Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. False positive on SpamHaus

False positive on SpamHaus

Scheduled Pinned Locked Moved Solved Support
spamhausemail
47 Posts 10 Posters 2.2k Views 10 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • girishG girish

      @potemkin_ai @DualOSWinWiz one caveat I rediscovered recently (sorry, I forgot this entirely) is this file : https://git.cloudron.io/platform/box/-/blob/master/setup/start/unbound/prefer-ip4.conf?ref_type=heads

      We do spamhaus queries via unbound. If your server has IPv6, then older version of unbound might use IPv6 and SpamHaus often fails those queries. From ubuntu 24, there is a flag to tell unbound to prefer ipv4 instead of the ipv6 . Does this situation apply to either of you ? i.e do you have ubuntu < 24 and ipv6 ? if so, this might be the issue

      D Offline
      D Offline
      DualOSWinWiz
      wrote on last edited by
      #21

      @girish i have 24.04 and ipv6 is disabled

      1 Reply Last reply
      0
      • girishG girish

        @potemkin_ai @DualOSWinWiz one caveat I rediscovered recently (sorry, I forgot this entirely) is this file : https://git.cloudron.io/platform/box/-/blob/master/setup/start/unbound/prefer-ip4.conf?ref_type=heads

        We do spamhaus queries via unbound. If your server has IPv6, then older version of unbound might use IPv6 and SpamHaus often fails those queries. From ubuntu 24, there is a flag to tell unbound to prefer ipv4 instead of the ipv6 . Does this situation apply to either of you ? i.e do you have ubuntu < 24 and ipv6 ? if so, this might be the issue

        D Offline
        D Offline
        DualOSWinWiz
        wrote on last edited by
        #22

        @girish already 380ce3db-fd0b-4588-a52a-1153936e4bc0-image.png

        1 Reply Last reply
        0
        • D Offline
          D Offline
          DualOSWinWiz
          wrote on last edited by
          #23

          @girish finally i figured out the problem it was Unifiy Gateway (it was Using content filtering in order to moderate the traffic and using dns once i turned off that for all turned green and so far since last 3 hours its green.

          potemkin_aiP 1 Reply Last reply
          2
          • D DualOSWinWiz

            @girish finally i figured out the problem it was Unifiy Gateway (it was Using content filtering in order to moderate the traffic and using dns once i turned off that for all turned green and so far since last 3 hours its green.

            potemkin_aiP Offline
            potemkin_aiP Offline
            potemkin_ai
            wrote on last edited by
            #24

            @DualOSWinWiz would you mind elaborating how it affected you?

            1 Reply Last reply
            0
            • D Offline
              D Offline
              DualOSWinWiz
              wrote on last edited by
              #25

              so their is a separate feature in Unify gateway to filter content with options None, Work and Family i selected work. the problem was if you select either of Family or Work firewall was migrating traffic to be on open resolver regardless of Network settings. i turned off that feature and it worked out.

              1 Reply Last reply
              1
              • potemkin_aiP Offline
                potemkin_aiP Offline
                potemkin_ai
                wrote on last edited by
                #26

                @DualOSWinWiz , thank you!
                @girish , do you have some considerations, based on the information I've provided earlier?

                1 Reply Last reply
                1
                • jdaviescoatesJ jdaviescoates referenced this topic on
                • M Offline
                  M Offline
                  mmtrade
                  wrote on last edited by
                  #27

                  it never happened to me before..

                  i am not able to remove it because i need to send email directly from the server to unblock it

                  1 Reply Last reply
                  0
                  • jdaviescoatesJ Offline
                    jdaviescoatesJ Offline
                    jdaviescoates
                    wrote on last edited by
                    #28

                    @jdaviescoates said in URGENT:

                    In a post on an originally unrelated thread about IPv6 issues @Gengar posted this link https://www.spamhaus.com/resource-center/successfully-accessing-spamhauss-free-block-lists-using-a-public-dns/ which I think explains what's going on with all these false positive spamhaus issues people are having:

                    The TL;DR seems to be: fill in this form https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account/

                    I use Cloudron with Gandi & Hetzner

                    potemkin_aiP 1 Reply Last reply
                    1
                    • jdaviescoatesJ jdaviescoates

                      @jdaviescoates said in URGENT:

                      In a post on an originally unrelated thread about IPv6 issues @Gengar posted this link https://www.spamhaus.com/resource-center/successfully-accessing-spamhauss-free-block-lists-using-a-public-dns/ which I think explains what's going on with all these false positive spamhaus issues people are having:

                      The TL;DR seems to be: fill in this form https://www.spamhaus.com/free-trial/sign-up-for-a-free-data-query-service-account/

                      potemkin_aiP Offline
                      potemkin_aiP Offline
                      potemkin_ai
                      wrote on last edited by
                      #29

                      @jdaviescoates thank you! I will keep that as a final resort!

                      @girish , I would much appreciate any additional information to work-out those false positive alerts as they shall be handled - as I highlighted earlier, Ubuntu update doesn't seem to be relevant...

                      1 Reply Last reply
                      1
                      • potemkin_aiP potemkin_ai referenced this topic on
                      • J Offline
                        J Offline
                        joseph
                        Staff
                        wrote on last edited by
                        #30

                        I will close this thread and we can continue in the new one at https://forum.cloudron.io/topic/13531/can-t-install-cloudron-due-to-unbound-issues

                        1 Reply Last reply
                        0
                        • J joseph has marked this topic as solved on
                        • potemkin_aiP Offline
                          potemkin_aiP Offline
                          potemkin_ai
                          wrote on last edited by
                          #31

                          Those are two different issues actually.

                          1 Reply Last reply
                          0
                          • J Offline
                            J Offline
                            joseph
                            Staff
                            wrote on last edited by joseph
                            #32

                            OK, I don't really understand the difference entirely, but maybe others can help out. Will leave this as unsolved.

                            M 1 Reply Last reply
                            0
                            • J joseph has marked this topic as unsolved on
                            • potemkin_aiP Offline
                              potemkin_aiP Offline
                              potemkin_ai
                              wrote on last edited by
                              #33

                              This particular issue is due to the system's configuration which prevents correct spam resolution. Might be the root cause is one, but we can't be sure on that.

                              1 Reply Last reply
                              0
                              • J joseph

                                OK, I don't really understand the difference entirely, but maybe others can help out. Will leave this as unsolved.

                                M Offline
                                M Offline
                                mmtrade
                                wrote on last edited by
                                #34

                                @joseph do you think this issue is from the Ubuntu OS?

                                there are a lot off issues and why will your emails automatically stop sending. It gets disconnected entirely.

                                1 Reply Last reply
                                0
                                • potemkin_aiP potemkin_ai referenced this topic on
                                • J joseph has marked this topic as solved on
                                • C Offline
                                  C Offline
                                  ccfu
                                  wrote last edited by
                                  #35

                                  Since the update to 8.3.2 (on Ubuntu 24) I am seeing these false positives as well. Nothing has changed with the network settings or DNS. I know it is ultimately just a cosmetic problem, but it would be nice to be able to deactivate this check as it serves no real purpose in my opinion.

                                  potemkin_aiP 1 Reply Last reply
                                  0
                                  • C ccfu

                                    Since the update to 8.3.2 (on Ubuntu 24) I am seeing these false positives as well. Nothing has changed with the network settings or DNS. I know it is ultimately just a cosmetic problem, but it would be nice to be able to deactivate this check as it serves no real purpose in my opinion.

                                    potemkin_aiP Offline
                                    potemkin_aiP Offline
                                    potemkin_ai
                                    wrote last edited by
                                    #36

                                    @ccfu I can not agree on deactivate - the purpose is very useful. I would rather have it working properly!

                                    C 1 Reply Last reply
                                    0
                                    • potemkin_aiP potemkin_ai

                                      @ccfu I can not agree on deactivate - the purpose is very useful. I would rather have it working properly!

                                      C Offline
                                      C Offline
                                      ccfu
                                      wrote last edited by ccfu
                                      #37

                                      @potemkin_ai

                                      If it worked properly that would of course be better 😉

                                      If only one blocklist is being checked (Spamhaus) its purpose is, in my view, rather limited. In any case a failed check due to a connection error should not cause a notification that the mailboxes are not set up correctly and these mailboxes to be showing as red in the list.

                                      Edit: Connection errors happen with correct configuration when an ISP's DNS gets temporarily blocked by the DNSBL server. That seems to be my issue at the moment. In such cases I would like to be able to deactivate the check (even temporarily, for example 24 or 48 hours).

                                      1 Reply Last reply
                                      1
                                      • andreasduerenA Offline
                                        andreasduerenA Offline
                                        andreasdueren
                                        wrote last edited by
                                        #38

                                        Im having the same false positive issue. Do I have to read through this whole thread and the other one or is there a simple fix/do I just need to wait for an update?

                                        1 Reply Last reply
                                        1
                                        • girishG Offline
                                          girishG Offline
                                          girish
                                          Staff
                                          wrote last edited by
                                          #39

                                          I have a task to make this check more "stable" for next release. Currently, it just shows the message on a single failure . I will fix the code to make it show when the error is more persistent (i.e over several failures or something like that).

                                          C 1 Reply Last reply
                                          1
                                          • girishG girish

                                            I have a task to make this check more "stable" for next release. Currently, it just shows the message on a single failure . I will fix the code to make it show when the error is more persistent (i.e over several failures or something like that).

                                            C Offline
                                            C Offline
                                            ccfu
                                            wrote last edited by ccfu
                                            #40

                                            @girish That would be a big help for sure, but would it not make more sense to differentiate between connection failure and actual confirmed presence on the blocklist?

                                            At the moment it seems to check every 30 minutes and if the DNS server has been blocked (e.g. for overuse of queries) this is likely to persist for 24 - 48 hours at least.

                                            girishG 1 Reply Last reply
                                            0
                                            Reply
                                            • Reply as topic
                                            Log in to reply
                                            • Oldest to Newest
                                            • Newest to Oldest
                                            • Most Votes


                                              • Login

                                              • Don't have an account? Register

                                              • Login or register to search.
                                              • First post
                                                Last post
                                              0
                                              • Categories
                                              • Recent
                                              • Tags
                                              • Popular
                                              • Bookmarks
                                              • Search