I'm on a blocklist! HELP!

Recently, an abuse desk rep asked what to do when customers were complaining about being assigned an IP address located on a blocklist. Because not every blocklist actually affects mail delivery it’s helpful to identify if the listing is causing a problem before diving in and trying to resolve the issue.

  1. Find out whether mail is actually being blocked, or whether the customer just went to one of the jumbo economy blacklist checker sites.
  2. If no mail is being blocked, it’s not an issue.
  3. If mail is being deferred (Yahoo…) it’s not the same issue as being blocked, and likely isn’t worth pursuing.
  4. If mail is being blocked, don’t take the customers word for why. If they got an email rejected by, say, Earthlink for some reason and then went to the blacklist checker and discovered that they’re listed on FIVETEN, they might grab onto that listing like a rabid terrier when it’s really an irrelevant rathole.
  5. Start with the rejection message. If it has a URL in it, that’s all you need to start with.
  6. If not, see if it’s consistent – does test mail get rejected. If not, it’s either a transient issue or it’s a content-based block rather than an IP based block, and hence not your problem.
  7. If there’s no URL in the rejection, contact the entity that blocked the mail, perhaps.
  8. Make a good judgement call about whether it’s worth caring. If it’s just one guy in his Mom’s basement blocking mail then it’s not worth the time or energy to care about the issue.
  9. If this is really business-critical for the customer then they should talk to a decent consultant rather than relying on their abuse desk for assistance.

Related Posts

Sender complaints about spamfiltering

JD posed a question in my post about Postini and trying to sort out a customer getting marked as spam by their filtering mechanism and I think it bears more discussion than can be done in comments.

Read More

Yahoo and Spamhaus

Yahoo has updated and modified their postmaster pages. They have also put a lot of work into clarifying their response codes. The changes should help senders identify and troubleshoot problems without relying on individual help from Yahoo.
There is one major change that deserves its own discussion. Yahoo is now using the SBL, XBL and PBL to block connections from listed IP addresses. These are public blocklists run by Spamhaus. Each of them targets a different type of spam source.
The SBL is the blocklist that addresses fixed spam sources. To get listed on the SBL, a sender is sending email to people who have never requested it. Typically, this involves email sent to an address that has not opted in to the email. These addresses, known as spamtraps, are used as sentinel addresses. Any mail sent to them is, by definition, not opt-in. These addresses are never signed up to any email address lists by the person who owns the email address. Spamtraps can get onto a mailing list in a number of different ways, but none of them involve the owner of the address giving the sender permission to email them.
Additionally, the SBL will list spam gangs and spam supporters. Spam supporters include networks that provide services to spammers and do not take prompt action to remove the spammers from their services.
The XBL is a list of IP addresses which appear to be infected with trojans or spamware or can be used by hackers to send spam (open proxies or open relays). This list includes both the CBL and the NJABL open proxy list. The CBL list machines which appear to be infected with spamware or trojans. The CBL works passively, looking only at those machines which actively make connections to CBL detectors. NJABL lists machines that are open proxies and open relays.
The Policy Block List (PBL) is Spamhaus’ newest list. Spamhaus describes this list as

Read More

Legitimate email marketers need to take a stand

I was reading an article on Virus Rants and the opening paragraph really stood out.

Read More