do I set the import options? Thanx Tim

  • G5 2ghz Dual - Hanging with LED #7!!!

    Hi folks, my 8 month old G5 has just started hanging (freezing completely!) with the #7 LED lit. There are no Kernel Panic screens shown - it just stops working. At the moment its run time is limited to about 60mins. Its not a software issue as all t

  • Keeping Keynote Full Screen while Using Other Apps

    Hello, I searched around and wasn't able to find much of anything on this topic anywhere. I am looking to do Keynote presentations in full screen. While the presentation is in full screen I would like to use other applications on the display which I

  • Strange network track quirk...

    Yes, yet another annoying and time-wasteful feature that is Logic "Pro" 8. Can anyone explain this,please? If I create or change to a network-based track, ie: ctrl/click/hold and select from "reassign track object", whereupon I choose a multi-instrum

  • Backup failed with error: 11 -Error: (-41) SrcErr:NO Copying

    Like many of you, I was unlucky to get the famous TimeMachine error message: "The backup was not performed because an error occurred while copying files to the backup disk". I started to get as much help as I could from Google and all your forum post