Elektrine lite

← Feed

@cks@mastodon.social

Post #1475625

2026-04-20 15:54 UTC

Oops, I have to retract some of my 'the spammers are showing up on schedule' snark, because our primary MX greylists people sometime and if the primary MX is 4xx'ing things, trying the backup MX is reasonable. (But surprise, the backup MX will greylist you too because our MXes are running the same configuration.)

Replies (1)

  • @cks@mastodon.social 2026-04-20 18:34

    I did some more digging using our firewall PF logs and it appears pretty definite that some people showed up to do SMTP authentication probes only after this host appeared in DNS MX and got a TLS certificate. It's possible that the TLS certificate is the trigger for SMTP auth attempts, but they're very bad SMTP auth attempts (they aren't starting TLS, for a start, and this backup MX doesn't do SMTP auth).

    Open ##1475624