<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs?]]></title><description><![CDATA[<p dir="auto">I keep seeing this message recently (a bit ago it was several different attempts in less than 10 minutes for the same domain, image below) and it seems to be growing in popularity in the logs over the past month or so, today in particular seems extra bad. I know the SPF record for the domain in question is correct.</p>
<p dir="auto">The IP addresses are different but similar in range, and I see them on the blacklists check too so they're definitely spammy IPs.</p>
<p dir="auto"><img src="/assets/uploads/files/1617146256717-f22b6787-a5b4-49e5-b2d2-3871f6ea4302-image-resized.png" alt="f22b6787-a5b4-49e5-b2d2-3871f6ea4302-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Here is the top example:</p>
<pre><code>{
  "ts": 1617145926606,
  "type": "denied",
  "direction": "inbound",
  "uuid": "5D744873-5B50-49C7-A471-8E4DCFB5961B.1",
  "remote": {
    "ip": "114.99.130.140",
    "port": 57217,
    "host": "NXDOMAIN",
    "info": "NXDOMAIN",
    "closed": false,
    "is_private": false,
    "is_local": false
  },
  "authUser": null,
  "mailFrom": "&lt;{username}@{MyClientsHostedDomainOnCloudronServer}&gt;",
  "rcptTo": [],
  "details": {
    "relaying": false,
    "pluginName": "rcpt_to.in_host_list",
    "errorCode": 902,
    "message": "Mail from domain 'drjaver.com' is not allowed from your host",
    "rejectionCountLastHour": 0
  }
}
</code></pre>
<p dir="auto">I found this in the Haraka docs: <a href="https://github.com/haraka/Haraka/blob/master/docs/plugins/rcpt_to.in_host_list.md" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/haraka/Haraka/blob/master/docs/plugins/rcpt_to.in_host_list.md</a></p>
<p dir="auto">I just want to make sure I understand the workflow here. I believe the issue here is somebody is trying to spoof the email address of an email address I host on my mail server, coming from some spammy IP. Is that correct?</p>
<p dir="auto">I guess if that's correct then there's not much I can do though here except try and report the spam to the abuse@ contacts for the network, which doesn't really do anything in most cases anyways. Or I guess just outright block the IPs from my server completely.</p>
<p dir="auto">I'm curious though too why there's no value for <code>rcptTo</code>, is that expected behaviour? It almost makes it look like there's an email address sent to no particular email address, which can't be right.</p>
<p dir="auto">I ultimately am wanting to understand:</p>
<ol>
<li>If others have seen an increase in this type of spam caught by Haraka in Cloudron</li>
<li>If I understand the workflow correctly in that it's an incoming spam message pretending to be from an email address domain I host which means per the SPF record it cannot possibly come from the originating IP so gets denied... right? The lack of a <code>rcptTo</code> in particular confuses me though.</li>
</ol>
]]></description><link>https://forum.cloudron.io/topic/4795/anyone-else-see-many-connections-denied-due-to-mail-from-domain-domain-is-not-allowed-from-your-host-repeatedly-from-spammy-ips</link><generator>RSS for Node</generator><lastBuildDate>Sat, 13 Jun 2026 12:53:59 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/4795.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 30 Mar 2021 23:35:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 27 Oct 2023 14:17:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/76160">Anyone else see many connections denied due to "Mail from domain &lt;domain&gt; is not allowed from your host" repeatedly from spammy IPs?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/necrevistonnezr" aria-label="Profile: necrevistonnezr">@<bdi>necrevistonnezr</bdi></a> Ah, sorry! I misread. In my case, the sender is just spamming the hell out of me for video content. Sender is not trying to spoof. I guess you have to block by IP in the network firewall.</p>
</blockquote>
<p dir="auto">Yeah, well, those IPs are never the same (see above) and even ranges are difficult to ascertain. Maybe an easy way to subscribe to a blocklist would help? <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> (as suggested in my old topic linked above…)</p>
]]></description><link>https://forum.cloudron.io/post/76161</link><guid isPermaLink="true">https://forum.cloudron.io/post/76161</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Fri, 27 Oct 2023 14:17:50 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 27 Oct 2023 14:15:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/necrevistonnezr" aria-label="Profile: necrevistonnezr">@<bdi>necrevistonnezr</bdi></a> Ah, sorry! I misread. In my case, the sender is just spamming the hell out of me for video content. Sender is not trying to spoof. I guess you have to block by IP in the network firewall.</p>
]]></description><link>https://forum.cloudron.io/post/76160</link><guid isPermaLink="true">https://forum.cloudron.io/post/76160</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 27 Oct 2023 14:15:26 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 27 Oct 2023 14:16:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/76135">Anyone else see many connections denied due to "Mail from domain &lt;domain&gt; is not allowed from your host" repeatedly from spammy IPs?</a>:</p>
<blockquote>
<p dir="auto">You can block by sender name. In my case, i have this advid guy who is really really persistent.</p>
<p dir="auto"><img src="/assets/uploads/files/1698401303121-4232d881-8648-496b-b45d-b7e026b00c9d-image.png" alt="image.png" class=" img-fluid img-markdown" /></p>
</blockquote>
<p dir="auto">The addresses you listed: Are those the ones the sender is trying to send as (i.e. the one showing up as  <code>“mailFrom:“</code> in the mail event log entry?</p>
]]></description><link>https://forum.cloudron.io/post/76157</link><guid isPermaLink="true">https://forum.cloudron.io/post/76157</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Fri, 27 Oct 2023 14:16:16 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 27 Oct 2023 14:02:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> said in <a href="/post/76130">Anyone else see many connections denied due to "Mail from domain &lt;domain&gt; is not allowed from your host" repeatedly from spammy IPs?</a>:</p>
<blockquote>
<p dir="auto">Yes, there is a "network block"/filter in the UI. Just paste the networks and IPs like you have in that list.</p>
<p dir="auto">There are other forum posts with that " " search term above.</p>
</blockquote>
<p dir="auto">I know, I even linked <em>my</em> topic on the matter. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=";)" alt="😉" /></p>
<p dir="auto">But currently, we don’t have a way to subscribe to- regularly updated- IP blocklists; and <em>manually</em> going through each blocked sending attempt and then copy&amp;paste some IP (fruitless) or figuring out the relevant IP range doesn’t seem „comfortable“ or „sensible“ (to quote myself)…<br />
And I thought there might even be some other way I‘m not aware of (e.g. spam filter rule)</p>
]]></description><link>https://forum.cloudron.io/post/76155</link><guid isPermaLink="true">https://forum.cloudron.io/post/76155</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Fri, 27 Oct 2023 14:02:34 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 27 Oct 2023 10:08:28 GMT]]></title><description><![CDATA[<p dir="auto">You can block by sender name. In my case, i have this advid guy who is really really persistent.</p>
<p dir="auto"><img src="/assets/uploads/files/1698401303121-4232d881-8648-496b-b45d-b7e026b00c9d-image.png" alt="image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.cloudron.io/post/76135</link><guid isPermaLink="true">https://forum.cloudron.io/post/76135</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 27 Oct 2023 10:08:28 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 27 Oct 2023 09:24:18 GMT]]></title><description><![CDATA[<p dir="auto">Yes, there is a "network block"/filter in the UI. Just paste the networks and IPs like you have in that list.</p>
<p dir="auto">There are other forum posts with that " " search term above.</p>
]]></description><link>https://forum.cloudron.io/post/76130</link><guid isPermaLink="true">https://forum.cloudron.io/post/76130</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Fri, 27 Oct 2023 09:24:18 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 27 Oct 2023 06:01:52 GMT]]></title><description><![CDATA[<p dir="auto">I see the same behavior- someone is permanently trying to send as one <em>specific</em> sender (<a href="mailto:specificname@domain.com" target="_blank" rel="noopener noreferrer nofollow ugc">specificname@domain.com</a>) from IPs such as:</p>
<pre><code>2.133.95.174 
2.135.199.137

5.126.117.216

31.169.30.190

89.237.194.133

91.98.60.233

103.234.25.66
103.71.59.198

113.185.92.35

125.212.159.28
125.212.158.246

149.54.6.150

178.217.173.123

195.158.14.27

213.230.96.66
213.230.92.146
213.230.126.9
213.230.80.33
213.230.93.109

217.29.22.198
</code></pre>
<p dir="auto">Is there any „comfortable“ or sensible way to block this?</p>
<p dir="auto">In this context I just remembered: <a href="https://forum.cloudron.io/topic/3795/">https://forum.cloudron.io/topic/3795/</a></p>
]]></description><link>https://forum.cloudron.io/post/76108</link><guid isPermaLink="true">https://forum.cloudron.io/post/76108</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Fri, 27 Oct 2023 06:01:52 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Fri, 02 Apr 2021 05:17:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/29060">Anyone else see many connections denied due to "Mail from domain &lt;domain&gt; is not allowed from your host" repeatedly from spammy IPs?</a>:</p>
<blockquote>
<p dir="auto">A bit of a wild guess: mail from is usually &lt;&gt;  for bounce mail. So, this seems like some poor denial of service or maybe those IPs know that some mail software misbehaves with such carefully crafted mail.</p>
</blockquote>
<p dir="auto">Ah very interesting, I appreciate that insight. It was definitely strange when I saw it happening - so many requests at once. I'll keep an eye out for it. Sounds like it's all good then as far as Cloudron is concerned. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=13d69e59554" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /> Thanks Girish.</p>
]]></description><link>https://forum.cloudron.io/post/29070</link><guid isPermaLink="true">https://forum.cloudron.io/post/29070</guid><dc:creator><![CDATA[d19dotca]]></dc:creator><pubDate>Fri, 02 Apr 2021 05:17:06 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Thu, 01 Apr 2021 23:44:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/d19dotca" aria-label="Profile: d19dotca">@<bdi>d19dotca</bdi></a> said in <a href="/post/28941">Anyone else see many connections denied due to "Mail from domain &lt;domain&gt; is not allowed from your host" repeatedly from spammy IPs?</a>:</p>
<blockquote>
<p dir="auto">I just want to make sure I understand the workflow here. I believe the issue here is somebody is trying to spoof the email address of an email address I host on my mail server, coming from some spammy IP. Is that correct?</p>
</blockquote>
<p dir="auto">I think your analysis is correct. Someone is trying to send mails to Cloudron, with FROM address set to a domain that you host. Cloudron then rejects it saying this is not allowed because after all only itself and other SPF listed servers can send mail with that FROM address.</p>
<p dir="auto">A bit of a wild guess: mail from is usually <code>&lt;&gt;</code>  for bounce mail. So, this seems like some poor denial of service or maybe those IPs know that some mail software misbehaves with such carefully crafted mail.</p>
]]></description><link>https://forum.cloudron.io/post/29060</link><guid isPermaLink="true">https://forum.cloudron.io/post/29060</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Thu, 01 Apr 2021 23:44:42 GMT</pubDate></item><item><title><![CDATA[Reply to Anyone else see many connections denied due to &quot;Mail from domain &lt;domain&gt; is not allowed from your host&quot; repeatedly from spammy IPs? on Wed, 31 Mar 2021 00:09:49 GMT]]></title><description><![CDATA[<p dir="auto">To give a better idea of the extent of this for my mail server... this is how much of this I've seen just in the last hour for the same domain. Almost every IP I looked up is coming from the same ASN <code>#4134 - Asia Pacific Network Information Centre</code>. This is far from the usual (I'll maybe see this between 2 and 10 times a day, not almost 40 in a single hour). Looks like the "attack" started about 3 hours ago when I go further back in the logs. Seems the Haraka engine is doing fine though, I hope this doesn't impact my other clients on the same server email-wise. Should be okay, plenty of memory available anyways.</p>
<p dir="auto">I'd normally try to just revoke the IP CIDR range, but when I look it up the one has over 2 million IPs in the CIDR and since about 20% of the traffic to three different client's websites comes from China for business (COVID-19 testing for essential travel), I don't think I can outright block the ASN (yet) unfortunately.</p>
<p dir="auto"><img src="/assets/uploads/files/1617148041200-3af09429-cc8b-4747-9dd3-0780d2a68f66-image-resized.png" alt="3af09429-cc8b-4747-9dd3-0780d2a68f66-image.png" class=" img-fluid img-markdown" /></p>
<hr />
<p dir="auto">EDIT: I decided to block at the IP level for now but did some CIDR calculations to have less false-positives. Blocked the following ranges temporarily (I'll remove them tomorrow and see if the issue continues):</p>
<p dir="auto">60.167.0.0/17<br />
114.99.128.0/21<br />
223.241.48.0/20</p>
]]></description><link>https://forum.cloudron.io/post/28942</link><guid isPermaLink="true">https://forum.cloudron.io/post/28942</guid><dc:creator><![CDATA[d19dotca]]></dc:creator><pubDate>Wed, 31 Mar 2021 00:09:49 GMT</pubDate></item></channel></rss>