cPanel Mails with External Anti-SPAM Configuration

ashakhshir

Registered
Feb 19, 2012
2
0
51
cPanel Access Level
Root Administrator
Dears,
We have an external Anti-SPAM appliance that we want to use to filter incoming mails for the domains hosted on the cPanel,
Our cPanel server “WHM 11.30.6 (build 3)” contains the DNS, Website & Mailboxes for the domains…

Initially this is supposed to be done by adding an MX Record on the DNS for this domain with the higher priority pointing to the Anti-SPAM appliance, but this isn’t working,
I tried changing between different “E-mail Routing” options, but am having different issue on each one as the below :

- Local Mail Exchanger : mail is received , but directly to the cPanel, without going to the Anti-SPAM appliance, seems like the cPanel did an override to the DNS configuration and relayed the mail according to the Email Routing in the Mail Exchange Maintenance …
“domain automatically added to the “/etc/localdomains” file “



- Backup Mail Exchanger: The mail seems to keep looping between the cPanel and the AntiSPAM appliance, then a “too many hops” NDR is sent, below is the Exim log from the cPanel :


2012-02-26 11:19:48 1S1aGi-0007Td-32 =>[email protected]=lookuphost T=remote_smtp H=AntiSPAM-Appliance “x.x.x.x” X=TLSv1:DHE-RSA-AES256-SHA:256
2012-02-26 11:19:49 1S1aGi-0007WI-OK => [email protected] R=lookuphost T=remote_smtp H=AntiSPAM-Appliance “x.x.x.x” X=TLSv1:DHE-RSA-AES256-SHA:256
2012-02-26 11:19:49 1S1aGj-0007WZ-6t => [email protected] R=lookuphost T=remote_smtp H=AntiSPAM-Appliance “x.x.x.x” X=TLSv1:DHE-RSA-AES256-SHA:256


Something similar is on the AntiSPAM appliance logs, knowing that the domain is automatically in the /etc/remotedomains & /etc/secondarymx files …



- Remote Mail Exchanger: The mail is bounced back to the sender with the below NDR to the sender, without going through the AntiSPAM Appliance :

Delivery to the following recipient failed permanently:
[email protected]

Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 550 550-mail-tul01m020-f170.google.com “209.85.214.170” is currently not permitted
550-to relay through this server. Perhaps you have not logged into the pop/imap
550-server in the last 30 minutes or do not have SMTP Authentication turned on
550 in your email client. (state 14).


And the below exim log on the cPanel :

2012-02-26 12:59:30 H=mail-tul01m020-f170.google.com “209.85.214.170” F=<[email protected]> rejected RCPT <[email protected] >: mail-tul01m020-f170.google.com “209.85.214.170” is currently not permitted to relay through this server. Perhaps you have not logged into the pop/imap server in the last 30 minutes or do not have SMTP Authentication turned on in your email client.

The domain is only in the “/etc/remotedomains” files …

Please take into consideration, when choosing the automatically detect configuration, it selects the Backup setup …


Thanks in advance ...