Tech Report

 

Decommissioned blacklist begins returning false positives

On December 18th 2006, the Open Relay DataBase (ordb.org) anti-spam blacklist ceased operation. This blacklist was set up to advise mail servers about open relays which were used to transmit spam.

Since that time, the ordb.org servers have been discarding queries made against them, but this morning they began returning a positive match for every query. This has the effect of blacklisting every mail server on the Internet.

It has come to our attention that several customers have been continuing to query the ORDB blacklist for their incoming mail, and this morning have begun rejecting this incoming mail believing that Web Secure MailGuard's servers were blacklisted. We have contacted every affected customer directly by telephone, and advised that this configuration must be removed.

The reason for this email is to advise you that it is likely that some of your outgoing email will be rejected by mail servers on the greater Internet which still refer to the ORDB blacklist. If this happens, you will receive an non-delivery report (possibly from Web Secure MailGuard's servers) which states something along the lines of the following:

. "This server does not accept messages from known blacklisted site.
Your host was found in the DNS Blacklist at relays.ordb.org"
. "Service unavailable; Client host blocked using relays.ordb.org; ordb.org was shut down on December 18, 2006. Please remove from your mailserver."

If you receive a bounce email containing something similar to the above, you should contact your correspondent by phone or using a different email address and advise them of the problem.

Again, this problem is affecting all email users globally. We have contacted those customers whose mail servers were directly affected, so if you have not heard from us you don't need to change anything.

The following link provides breaking news coverage of this event:

http://news.google.com/news?hl=en&ned=&q=ordb
<http://news.google.com/news?hl=en&ned=&q=ordb>

If you have any questions or concerns regarding this matter, please contact the Web Secure MailGuard Service Desk on 1300 725 913.