Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Access to att.com email

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 5 Posters 824 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      BobL4002
      last edited by

      I recently switched back to Comcast/Xfinity ISP from TMobile. I am having issues accessing currently.att.com (email server) due to "timeouts". I have disabled SNORT and it still fails. If i bypass pfSense firewall and run with direct connection to Xfinity gateway, no issues.

      E 1 Reply Last reply Reply Quote 0
      • E
        elvisimprsntr @BobL4002
        last edited by elvisimprsntr

        @BobL4002

        I believe ATT sill uses Yahoo for email services, which is considered an open cesspool. So it’s likely something is blocking access.

        B 1 Reply Last reply Reply Quote 0
        • B
          BobL4002 @elvisimprsntr
          last edited by

          @elvisimprsntr Yes, they do. When I am behind pfSense firewall, I can access most all other websites I regularly use with no issue, just not "currently.att.com".
          When I circumvent pfSense FW, I can access the initial website and the ATT.COM login page with not issue. From pfSense, I can traceroute to the ip address with no issue. Trying to access through browser(s) [Brave/Chrome/Edge], the connection timesout. I have disabled both SNORT and pfBlocker and still have same issue.

          E NollipfSenseN 2 Replies Last reply Reply Quote 0
          • E
            elvisimprsntr @BobL4002
            last edited by elvisimprsntr

            @BobL4002

            What DNS servers are you using? it's possible one DNS provider considers Yahoo an open cesspool and blocks their mail domain.

            I had to stop using a pfBlockerNG rule set as it was blocking legitimate enterprise VPN concentrators.

            Had another case where Quad9 was blocking access to my HOA bill pay website, which they were importing blocklists from some third party.

            B 1 Reply Last reply Reply Quote 0
            • NollipfSenseN
              NollipfSense @BobL4002
              last edited by

              @BobL4002 said in Access to att.com email:

              I have disabled both SNORT and pfBlocker and still have same issue.

              Those wasn't the problem then...you may have subdomain blocked...

              pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
              pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

              1 Reply Last reply Reply Quote 0
              • B
                BobL4002 @elvisimprsntr
                last edited by

                @elvisimprsntr

                Using Cloudflare as primary, also Quad9 as backup
                .

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  What actual error is shown?

                  Can you resolve the site from the pfSense CLI?

                  B 1 Reply Last reply Reply Quote 0
                  • B
                    BobL4002 @stephenw10
                    last edited by

                    @stephenw10 Browser attempts access for lengthy period then finally issues message that website took too long to respond. I did run traceroute from Diagnostics Page in pfSense and it worked fine getting to the address "currently.att.com" with about 18 hops.

                    Also forgot to mention earlier, I have same issue connecting to Netflix. With my TV behind the firewall, it pops up error "failure to connect to servers". When I connect TV directly to Xfinity gateway ethernet port, it works fine.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      @BobL4002 said in Access to att.com email:

                      currently.att.com

                      That just redirects for me. Can you reach: https://currently.att.yahoo.com ?

                      B 1 Reply Last reply Reply Quote 0
                      • B
                        BobL4002 @stephenw10
                        last edited by

                        @stephenw10 No, that times out also

                        E 1 Reply Last reply Reply Quote 0
                        • E
                          elvisimprsntr @BobL4002
                          last edited by elvisimprsntr

                          @BobL4002

                          A quick Google search, Cloudflare has been known to block Yahoo mail servers since Yahoo mail is an open cesspool.

                          https://www.google.com/search?q=cloudflare+blocking+yahoo+mail+servers

                          Try using Google DNS servers, 8.8.8.8 and 8.8.4.4

                          Sign up for a free gmail address, or register your own domain and sign up for email services with the domain registrar.

                          B 1 Reply Last reply Reply Quote 0
                          • B
                            BobL4002 @elvisimprsntr
                            last edited by

                            @elvisimprsntr Will try it. I did check box on General Setup indicating to use ISP DNS servers first and that did not work, even though they work when I circumvent pfSense firewall.

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Are you running Unbound (DNS Resolver) in forwarding mode?

                              Do you have the box checked to allow using DNS servers passed by the ISP?

                              B 1 Reply Last reply Reply Quote 0
                              • B
                                BobL4002 @stephenw10
                                last edited by

                                @stephenw10

                                Not running in forwarding mode.

                                Typically I do not check the "Allow ISP DNS Servers", however I did try this to bypass the DNS servers I normally use > 1.1.1.1; 9.9.9.9.

                                I will try the Google DNS servers you suggested above.

                                B 1 Reply Last reply Reply Quote 0
                                • B
                                  BobL4002 @BobL4002
                                  last edited by

                                  @BobL4002

                                  I re-checked and Forwarding Mode is checked.

                                  johnpozJ 1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @BobL4002
                                    last edited by

                                    @BobL4002 so you can't go here?

                                    https://currently.att.yahoo.com

                                    does it resolve from your client?

                                    $ dig currently.att.yahoo.com                                                         
                                                                                                                          
                                    ; <<>> DiG 9.16.50 <<>> currently.att.yahoo.com                                       
                                    ;; global options: +cmd                                                               
                                    ;; Got answer:                                                                        
                                    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41641                             
                                    ;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1                  
                                                                                                                          
                                    ;; OPT PSEUDOSECTION:                                                                 
                                    ; EDNS: version: 0, flags:; udp: 1232                                                 
                                    ;; QUESTION SECTION:                                                                  
                                    ;currently.att.yahoo.com.       IN      A                                             
                                                                                                                          
                                    ;; ANSWER SECTION:                                                                    
                                    currently.att.yahoo.com. 3532   IN      CNAME   atsv2-fp-shed.wg1.b.yahoo.com.        
                                    atsv2-fp-shed.wg1.b.yahoo.com. 3532 IN  A       74.6.143.26                           
                                    atsv2-fp-shed.wg1.b.yahoo.com. 3532 IN  A       74.6.231.20                           
                                    atsv2-fp-shed.wg1.b.yahoo.com. 3532 IN  A       74.6.231.21                           
                                    atsv2-fp-shed.wg1.b.yahoo.com. 3532 IN  A       74.6.143.25                           
                                                                                                                          
                                    ;; Query time: 12 msec                                                                
                                    ;; SERVER: 192.168.3.10#53(192.168.3.10)                                              
                                    ;; WHEN: Tue Sep 03 13:21:59 Central Daylight Time 2024                               
                                    ;; MSG SIZE  rcvd: 159                                                                
                                    

                                    what about in pfsense dns host lookup?

                                    dns.jpg

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 1
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.