Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SMTP Issue - Hostgator and KingHost

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 4 Posters 466 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @antonioremigio1
      last edited by johnpoz

      @antonioremigio1 looks like they never answered you syn..

      Which would scream they are blocking your IP to me to be honest.. I just tried connecting to them

      Trying 192.185.177.60...
      Connected to 192.185.177.60.
      Escape character is '^]'.
      220-br184.hostgator.com.br ESMTP Exim 4.96.2 #2 Mon, 30 Sep 2024 22:50:31 -0300 
      220-We do not authorize the use of this system to transport unsolicited, 
      

      If they are not blocking your IP, something between you and them maybe.. Something upstream of you blocking 587?

      Or maybe you got back a rst, if you looked at your states right away and seeing closed, maybe they sent a rst.. I would sniff on pfsense wan when you try and open the connection.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      A 1 Reply Last reply Reply Quote 2
      • A
        antonioremigio1 @johnpoz
        last edited by

        Hello @johnpoz,

        Thanks for your reply.

        Capturing packets from the WAN, it shows like this:

        10:23:01.221460 IP MY_IP.14054 > 191.6.220.63.587: tcp 0
        10:23:09.230543 IP MY_IP.14054 > 191.6.220.63.587: tcp 0
        10:24:29.122553 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
        10:24:29.122636 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
        10:24:29.285716 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
        10:24:30.126378 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
        10:24:30.126476 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
        10:24:30.298397 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
        10:24:32.126268 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
        10:24:32.126304 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
        10:24:32.313791 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
        10:24:36.126446 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
        10:24:36.141969 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
        10:24:36.313947 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
        10:24:44.142201 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
        10:24:44.157670 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
        10:24:44.329661 IP MY_IP.39871 > 191.6.220.63.587: tcp 0

        Thank's.

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @antonioremigio1
          last edited by

          @antonioremigio1 so you never get anything back from them. Either they just dropping your traffic or it never gets to them because of a block between you and them on 587.

          Or they are blocking you and the prob level 1 guy you talking to didn't have a clue..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 1
          • GertjanG
            Gertjan @antonioremigio1
            last edited by Gertjan

            @antonioremigio1

            Same thing here :

            220-br184.hostgator.com.br ESMTP Exim 4.96.2 #2 Tue, 01 Oct 2024 10:50:02 -0300
            220-We do not authorize the use of this system to transport unsolicited,
            220 and/or bulk e-mail.
            HELO me.com
            250 br184.hostgator.com.br Hello laubervilliers-658-1-179-108.w82-127.abo.wanadoo.fr [82.127.62.180]
            quit
            

            Answers just fine.

            Btw : Hosting a (whatever) server means often therein is a fail2ban or comparable protection mechanism that scans the logs of the server you try to contact. If there are to many failed attempts, lets say 3 within 10 minutes, the IP gets banned. This happens more then you think, as we all think we know our mail password ;)
            Normally, when banning arrives, a firewall gets injected that blocks "the IP using port '587' TCP" (in this case) so you will still be able to contact port 443 TCP so you can still connect to the web interface - if any - or use the POP or IMAP access.

            And yeah, TCP is not ICMP.

            The guy that can tell you that your are blocked is normally not the one you can get on the phone.
            IPv4 on the block lists don't stay blocked for ever, as that is impossible : over time, the blacklist would contain every possible IPv4 ... so they are releases after 'some time'.

            Here you have my fail2ban stats..

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            A 1 Reply Last reply Reply Quote 1
            • A
              antonioremigio1 @Gertjan
              last edited by

              Alright @Gertjan,

              But is this rule automatically created by pfSense?

              The Hostgator SMTP started working again without me taking any action on my firewall, only Kinghost's SMTP is still blocked.

              I’m 99% sure the block is on their end.

              I’m waiting for support to reply.

              I’ll update here once I have any news.

              Thanks.

              stephenw10S GertjanG 2 Replies Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator @antonioremigio1
                last edited by

                @antonioremigio1 said in SMTP Issue - Hostgator and KingHost:

                is this rule automatically created by pfSense?

                No it's at the mail server end. Nothing you can do about it but wait for it to expire usually.

                1 Reply Last reply Reply Quote 1
                • GertjanG
                  Gertjan @antonioremigio1
                  last edited by

                  @antonioremigio1 said in SMTP Issue - Hostgator and KingHost:

                  The Hostgator SMTP started working again without me taking any action on my firewall, only Kinghost's SMTP is still blocked.

                  I’m 99% sure the block is on their end.

                  Exact. Proves somewhat my point : the fail2ban story. The block was only temporary.
                  You can easily test all this : use telnet on port 587 to login manually, like a mail client does.
                  But : do not use the correct password. Within minutes of testing, you will get blocked.
                  And unblocked xx hours later, as you've seen.

                  The mentioned fail2ban process (run on the server) puts firewall rules on the (mail) server to block users that 'fail' something, mostly : wrong password. Think about password guessing scripts ....

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  A 1 Reply Last reply Reply Quote 1
                  • A
                    antonioremigio1 @Gertjan
                    last edited by

                    @Gertjan

                    Solved:

                    Hey everyone,

                    It worked, the issue was a block on the email provider's side.

                    They unblocked my IP, and email sending is working again.

                    Thank you all for your support.

                    Cheers!

                    johnpozJ 1 Reply Last reply Reply Quote 1
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @antonioremigio1
                      last edited by

                      @antonioremigio1 said in SMTP Issue - Hostgator and KingHost:

                      It worked, the issue was a block on the email provider's side.

                      So like I thought the first guy you talked to "opened a ticket with Hostgator, and they confirmed that our IP is NOT blocked" was some idiot without a clue ;)

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      A 1 Reply Last reply Reply Quote 1
                      • A
                        antonioremigio1 @johnpoz
                        last edited by

                        @johnpoz

                        Hahaha

                        Qualified professional lol

                        Thanks for the support.

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @antonioremigio1
                          last edited by

                          @antonioremigio1 Hope gave them a bit of business end about - thought you said our IP wasn't blocked ;)

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.