Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I don't receive emails ONLY on Apple devices

    Scheduled Pinned Locked Moved pfBlockerNG
    13 Posts 5 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • UnoptanioU
      Unoptanio
      last edited by

      Good morning,
      I am writing from Italy.
      Suddenly Apple desktop PCs and Apple Phones no longer receive emails without displaying any errors. The emails simply do not arrive.
      On PCs that use Windows with Outlook and Android phones everything works.

      If I disable pfBlocker everything works regularly also on Apple devices.

      Do you have any ideas? What could it depend on?

      pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
      CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
      n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

      GertjanG dennypageD 2 Replies Last reply Reply Quote 0
      • GertjanG
        Gertjan @Unoptanio
        last edited by

        @Unoptanio

        Check your pfBLockerng logs and stats.
        On or more mail host name(s) ? Only you know where the mails should com from : gmail ? oulook ? icloud ? hotmail ? yahoo ?

        Strange is, if pfBlockerng blocks a (mail) host name, it would block it for all devices on your LAN, not just 'Apple' devices.

        ( Maybe your Windows and droid devices don't use pfSense as their DNS, so they can't use pfBlocklerng neither )

        It doesn't matter what OS or mail app is used, they all use the same host names, for example gmail uses imap.gmail.com, pop.gmail.com and smtp.gmail.com.

        @Unoptanio said in I don't receive emails ONLY on Apple devices:

        If I disable pfBlocker everything works regularly also on Apple devices.

        So pfBlockerng is blocking a host name that should be whitelisted - you've checked the Reports => Alerts and Report => Unified logs ?

        Did you've picked a DNSBL feed that contains host names that shouldn't be blocked ? ( ! )

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        UnoptanioU 1 Reply Last reply Reply Quote 0
        • UnoptanioU
          Unoptanio @Gertjan
          last edited by

          @Gertjan

          5803ccd5-237f-4bec-b156-bd2773a9bfec-image.png

          ADs_Basic
          Unified hosts + fakenews + gambling + porn

          a793e116-699b-41ce-ba6c-733d6935a1b4-image.png

          dfb2d0bb-d2ea-4b93-9149-65f113358a94-image.png

          a28e0e0f-5fe2-4a9c-bae5-50b5ce5650da-image.png

          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @Unoptanio
            last edited by

            @Unoptanio

            Well, yeah, no : I don't know what is in all those lists.
            You (should !) know (before using them).

            The mail service(s ?) that don't work anymore, who are they ?

            @Unoptanio said in I don't receive emails ONLY on Apple devices:

            fakenews

            Yeah, I can imagine that a mail server might fall under that category .... 👍 😊

            As said above : if pfBlockerng blocks for example "yahoo.com", you can see that happening on the Firewall > pfBlockerNG > Alerts page. You see also then which list contained the blocked host name.
            You can unblock (whitelist) domains on the same Firewall > pfBlockerNG > Alerts page.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 1
            • dennypageD
              dennypage @Unoptanio
              last edited by

              @Unoptanio By default, Apple devices use Privacy Protection, which routes email access through a relay in order to hide the user’s IP address. The relay is probably appearing in the blacklist.

              On a phone, the setting which controls this can be found in Settings -> Apps -> Mail -> Privacy Protection.

              GertjanG 1 Reply Last reply Reply Quote 1
              • GertjanG
                Gertjan @dennypage
                last edited by

                @dennypage said in I don't receive emails ONLY on Apple devices:

                On a phone, the setting which controls this can be found in Settings -> Apps -> Mail -> Privacy Protection.

                I'll have to play with that option.
                Mine was not set of course, but what happens when it is set ?
                Is this for sending mails ? Receiving ? Both ?

                And why "hiding" mail traffic ?
                There isn't (shouldn't be, were in 2025 now) be any mail traffic anymore that doesn't use TLS, so no MITM is possible between my phone, and the server at the other end.

                Hiding what from the mail server to which I've send a mail ?
                That's counter productive as if the receiving mail server can't check who I am - where the mail came from, change become bigger that the mail is treated as "less serious" thus the mail gets marked as spam or even discarded.

                Anyway, me just thing out loud here, I'll set this option to on and see what happens.

                edit : activating the option doesn't change anything for me.
                I could send a mail to a gmail account just fine.
                Still saw my Phone's IPv6 (a pfSense LAN prefix IPv6) in the mail headers.
                I'm plowing through the mail headers right now, can't see anything obvious or new or different.

                Is it this :

                294e03fb-456e-4b49-8000-3b72bb041937-image.png

                ?

                So before sending a mail, my phone needs to tell apple first where I'm sending to, receiving from ?
                For my privacy ? 😲

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                dennypageD 1 Reply Last reply Reply Quote 0
                • QinnQ
                  Qinn
                  last edited by Qinn

                  It might be that Apple's iCloud Private Relay is blocked and if you add below to your whitelist and do an update in pfBlockerNG, you should recieve mail again

                  Good luck

                  .metrics.icloud.com # Apple mail block introduced with ios 18.2
                  

                  Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
                  Firmware: Latest-stable-pfSense CE (amd64)
                  Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

                  1 Reply Last reply Reply Quote 2
                  • dennypageD
                    dennypage @Gertjan
                    last edited by

                    @Gertjan said in I don't receive emails ONLY on Apple devices:

                    And why "hiding" mail traffic ?
                    There isn't (shouldn't be, were in 2025 now) be any mail traffic anymore that doesn't use TLS, so no MITM is possible between my phone, and the server at the other end.

                    It's not about the content, it's about tracking. In short, senders of emails place content links in emails sent to you. When you access the email, the sender can see the IP address(s) that are used to retrieve the content. The IP address information allows for tracking of your physical location. The relay addresses this by routing all content retrieval through a privacy proxy.

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG
                      Gertjan @dennypage
                      last edited by

                      @dennypage said in I don't receive emails ONLY on Apple devices:

                      senders of emails place content links in emails sent to you. When you access the email, the sender can see the IP address(s) that are used to retrieve the content. The IP address information allows for tracking of your physical location

                      The famous white 1x1 pixel image present in a mail ... I know.

                      That issue has been solved many years ago 😊
                      Example : my mail client (Outlook 365) shows this :

                      867e4a4c-25b7-4d48-8acc-4ef752f01cc5-image.png

                      Based of who sends the mail == who I think was sending the mail and the content .... publicity of course in this case, it's "Delete" right away.

                      @dennypage said in I don't receive emails ONLY on Apple devices:

                      The relay addresses this by routing all content retrieval through a privacy proxy

                      Ah, the interesting part. Thanks.
                      So, when using this functionality on the iDevice, the mail client will access all URLs in a mail using some Apple proxy.
                      If this proxy - most probably know by the iOS with a host name, is blocked by pfBlockerng, then loading te images in a mail becomes impossible.
                      Still, the mail app in the iPhone would show == receive the mails ....
                      This doesn't check with the subject of this thread :

                      I don't receive emails ONLY on Apple devices

                      where @Unoptanio says he/she can't retrieve the mails == she/he can't access his mail server ... (I guess - posed questions are still unanswered )

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      dennypageD 1 Reply Last reply Reply Quote 0
                      • dennypageD
                        dennypage @Gertjan
                        last edited by

                        @Gertjan said in I don't receive emails ONLY on Apple devices:

                        The famous white 1x1 pixel image present in a mail ... I know.

                        That issue has been solved many years ago

                        Not the infamous 1 pixel image used on websites. This is usually general, required content. Real images, present in almost all commercial messages, without which the email does not render properly. Like the name of the sender as an image, signature lines, etc. You probably see dozens per day without noticing. Install something like Little Snitch if you want to see what's all going on behind the scenes.

                        UnoptanioU 1 Reply Last reply Reply Quote 0
                        • UnoptanioU
                          Unoptanio @dennypage
                          last edited by Unoptanio

                          @dennypage
                          Mail cannot function in IOS 18.2 if iCloud Private Relay is blocked at a network level

                          https://discussions.apple.com/thread/255916395?sortBy=rank

                          mask.icloud.com
                          mask-h2.icloud.com
                          

                          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
                          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
                          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

                          johnpozJ dennypageD 2 Replies Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @Unoptanio
                            last edited by

                            @Unoptanio maybe for apple (icloud) mail? But gmail mail works just fine on my iphone and tablet with those blocked..

                            ; <<>> DiG 9.16.50 <<>> mask.icloud.com
                            ;; global options: +cmd
                            ;; Got answer:
                            ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 5949
                            ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
                            
                            ; <<>> DiG 9.16.50 <<>> mask-h2.icloud.com
                            ;; global options: +cmd
                            ;; Got answer:
                            ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 42606
                            ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
                            

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • dennypageD
                              dennypage @Unoptanio
                              last edited by

                              @Unoptanio said in I don't receive emails ONLY on Apple devices:

                              Mail cannot function in IOS 18.2 if iCloud Private Relay is blocked at a network level

                              https://discussions.apple.com/thread/255916395?sortBy=rank

                              This reference is/was out of date. The linked discussion referrers to a specific bug introduced iOS 18.2 (December 11, 2024), which was corrected in iOS 18.3 (January 27, 2025). Apple stopped signing of 18.2.X a week later, almost 2 months before this thread began.

                              1 Reply Last reply Reply Quote 1
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.