Mailing List Archive

[Bug 3042] EXim closes connection direct after end of DATA (.)
https://bugs.exim.org/show_bug.cgi?id=3042

--- Comment #1 from Lars Timmann <lt@timmann.de> ---
Disabling chunking (switching from BDATA to DATA) did not change anything:
chunking_advertise_hosts = ""

Just to let you know...

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
[Bug 3042] EXim closes connection direct after end of DATA (.) [ In reply to ]
https://bugs.exim.org/show_bug.cgi?id=3042

Lars Timmann <lt@timmann.de> changed:

What |Removed |Added
----------------------------------------------------------------------------
Hardware|Sun |x86-64

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
[Bug 3042] EXim closes connection direct after end of DATA (.) [ In reply to ]
https://bugs.exim.org/show_bug.cgi?id=3042

Lars Timmann <lt@timmann.de> changed:

What |Removed |Added
----------------------------------------------------------------------------
Priority|medium |high

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
[Bug 3042] EXim closes connection direct after end of DATA (.) [ In reply to ]
https://bugs.exim.org/show_bug.cgi?id=3042

--- Comment #2 from Jeremy Harris <jgh146exb@wizmail.org> ---
What does debug show?

https://exim.org/exim-html-current/doc/html/spec_html/ch-the_exim_command_line.html#SECID39

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
[Bug 3042] EXim closes connection direct after end of DATA (.) [ In reply to ]
https://bugs.exim.org/show_bug.cgi?id=3042

--- Comment #3 from Lars Timmann <lt@timmann.de> ---
I can add more debugging output on monday as I does not have direct access to
the systems.

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
[Bug 3042] EXim closes connection direct after end of DATA (.) [ In reply to ]
https://bugs.exim.org/show_bug.cgi?id=3042

--- Comment #4 from Lars Timmann <lt@timmann.de> ---
We catched one problematic mail.

This mail hangs on our external mail server and is not delivered to our
internal mailserver. Both updated to exim-4.96.2. As it is obviously spam we
could show all data:

# exim -Mvl 1qxQSQ-0000I8-1U
2023-10-30 12:29:22.160 Received from admin@genarec.com H=sophosxgs.domain.tld
[192.168.104.42]:45786 I=[192.168.104.33]:25 P=esmtps L.
X=TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256 CV=no S=4191 M8S=0 RT=0.001s
id=20231030112909.0E44C3A2DFE35454@genarec.com T="Business investment"
2023-10-30 12:29:22.430 H=mail.domain.tld [192.168.9.2]:25: Remote host closed
connection in response to end of data
2023-10-30 12:29:22.644 H=mail.domain.tld [192.168.9.100]:25: Remote host
closed connection in response to end of data
2023-10-30 12:29:22.646 user@domain.tld R=mail_route T=remote_smtp defer (-18)
H=mail.domain.tld [192.168.9.100]:25 I=[192.168.104.33]:61120 DT=0.213s: Remote
host closed connection in response to end of data
2023-10-30 12:30:03.901 H=mail.domain.tld [192.168.9.100]:25: Remote host
closed connection in response to end of data
2023-10-30 12:30:04.201 H=mail.domain.tld [192.168.9.2]:25: Remote host closed
connection in response to end of data
2023-10-30 12:30:04.203 user@domain.tld R=mail_route T=remote_smtp defer (-18)
H=mail.domain.tld [192.168.9.2]:25 I=[192.168.104.33]:53387 DT=0.298s: Remote
host closed connection in response to end of data
...
And so on...

# exim -Mvh 1qxQSQ-0000I8-1U
1qxQSQ-0000I8-1U-H
exim 100 100
<admin@genarec.com>
1698665362 0
-received_time_usec .157578
-received_time_complete 1698665362.159479
--helo_name sophosxgs.domain.tld
-host_address [192.168.104.42]:45786
--host_name sophosxgs.domain.tld
-interface_address [192.168.104.33]:25
-received_protocol esmtps
-aclm _linelength_limit 3
998
-body_linecount 10
-max_received_linelength 92
-tls_cipher TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256
-tls_ourcert -----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----\n
-tls_resumption B
-tls_ver TLS1.2
XX
1
user@domain.tld

298P Received: from sophosxgs.domain.tld ([192.168.104.42]:45786)
by MailExt1.domain.tld with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.96.2)
(envelope-from <admin@genarec.com>)
id 1qxQSQ-0000I8-1U
for user@domain.tld;
Mon, 30 Oct 2023 12:29:22 +0100
325P Received: from mailext.domain.tld ([192.168.104.34]:42831
helo=MailExt2.domain.tld)
by sophosxgs.domain.tld with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.96)
(envelope-from <admin@genarec.com>)
id 1qxQSG-0001T1-2t
for user@domain.tld;
Mon, 30 Oct 2023 12:29:12 +0100
320P Received: from hwsrv-1105621.hostwindsdns.com ([192.168.216.93]:44389
helo=genarec.com)
by MailExt2.MH-Hannover.DE with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.96.2)
(envelope-from <admin@genarec.com>)
id 1qxQSG-0006Vl-37
for user@domain.tld;
Mon, 30 Oct 2023 12:29:12 +0100
038R Reply-To: alamoudimohammad5@gmail.com
065F From: Password Notification <anxjf<info@genarec.com>
033T To: user@domain.tld
029 Subject: Business investment
033 Date: 30 Oct 2023 11:29:10 +0000
058I Message-ID: <20231030112909.0E44C3A2DFE35454@genarec.com>
018 MIME-Version: 1.0
024 Content-Type: text/html
044 Content-Transfer-Encoding: quoted-printable
022 X-Sophos-IBS: success
072 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 192.168.30.105116
018 X-SASI-RCODE: 200
028 X-SASI-SpamProbability: 30%
2142 X-SASI-Hits: BODYTEXTH_SIZE_10000_LESS 0.000000, BODY_SIZE_1000_LESS
0.000000,
BODY_SIZE_2000_LESS 0.000000, BODY_SIZE_5000_LESS 0.000000,
BODY_SIZE_500_599 0.000000, BODY_SIZE_7000_LESS 0.000000,
CTE_QUOTED_PRINTABLE 0.000000, CTYPE_JUST_HTML 0.500000,
FRAUD_WEBMAIL_R_NOT_F 0.100000, FRAUD_X3 1.000000, FROM_NAME_PHRASE 0.000000,
HREF_LABEL_TEXT_NO_URI 0.000000, HREF_LABEL_TEXT_ONLY 0.000000,
HTML_NO_HTTP 0.100000, KNOWN_MTA_TFX 0.000000, NO_CTA_URI_FOUND 0.000000,
NO_URI_HTTPS 0.000000, RCVD_EXIM_IP_PORT 1.000000,
REPLYTO_FROM_DIFF_ADDY 0.100000, SENDER_NO_AUTH 0.000000,
SINGLE_HREF_URI_IN_BODY 0.000000, SXL_IP_TFX_WM 0.000000,
TO_DOMAIN_IN_FROMNAME_NOT_SAME 0.000000, TO_DOMAIN_IN_FROM_NOT_SAME 0.000000,
WEBMAIL_REPLYTO_NOT_FROM 0.500000, __ANY_URI 0.000000,
__BODY_TEXT_X4 0.000000, __CSHC_NS_B_FN_FA 0.000000, __CT 0.000000,
__CTE 0.000000, __CTYPE_HTML 0.000000, __CTYPE_IS_HTML 0.000000,
__DC_PHRASE 0.000000, __FRAUD_BODY_WEBMAIL 0.000000, __FRAUD_COMMON 0.000000,
__FRAUD_INTRO 0.000000, __FRAUD_REPLY 0.000000, __FRAUD_URGENCY 0.000000,
__FRAUD_WEBMAIL 0.000000, __FRAUD_WEBMAIL_REPLYTO 0.000000,
__FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000,
__FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000,
__HAS_HTML 0.000000, __HAS_MSGID 0.000000, __HAS_REPLYTO 0.000000,
__HEADER_ORDER_FROM 0.000000, __HREF_LABEL_TEXT 0.000000,
__HTML_AHREF_TAG 0.000000, __MIME_HTML 0.000000, __MIME_HTML_ONLY 0.000000,
__MIME_TEXT_H 0.000000, __MIME_TEXT_H1 0.000000, __MIME_VERSION 0.000000,
__MSGID_DATETIME_DOT_HEX16 0.000000, __PART_TYPE_HTML 0.000000,
__PHISH_SPEAR_GREETING 0.000000, __RCPT_HOST_IN_FROM 0.000000,
__RCPT_HOST_IN_FROM_NAME 0.000000, __RCVD_EXIM_IP_PORT 0.000000,
__REPLYTO_GMAIL 0.000000, __SANE_MSGID 0.000000, __SEO_WEBSITE 0.000000,
__SPEAR_FROM_NAME 0.000000, __STOCK_PHRASE_8 0.000000,
__SUBJ_ALPHA_END 0.000000, __SUBJ_SHORT 0.000000, __TAG_EXISTS_HTML 0.000000,
__TO_HOST_IN_FROM 0.000000, __TO_HOST_IN_FROM_NAME 0.000000,
__TO_MALFORMED_2 0.000000, __TO_NO_NAME 0.000000, __URI_MAILTO 0.000000,
__URI_NO_WWW 0.000000, __URI_NS 0.000000
030 X-Sophos-Firewall: smtpd v1.0

# exim -Mvb 1qxQSQ-0000I8-1U
1qxQSQ-0000I8-1U-D
<html><head>
<meta http-equiv=3D"X-UA-Compatible" content=3D"IE=3Dedge">
</head>
<body><p>Dear Sir Madam,</p><p>My name is Mohammed Al Amoudi from the Kingd=
om of Saudi Arabia.</p><p>I contacted you because of my interest in your se=
ctor.</p><p>We would like to get an idea of the chances of a successful inv=
estment in your area and for other important business discussions.</p><p>I =
await your urgent response.</p><p>Reply to email address for further discus=
sions <a href=3D"mailto:&#8220;alamoudimohammad5@gmail.com">&#8220;alamoudi=
mohammad5@gmail.com</a>&#8221;</p></body></html>

On the internal mail server we just see:

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
[Bug 3042] EXim closes connection direct after end of DATA (.) [ In reply to ]
https://bugs.exim.org/show_bug.cgi?id=3042

--- Comment #5 from Lars Timmann <lt@timmann.de> ---
# exim -d+all -M 1qxQSQ-0000I8-1U
14:01:19 28661 Exim version 4.96.2 uid=0 gid=0 pid=28661 D=fff9ffff
14:01:19 28661 Support for: iconv() Expand_dlfunc OpenSSL TLS_resume
Content_Scanning DANE DKIM DNSSEC Event OCSP PIPECONNECT PRDR Queue_Ramp
14:01:19 28661 Lookups (built-in):
14:01:19 28661 Authenticators:
14:01:19 28661 Routers: accept dnslookup ipliteral manualroute queryprogram
redirect
14:01:19 28661 Transports: appendfile autoreply lmtp pipe smtp
14:01:19 28661 Malware: f-protd f-prot6d drweb fsecure sophie clamd avast sock
cmdline
14:01:19 28661 Fixed never_users: 0
14:01:19 28661 Configure owner: 0:0
14:01:19 28661 Size of off_t: 8
14:01:19 28661 Compiler: GCC [12.2.0]
14:01:19 28661 Probably GDBM (native mode)
14:01:19 28661 Library version: OpenSSL: Compile: OpenSSL 1.0.2zg 7 Feb 2023
14:01:19 28661 Runtime: OpenSSL 1.0.2zg 7 Feb 2023
14:01:19 28661 : built on: date not available
14:01:19 28661 Library version: PCRE2: Compile: 10.40
14:01:19 28661 Runtime: 10.40 2022-04-14
14:01:19 28661 Loading lookup modules from /opt/exim/lookups/
14:01:19 28661 Loaded "dsearch.so" (1 lookup types)
14:01:19 28661 Loaded "dnsdb.so" (1 lookup types)
14:01:19 28661 Loaded "lsearch.so" (4 lookup types)
14:01:19 28661 Loaded "dbmdb.so" (3 lookup types)
14:01:19 28661 Loaded 4 lookup modules
14:01:19 28661 Total 10 lookups
14:01:19 28661 Library version: DBM: Exim version 4.96.2
14:01:19 28661 Library version: DNSDB: Exim version 4.96.2
14:01:19 28661 Library version: dsearch: Exim version 4.96.2
14:01:19 28661 Library version: lsearch: Exim version 4.96.2
14:01:19 28661 WHITELIST_D_MACROS unset
14:01:19 28661 TRUSTED_CONFIG_LIST unset
14:01:19 28661 changed uid/gid: forcing real = effective
14:01:19 28661 uid=0 gid=0 pid=28661
14:01:19 28661 auxiliary group list: <none>
14:01:19 28661 seeking password data for user "root": cache not available
14:01:19 28661 getpwnam() succeeded uid=0 gid=0
14:01:19 28661 seeking password data for user "daemon": cache not available
14:01:19 28661 getpwnam() succeeded uid=1 gid=1
14:01:19 28661 seeking password data for user "bin": cache not available
14:01:19 28661 getpwnam() succeeded uid=2 gid=2
14:01:19 28661 seeking password data for user "root": cache not available
14:01:19 28661 getpwnam() succeeded uid=0 gid=0
14:01:19 28661 seeking password data for user "exim": cache not available
14:01:19 28661 getpwnam() succeeded uid=100 gid=100
14:01:19 28661 openssl option, adding to 03104000: 01000000 (no_sslv2
+no_sslv3 +no_tlsv1 +no_tlsv1_1 +cipher_server_preference)
14:01:19 28661 openssl option, adding to 03104000: 02000000 (no_sslv3
+no_tlsv1 +no_tlsv1_1 +cipher_server_preference)
14:01:19 28661 openssl option, adding to 03104000: 04000000 (no_tlsv1
+no_tlsv1_1 +cipher_server_preference)
14:01:19 28661 openssl option, adding to 07104000: 10000000 (no_tlsv1_1
+cipher_server_preference)
14:01:19 28661 openssl option, adding to 17104000: 00400000
(cipher_server_preference)
14:01:19.040 28661 configuration file is /etc/exim/exim.conf
14:01:19.040 28661 log selectors = ffffffff ffffffff ffffffff
14:01:19.040 28661 LOG: MAIN
14:01:19.040 28661 cwd=/root 4 args: exim -d+all -M 1qxQSQ-0000I8-1U
14:01:19.045 28661 trusted user
14:01:19.045 28661 admin user
14:01:19.045 28661 dropping to exim gid; retaining priv uid
14:01:19.045 28661 set_process_info: 28661 delivering specified messages
14:01:19.045 28661 set_process_info: 28661 delivering 1qxQSQ-0000I8-1U
14:01:19.045 28661 Trying spool file
/var/spool/exim//input/Q/1qxQSQ-0000I8-1U-D
14:01:19.045 28661 reading spool file 1qxQSQ-0000I8-1U-H
14:01:19.045 28661 user=exim uid=100 gid=100 sender=admin@genarec.com
14:01:19.046 28661 sender_fullhost = sophosxgs.domain.tld
[192.168.104.42]:45786
14:01:19.046 28661 sender_rcvhost = sophosxgs.domain.tld
([192.168.104.42]:45786)
14:01:19.046 28661 sender_local=0 ident=unset
14:01:19.046 28661 Non-recipients:
14:01:19.046 28661 Empty Tree
14:01:19.046 28661 ---- End of tree ----
14:01:19.046 28661 recipients_count=1
14:01:19.046 28661 **** SPOOL_IN - No additional fields
14:01:19.046 28661 body_linecount=10 message_linecount=67
14:01:19.046 28661 DSN: set orcpt: flags: 0x0
14:01:19.046 28661 Delivery address list:
14:01:19.046 28661 user@domain.tld
14:01:19.046 28661 locking /var/spool/exim/db/retry.lockfile
14:01:19.046 28661 locked /var/spool/exim/db/retry.lockfile
14:01:19.046 28661 EXIM_DBOPEN: file </var/spool/exim/db/retry> dir
</var/spool/exim/db> flags=O_RDONLY
14:01:19.047 28661 returned from EXIM_DBOPEN: 69cf10
14:01:19.047 28661 opened hints database /var/spool/exim/db/retry:
flags=O_RDONLY
14:01:19.047 28661 >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
14:01:19.047 28661 Considering: user@domain.tld
14:01:19.047 28661 unique = user@domain.tld
14:01:19.047 28661 dbfn_read: key=R:domain.tld
14:01:19.047 28661 dbfn_read: key=R:user@domain.tld
14:01:19.047 28661 dbfn_read: key=R:user@domain.tld:<admin@genarec.com>
14:01:19.048 28661 no domain retry record
14:01:19.048 28661 no address retry record
14:01:19.048 28661 user@domain.tld: queued for routing
14:01:19.048 28661 EXIM_DBCLOSE(69cf10)
14:01:19.048 28661 closed hints database and lockfile
14:01:19.048 28661 >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
14:01:19.048 28661 routing user@domain.tld
14:01:19.048 28661 --------> send_to_sophos_with_dkim router <--------
14:01:19.048 28661 local_part=user domain=domain.tld
14:01:19.048 28661 checking senders
14:01:19.048 28661 address match test: subject=admin@genarec.com
pattern=*@domain.tld
14:01:19.048 28661 genarec.com in "domain.tld"? no (end of list)
14:01:19.048 28661 address match test: subject=admin@genarec.com
pattern=bla@blub.tld
14:01:19.048 28661 admin@genarec.com in "*@domain.tld : !bla@blub.tld"? yes
(end of list)
14:01:19.048 28661 checking "condition" "${if or {{eq
{$sender_host_address}{192.168.104.40}} {eq {$sender_host_address}{"...
14:01:19.048 28661 ?considering: ${if or {{eq
{$sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ?considering: $sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ?considering: }{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ???expanding: $sender_host_address
14:01:19.048 28661 ??????result: 192.168.104.42
14:01:19.048 28661 ?considering: 192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ????????text: 192.168.104.40
14:01:19.048 28661 ?considering: }} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ???expanding: 192.168.104.40
14:01:19.048 28661 ??????result: 192.168.104.40
14:01:19.048 28661 ?considering: $sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ?considering: }{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ???expanding: $sender_host_address
14:01:19.048 28661 ??????result: 192.168.104.42
14:01:19.048 28661 ?considering: 192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ????????text: 192.168.104.41
14:01:19.048 28661 ?considering: }} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ???expanding: 192.168.104.41
14:01:19.048 28661 ??????result: 192.168.104.41
14:01:19.048 28661 ?considering: $sender_host_address}{192.168.104.42}}
}{no}{yes}}
14:01:19.048 28661 ?considering: }{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ???expanding: $sender_host_address
14:01:19.048 28661 ??????result: 192.168.104.42
14:01:19.048 28661 ?considering: 192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ????????text: 192.168.104.42
14:01:19.048 28661 ?considering: }} }{no}{yes}}
14:01:19.048 28661 ???expanding: 192.168.104.42
14:01:19.048 28661 ??????result: 192.168.104.42
14:01:19.048 28661 ???condition: or {{eq
{$sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }
14:01:19.048 28661 ??????result: true
14:01:19.048 28661 ?considering: no}{yes}}
14:01:19.048 28661 ????????text: no
14:01:19.048 28661 ?considering: }{yes}}
14:01:19.048 28661 ???expanding: no
14:01:19.048 28661 ??????result: no
14:01:19.048 28661 ????scanning: yes}}
14:01:19.048 28661 ????????text: yes
14:01:19.048 28661 ????scanning: }}
14:01:19.048 28661 ???expanding: yes
14:01:19.048 28661 ??????result: yes
14:01:19.048 28661 ????skipping: result is not used
14:01:19.048 28661 ???expanding: ${if or {{eq
{$sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ??????result: no
14:01:19.048 28661 send_to_sophos_with_dkim router skipped: condition failure
14:01:19.048 28661 --------> send_to_sophos router <--------
14:01:19.048 28661 local_part=user domain=domain.tld
14:01:19.048 28661 checking senders
14:01:19.048 28661 address match test: subject=admin@genarec.com
pattern=bla@blub.tld
14:01:19.048 28661 admin@genarec.com in "!bla@blub.tld"? yes (end of list)
14:01:19.048 28661 checking "condition" "${if or {{eq
{$sender_host_address}{192.168.104.40}} {eq {$sender_host_address}{"...
14:01:19.048 28661 ?considering: ${if or {{eq
{$sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ?considering: $sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ?considering: }{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ???expanding: $sender_host_address
14:01:19.048 28661 ??????result: 192.168.104.42
14:01:19.048 28661 ?considering: 192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ????????text: 192.168.104.40
14:01:19.048 28661 ?considering: }} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.048 28661 ???expanding: 192.168.104.40
14:01:19.049 28661 ??????result: 192.168.104.40
14:01:19.049 28661 ?considering: $sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.049 28661 ?considering: }{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.049 28661 ???expanding: $sender_host_address
14:01:19.049 28661 ??????result: 192.168.104.42
14:01:19.049 28661 ?considering: 192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.049 28661 ????????text: 192.168.104.41
14:01:19.049 28661 ?considering: }} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.049 28661 ???expanding: 192.168.104.41
14:01:19.049 28661 ??????result: 192.168.104.41
14:01:19.049 28661 ?considering: $sender_host_address}{192.168.104.42}}
}{no}{yes}}
14:01:19.049 28661 ?considering: }{192.168.104.42}} }{no}{yes}}
14:01:19.049 28661 ???expanding: $sender_host_address
14:01:19.049 28661 ??????result: 192.168.104.42
14:01:19.049 28661 ?considering: 192.168.104.42}} }{no}{yes}}
14:01:19.049 28661 ????????text: 192.168.104.42
14:01:19.049 28661 ?considering: }} }{no}{yes}}
14:01:19.049 28661 ???expanding: 192.168.104.42
14:01:19.049 28661 ??????result: 192.168.104.42
14:01:19.049 28661 ???condition: or {{eq
{$sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }
14:01:19.049 28661 ??????result: true
14:01:19.049 28661 ?considering: no}{yes}}
14:01:19.049 28661 ????????text: no
14:01:19.049 28661 ?considering: }{yes}}
14:01:19.049 28661 ???expanding: no
14:01:19.049 28661 ??????result: no
14:01:19.049 28661 ????scanning: yes}}
14:01:19.049 28661 ????????text: yes
14:01:19.049 28661 ????scanning: }}
14:01:19.049 28661 ???expanding: yes
14:01:19.049 28661 ??????result: yes
14:01:19.049 28661 ????skipping: result is not used
14:01:19.049 28661 ???expanding: ${if or {{eq
{$sender_host_address}{192.168.104.40}} {eq
{$sender_host_address}{192.168.104.41}} {eq
{$sender_host_address}{192.168.104.42}} }{no}{yes}}
14:01:19.049 28661 ??????result: no
14:01:19.049 28661 send_to_sophos router skipped: condition failure
14:01:19.049 28661 --------> inst_route router <--------
14:01:19.049 28661 local_part=user domain=domain.tld
14:01:19.049 28661 checking domains
14:01:19.049 28661 domain.tld in "domain.tld"? yes (matched "domain.tld")
14:01:19.049 28661 checking local_parts
14:01:19.049 28661 user in "*"? yes (matched "*")
14:01:19.049 28661 calling inst_route router
14:01:19.049 28661 inst_route router called for user@domain.tld
14:01:19.049 28661 domain = domain.tld
14:01:19.049 28661 route_item = * mail.domain.tld
14:01:19.049 28661 domain.tld in "*"? yes (matched "*")
14:01:19.049 28661 original list of hosts = 'mail.domain.tld' options = ''
14:01:19.049 28661 expanded list of hosts = 'mail.domain.tld' options = ''
14:01:19.049 28661 set transport remote_smtp
14:01:19.049 28661 finding IP address for mail.domain.tld
14:01:19.049 28661 doing DNS lookup
14:01:19.049 28661 mail.domain.tld in "*"? yes (matched "*")
14:01:19.051 28661 DNS lookup of mail.domain.tld (A) succeeded
14:01:19.051 28661 DNS lookup of mail.domain.tld (A/AAAA) requested AD, but got
AA
14:01:19.051 28661 Actual local interface address is 192.168.0.1 (lo0)
14:01:19.051 28661 Actual local interface address is 192.168.104.33 (net0)
14:01:19.051 28661 fully qualified name = mail.domain.tld
14:01:19.051 28661 mail.domain.tld 192.168.9.100 mx=-1 sort=-132
14:01:19.051 28661 mail.domain.tld 192.168.9.2 mx=-1 sort=-34
14:01:19.051 28661 queued for remote_smtp transport: local_part = user
14:01:19.051 28661 domain = domain.tld
14:01:19.051 28661 errors_to=NULL
14:01:19.051 28661 domain_data=domain.tld local_part_data=*
14:01:19.051 28661 routed by inst_route router
14:01:19.051 28661 envelope to: user@domain.tld
14:01:19.051 28661 transport: remote_smtp
14:01:19.051 28661 host mail.domain.tld [192.168.9.100]
14:01:19.051 28661 host mail.domain.tld [192.168.9.2]
14:01:19.051 28661 >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
14:01:19.051 28661 After routing:
14:01:19.051 28661 Local deliveries:
14:01:19.051 28661 Remote deliveries:
14:01:19.051 28661 user@domain.tld
14:01:19.051 28661 Failed addresses:
14:01:19.051 28661 Deferred addresses:
14:01:19.051 28661 search_tidyup called
14:01:19.051 28661 >>>>>>>>>>>>>>>> Remote deliveries >>>>>>>>>>>>>>>>
14:01:19.051 28661 --------> user@domain.tld <--------
14:01:19.052 28661 search_tidyup called
14:01:19.052 28661 fresh-exec forking for transport
14:01:19.052 28661 fresh-exec forked for transport: 28665
14:01:19.052 28661 set_process_info: 28661 delivering 1qxQSQ-0000I8-1U: waiting
for a remote delivery subprocess to finish
14:01:19.052 28661 polling subprocess pipes
14:01:19.053 28665 postfork: transport
14:01:19.054 28665 changed uid/gid: remote delivery to user@domain.tld with
transport=remote_smtp
14:01:19.054 28665 uid=100 gid=100 pid=28665
14:01:19.054 28665 auxiliary group list: <none>
14:01:19.054 28665 set_process_info: 28665 delivering 1qxQSQ-0000I8-1U using
remote_smtp
14:01:19.054 28665 remote_smtp transport entered
14:01:19.054 28665 user@domain.tld
14:01:19.054 28665 hostlist:
14:01:19.054 28665 'mail.domain.tld' IP 192.168.9.100 port -1
14:01:19.054 28665 'mail.domain.tld' IP 192.168.9.2 port -1
14:01:19.056 28665 checking status of mail.domain.tld
14:01:19.056 28665 locking /var/spool/exim/db/retry.lockfile
14:01:19.056 28665 locked /var/spool/exim/db/retry.lockfile
14:01:19.056 28665 EXIM_DBOPEN: file </var/spool/exim/db/retry> dir
</var/spool/exim/db> flags=O_RDONLY
14:01:19.057 28665 returned from EXIM_DBOPEN: 69c940
14:01:19.057 28665 opened hints database /var/spool/exim/db/retry:
flags=O_RDONLY
14:01:19.057 28665 dbfn_read: key=T:mail.domain.tld:192.168.9.100
14:01:19.058 28665 dbfn_read:
key=T:mail.domain.tld:192.168.9.100:1qxQSQ-0000I8-1U
14:01:19.058 28665 EXIM_DBCLOSE(69c940)
14:01:19.058 28665 closed hints database and lockfile
14:01:19.058 28665 no host retry record
14:01:19.058 28665 no message retry record
14:01:19.058 28665 mail.domain.tld [192.168.9.100] retry-status = usable
14:01:19.059 28665 192.168.9.100 in serialize_hosts? no (option unset)
14:01:19.059 28665 delivering 1qxQSQ-0000I8-1U to mail.domain.tld
[192.168.9.100] (user@domain.tld)
14:01:19.059 28665 set_process_info: 28665 delivering 1qxQSQ-0000I8-1U to
mail.domain.tld [192.168.9.100] (user@domain.tld)
14:01:19.059 28665 192.168.9.100 in hosts_require_dane? no (option unset)
14:01:19.059 28665 192.168.9.100 in hosts_pipe_connect? no (option unset)
14:01:19.059 28665 Connecting to mail.domain.tld [192.168.9.100]:25 ...
connected
14:01:19.060 28665 ?considering: $primary_hostname
14:01:19.060 28665 ???expanding: $primary_hostname
14:01:19.060 28665 ??????result: MailExt1.domain.tld
14:01:19.071 28665 read response data: size=82
14:01:19.071 28665 SMTP<< 220 Mail.domain.tld ESMTP Exim 4.96.2/VoB #2 Mon,
30 Oct 2023 14:01:19 +0100
14:01:19.072 28665 192.168.9.100 in hosts_avoid_esmtp? no (option unset)
14:01:19.072 28665 SMTP>> EHLO MailExt1.domain.tld
14:01:19.072 28665 cmd buf flush 30 bytes
14:01:19.072 28665 read response data: size=163
14:01:19.072 28665 SMTP<< 250-Mail.domain.tld Hello mailext.domain.tld
[192.168.104.33]
14:01:19.072 28665 250-SIZE 41943040
14:01:19.072 28665 250-8BITMIME
14:01:19.072 28665 250-PIPELINING
14:01:19.072 28665 250-PIPECONNECT
14:01:19.072 28665 250-STARTTLS
14:01:19.072 28665 250 HELP
14:01:19.073 28665 ?considering: ${if and {{match{$host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.073 28665 ?considering: $host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.073 28665 ?considering: }{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.073 28665 ???expanding: $host
14:01:19.073 28665 ??????result: mail.domain.tld
14:01:19.073 28665 ?considering: .outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.073 28665 ????????text: .outlook.com
14:01:19.073 28665 ?considering: \$}} {match{$item}{\N^250-([\w.]+)\s\N}}}
{$1}}
14:01:19.073 28665 ?backslashed: '\$'
14:01:19.073 28665 ?considering: }} {match{$item}{\N^250-([\w.]+)\s\N}}}
{$1}}
14:01:19.073 28665 ???expanding: .outlook.com\$
14:01:19.073 28665 ??????result: .outlook.com$
14:01:19.074 28665 ????scanning: $item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.074 28665 ????scanning: }{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.074 28665 ???expanding: $item
14:01:19.074 28665 ??????result:
14:01:19.074 28665 ????skipping: result is not used
14:01:19.074 28665 ????scanning: \N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.074 28665 ???protected: ^250-([\w.]+)\s
14:01:19.074 28665 ????scanning: }}} {$1}}
14:01:19.074 28665 ???expanding: \N^250-([\w.]+)\s\N
14:01:19.074 28665 ??????result: ^250-([\w.]+)\s
14:01:19.074 28665 ????skipping: result is not used
14:01:19.074 28665 ???condition: and {{match{$host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}}
14:01:19.074 28665 ??????result: false
14:01:19.074 28665 ????scanning: $1}}
14:01:19.074 28665 ????scanning: }}
14:01:19.074 28665 ???expanding: $1
14:01:19.074 28665 ??????result: mail.domain.tld
14:01:19.074 28665 ????skipping: result is not used
14:01:19.074 28665 ???expanding: ${if and {{match{$host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.074 28665 ??????result:
14:01:19.074 28665 192.168.9.100 in hosts_avoid_tls? no (option unset)
14:01:19.074 28665 SMTP>> STARTTLS
14:01:19.074 28665 cmd buf flush 10 bytes
14:01:19.080 28665 read response data: size=18
14:01:19.080 28665 SMTP<< 220 TLS go ahead
14:01:19.080 28665 192.168.9.100 in hosts_require_ocsp? no (option unset)
14:01:19.080 28665 192.168.9.100 in hosts_request_ocsp? yes (matched "*")
14:01:19.086 28665 openssl option, adding to 03104000: 01000000 (no_sslv2
+no_sslv3 +no_tlsv1 +no_tlsv1_1 +cipher_server_preference)
14:01:19.086 28665 openssl option, adding to 03104000: 02000000 (no_sslv3
+no_tlsv1 +no_tlsv1_1 +cipher_server_preference)
14:01:19.086 28665 openssl option, adding to 03104000: 04000000 (no_tlsv1
+no_tlsv1_1 +cipher_server_preference)
14:01:19.086 28665 openssl option, adding to 07104000: 10000000 (no_tlsv1_1
+cipher_server_preference)
14:01:19.086 28665 openssl option, adding to 17104000: 00400000
(cipher_server_preference)
14:01:19.086 28665 setting SSL CTX options: 0x17504000
14:01:19.086 28665 Initialized TLS
14:01:19.086 28665 192.168.9.100 in tls_verify_hosts? no (option unset)
14:01:19.087 28665 192.168.9.100 in tls_try_verify_hosts? yes (matched "*")
14:01:19.087 28665 tls_verify_certificates: system
14:01:19.087 28665 tls_verify_certificates: system
14:01:19.087 28665 192.168.9.100 in tls_verify_cert_hostnames? yes (matched
"*")
14:01:19.087 28665 Cert hostname to check: "mail.domain.tld"
14:01:19.087 28665 192.168.9.100 in tls_resumption_hosts? no (option unset)
14:01:19.087 28665 Calling SSL_connect
14:01:19.087 28665 SSL info (undefined): hshake start: before/connect
initialization
14:01:19.087 28665 SSL_connect: before/connect initialization
14:01:19.087 28665 SSL_connect: SSLv2/v3 write client hello A
14:01:19.088 28665 Received TLS status callback (OCSP stapling):
14:01:19.088 28665 null
14:01:19.088 28665 SSL_connect: unknown state
14:01:19.109 28665 SSL verify ok: depth=3 SN=/C=GB/ST=Greater
Manchester/L=Salford/O=Comodo CA Limited/CN=AAA Certificate Services
14:01:19.109 28665 SSL verify ok: depth=2 SN=/C=US/ST=New Jersey/L=Jersey
City/O=The USERTRUST Network/CN=USERTrust RSA Certification Authority
14:01:19.110 28665 SSL verify ok: depth=1 SN=/C=NL/O=GEANT Vereniging/CN=GEANT
OV RSA CA 4
14:01:19.110 28665 SSL authenticated verify ok: depth=0
SN=/C=DE/ST=Niedersachsen/O=Institute (inst)/CN=mail.domain.tld
14:01:19.110 28665 SSL_connect: unknown state
14:01:19.110 28665 SSL_connect: unknown state
14:01:19.110 28665 SSL_connect: unknown state
14:01:19.110 28665 SSL_connect: unknown state
14:01:19.110 28665 SSL_connect: unknown state
14:01:19.111 28665 SSL_connect: unknown state
14:01:19.111 28665 SSL_connect: unknown state
14:01:19.112 28665 SSL_connect: unknown state
14:01:19.112 28665 SSL info (undefined): hshake done: SSL negotiation finished
successfully
14:01:19.112 28665 SSL_connect succeeded
14:01:19.112 28665 Cipher: TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256
14:01:19.112 28665 Have channel bindings cached for possible auth usage 6c0428
666220
14:01:19.112 28665 SMTP>> EHLO MailExt1.domain.tld
14:01:19.112 28665 cmd buf flush 30 bytes
14:01:19.112 28665 tls_write(74b1c8, 30)
14:01:19.112 28665 SSL_write(72f6b0, 74b1c8, 30)
14:01:19.112 28665 outbytes=30 error=0
14:01:19.112 28665 Calling SSL_read(72f6b0, 74a1c8, 4096)
14:01:19.112 28665 read response data: size=149
14:01:19.112 28665 SMTP<< 250-Mail.domain.tld Hello mailext.domain.tld
[192.168.104.33]
14:01:19.112 28665 250-SIZE 41943040
14:01:19.112 28665 250-8BITMIME
14:01:19.112 28665 250-PIPELINING
14:01:19.112 28665 250-PIPECONNECT
14:01:19.113 28665 250 HELP
14:01:19.113 28665 192.168.9.100 in hosts_avoid_pipelining? no (option unset)
14:01:19.113 28665 using PIPELINING
14:01:19.113 28665 not using DSN
14:01:19.113 28665 192.168.9.100 in hosts_require_auth? no (option unset)
14:01:19.113 28665 SMTP|> MAIL FROM:<admin@genarec.com> SIZE=5291
14:01:19.113 28665 SMTP|> RCPT TO:<user@domain.tld>
14:01:19.113 28665 SMTP>> DATA
14:01:19.113 28665 cmd buf flush 87 bytes
14:01:19.113 28665 tls_write(74b1c8, 87)
14:01:19.113 28665 SSL_write(72f6b0, 74b1c8, 87)
14:01:19.113 28665 outbytes=87 error=0
14:01:19.113 28665 sync_responses expect mail
14:01:19.268 28665 Calling SSL_read(72f6b0, 74a1c8, 4096)
14:01:19.268 28665 read response data: size=78
14:01:19.268 28665 SMTP<< 250 OK
14:01:19.268 28665 sync_responses expect rcpt for user@domain.tld
14:01:19.268 28665 SMTP<< 250 Accepted
14:01:19.268 28665 sync_responses expect data
14:01:19.268 28665 SMTP<< 354 Enter message, ending with "." on a line by
itself
14:01:19.268 28665 SMTP>> (writing message)
14:01:19.268 28665 cannot use sendfile for body: no support
14:01:19.268 28665 cannot use sendfile for body: spoolfile not wireformat
14:01:19.268 28665 SMTP>> .
14:01:19.268 28665 writing data block fd=8 size=4271 timeout=300
14:01:19.268 28665 tls_write(6bbd58, 4271)
14:01:19.268 28665 SSL_write(72f6b0, 6bbd58, 4271)
14:01:19.268 28665 outbytes=4271 error=0
14:01:19.273 28665 Calling SSL_read(72f6b0, 74a1c8, 4096)
14:01:19.273 28665 SMTP(closed)<<
14:01:19.273 28665 LOG: MAIN
14:01:19.273 28665 H=mail.domain.tld [192.168.9.100]:25: Remote host closed
connection in response to end of data
14:01:19.273 28665 ok=0 send_quit=0 send_rset=1 continue_more=0 yield=0
first_address is NULL
14:01:19.273 28665 SMTP(close)>>
14:01:19.273 28665 cmdlog:
'220:EHLO:250-:STARTTLS:220:EHLO:250-:MAIL|:RCPT|:DATA:250:250:354:.'
14:01:19.273 28665 set_process_info: 28665 delivering 1qxQSQ-0000I8-1U: just
tried mail.domain.tld [192.168.9.100] for user@domain.tld: result OK
14:01:19.273 28665 added retry item for
T:mail.domain.tld:192.168.9.100:1qxQSQ-0000I8-1U: errno=-18 more_errno=0,A
flags=6
14:01:19.273 28665 address match test: subject=*@mail.domain.tld
pattern=domain.tld
14:01:19.273 28665 mail.domain.tld in "domain.tld"? no (end of list)
14:01:19.273 28665 *@mail.domain.tld in "domain.tld"? no (end of list)
14:01:19.273 28665 address match test: subject=*@mail.domain.tld pattern=*
14:01:19.273 28665 mail.domain.tld in "*"? yes (matched "*")
14:01:19.273 28665 *@mail.domain.tld in "*"? yes (matched "*")
14:01:19.273 28665 checking status of mail.domain.tld
14:01:19.274 28665 locking /var/spool/exim/db/retry.lockfile
14:01:19.274 28665 locked /var/spool/exim/db/retry.lockfile
14:01:19.274 28665 EXIM_DBOPEN: file </var/spool/exim/db/retry> dir
</var/spool/exim/db> flags=O_RDONLY
14:01:19.274 28665 returned from EXIM_DBOPEN: 773e10
14:01:19.274 28665 opened hints database /var/spool/exim/db/retry:
flags=O_RDONLY
14:01:19.274 28665 dbfn_read: key=T:mail.domain.tld:192.168.9.2
14:01:19.274 28665 dbfn_read:
key=T:mail.domain.tld:192.168.9.2:1qxQSQ-0000I8-1U
14:01:19.275 28665 EXIM_DBCLOSE(773e10)
14:01:19.275 28665 closed hints database and lockfile
14:01:19.275 28665 no host retry record
14:01:19.275 28665 no message retry record
14:01:19.275 28665 mail.domain.tld [192.168.9.2] retry-status = usable
14:01:19.275 28665 192.168.9.2 in serialize_hosts? no (option unset)
14:01:19.275 28665 delivering 1qxQSQ-0000I8-1U to mail.domain.tld [192.168.9.2]
(user@domain.tld)
14:01:19.275 28665 set_process_info: 28665 delivering 1qxQSQ-0000I8-1U to
mail.domain.tld [192.168.9.2] (user@domain.tld)
14:01:19.275 28665 192.168.9.2 in hosts_require_dane? no (option unset)
14:01:19.275 28665 192.168.9.2 in hosts_pipe_connect? no (option unset)
14:01:19.275 28665 Connecting to mail.domain.tld [192.168.9.2]:25 ...
connected
14:01:19.278 28665 ?considering: $primary_hostname
14:01:19.278 28665 ???expanding: $primary_hostname
14:01:19.278 28665 ??????result: MailExt1.domain.tld
14:01:19.291 28665 read response data: size=82
14:01:19.291 28665 SMTP<< 220 Mail.domain.tld ESMTP Exim 4.96.2/VoB #2 Mon,
30 Oct 2023 14:01:19 +0100
14:01:19.291 28665 192.168.9.2 in hosts_avoid_esmtp? no (option unset)
14:01:19.291 28665 SMTP>> EHLO MailExt1.domain.tld
14:01:19.291 28665 cmd buf flush 30 bytes
14:01:19.291 28665 read response data: size=163
14:01:19.291 28665 SMTP<< 250-Mail.domain.tld Hello mailext.domain.tld
[192.168.104.33]
14:01:19.291 28665 250-SIZE 41943040
14:01:19.291 28665 250-8BITMIME
14:01:19.291 28665 250-PIPELINING
14:01:19.291 28665 250-PIPECONNECT
14:01:19.291 28665 250-STARTTLS
14:01:19.291 28665 250 HELP
14:01:19.291 28665 ?considering: ${if and {{match{$host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ?considering: $host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ?considering: }{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ???expanding: $host
14:01:19.292 28665 ??????result: mail.domain.tld
14:01:19.292 28665 ?considering: .outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ????????text: .outlook.com
14:01:19.292 28665 ?considering: \$}} {match{$item}{\N^250-([\w.]+)\s\N}}}
{$1}}
14:01:19.292 28665 ?backslashed: '\$'
14:01:19.292 28665 ?considering: }} {match{$item}{\N^250-([\w.]+)\s\N}}}
{$1}}
14:01:19.292 28665 ???expanding: .outlook.com\$
14:01:19.292 28665 ??????result: .outlook.com$
14:01:19.292 28665 ????scanning: $item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ????scanning: }{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ???expanding: $item
14:01:19.292 28665 ??????result:
14:01:19.292 28665 ????skipping: result is not used
14:01:19.292 28665 ????scanning: \N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ???protected: ^250-([\w.]+)\s
14:01:19.292 28665 ????scanning: }}} {$1}}
14:01:19.292 28665 ???expanding: \N^250-([\w.]+)\s\N
14:01:19.292 28665 ??????result: ^250-([\w.]+)\s
14:01:19.292 28665 ????skipping: result is not used
14:01:19.292 28665 ???condition: and {{match{$host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}}
14:01:19.292 28665 ??????result: false
14:01:19.292 28665 ????scanning: $1}}
14:01:19.292 28665 ????scanning: }}
14:01:19.292 28665 ???expanding: $1
14:01:19.292 28665 ??????result:
14:01:19.292 28665 ????skipping: result is not used
14:01:19.292 28665 ???expanding: ${if and {{match{$host}{.outlook.com\$}}
{match{$item}{\N^250-([\w.]+)\s\N}}} {$1}}
14:01:19.292 28665 ??????result:
14:01:19.292 28665 192.168.9.2 in hosts_avoid_tls? no (option unset)
14:01:19.292 28665 SMTP>> STARTTLS
14:01:19.292 28665 cmd buf flush 10 bytes
14:01:19.298 28665 read response data: size=18
14:01:19.298 28665 SMTP<< 220 TLS go ahead
14:01:19.298 28665 192.168.9.2 in hosts_require_ocsp? no (option unset)
14:01:19.298 28665 192.168.9.2 in hosts_request_ocsp? yes (matched "*")
14:01:19.300 28665 setting SSL CTX options: 0x17504000
14:01:19.300 28665 Initialized TLS
14:01:19.300 28665 192.168.9.2 in tls_verify_hosts? no (option unset)
14:01:19.300 28665 192.168.9.2 in tls_try_verify_hosts? yes (matched "*")
14:01:19.300 28665 tls_verify_certificates: system
14:01:19.300 28665 tls_verify_certificates: system
14:01:19.300 28665 192.168.9.2 in tls_verify_cert_hostnames? yes (matched "*")
14:01:19.300 28665 Cert hostname to check: "mail.domain.tld"
14:01:19.300 28665 192.168.9.2 in tls_resumption_hosts? no (option unset)
14:01:19.300 28665 Calling SSL_connect
14:01:19.301 28665 SSL info (undefined): hshake start: before/connect
initialization
14:01:19.301 28665 SSL_connect: before/connect initialization
14:01:19.301 28665 SSL_connect: SSLv2/v3 write client hello A
14:01:19.302 28665 Received TLS status callback (OCSP stapling):
14:01:19.302 28665 null
14:01:19.302 28665 SSL_connect: unknown state
14:01:19.326 28665 SSL verify ok: depth=3 SN=/C=GB/ST=Greater
Manchester/L=Salford/O=Comodo CA Limited/CN=AAA Certificate Services
14:01:19.326 28665 SSL verify ok: depth=2 SN=/C=US/ST=New Jersey/L=Jersey
City/O=The USERTRUST Network/CN=USERTrust RSA Certification Authority
14:01:19.327 28665 SSL verify ok: depth=1 SN=/C=NL/O=GEANT Vereniging/CN=GEANT
OV RSA CA 4
14:01:19.328 28665 SSL authenticated verify ok: depth=0
SN=/C=DE/ST=Niedersachsen/O=Institute (inst)/CN=mail.domain.tld
14:01:19.328 28665 SSL_connect: unknown state
14:01:19.329 28665 SSL_connect: unknown state
14:01:19.329 28665 SSL_connect: unknown state
14:01:19.330 28665 SSL_connect: unknown state
14:01:19.330 28665 SSL_connect: unknown state
14:01:19.330 28665 SSL_connect: unknown state
14:01:19.330 28665 SSL_connect: unknown state
14:01:19.332 28665 SSL_connect: unknown state
14:01:19.332 28665 SSL info (undefined): hshake done: SSL negotiation finished
successfully
14:01:19.332 28665 SSL_connect succeeded
14:01:19.332 28665 Cipher: TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256
14:01:19.332 28665 Have channel bindings cached for possible auth usage 6c04d8
666220
14:01:19.332 28665 SMTP>> EHLO MailExt1.domain.tld
14:01:19.332 28665 cmd buf flush 30 bytes
14:01:19.332 28665 tls_write(793728, 30)
14:01:19.332 28665 SSL_write(765de0, 793728, 30)
14:01:19.332 28665 outbytes=30 error=0
14:01:19.333 28665 Calling SSL_read(765de0, 792728, 4096)
14:01:19.333 28665 read response data: size=149
14:01:19.333 28665 SMTP<< 250-Mail.domain.tld Hello mailext.domain.tld
[192.168.104.33]
14:01:19.333 28665 250-SIZE 41943040
14:01:19.333 28665 250-8BITMIME
14:01:19.333 28665 250-PIPELINING
14:01:19.333 28665 250-PIPECONNECT
14:01:19.333 28665 250 HELP
14:01:19.333 28665 192.168.9.2 in hosts_avoid_pipelining? no (option unset)
14:01:19.333 28665 using PIPELINING
14:01:19.333 28665 not using DSN
14:01:19.333 28665 192.168.9.2 in hosts_require_auth? no (option unset)
14:01:19.333 28665 SMTP|> MAIL FROM:<admin@genarec.com> SIZE=5291
14:01:19.333 28665 SMTP|> RCPT TO:<user@domain.tld>
14:01:19.333 28665 SMTP>> DATA
14:01:19.333 28665 cmd buf flush 87 bytes
14:01:19.333 28665 tls_write(793728, 87)
14:01:19.334 28665 SSL_write(765de0, 793728, 87)
14:01:19.334 28665 outbytes=87 error=0
14:01:19.334 28665 sync_responses expect mail
14:01:19.459 28665 Calling SSL_read(765de0, 792728, 4096)
14:01:19.459 28665 read response data: size=78
14:01:19.459 28665 SMTP<< 250 OK
14:01:19.459 28665 sync_responses expect rcpt for user@domain.tld
14:01:19.459 28665 SMTP<< 250 Accepted
14:01:19.459 28665 sync_responses expect data
14:01:19.459 28665 SMTP<< 354 Enter message, ending with "." on a line by
itself
14:01:19.459 28665 SMTP>> (writing message)
14:01:19.459 28665 cannot use sendfile for body: no support
14:01:19.459 28665 cannot use sendfile for body: spoolfile not wireformat
14:01:19.459 28665 SMTP>> .
14:01:19.459 28665 writing data block fd=8 size=4271 timeout=300
14:01:19.459 28665 tls_write(6bbd58, 4271)
14:01:19.459 28665 SSL_write(765de0, 6bbd58, 4271)
14:01:19.460 28665 outbytes=4271 error=0
14:01:19.469 28665 Calling SSL_read(765de0, 792728, 4096)
14:01:19.469 28665 SMTP(closed)<<
14:01:19.469 28665 LOG: MAIN
14:01:19.469 28665 H=mail.domain.tld [192.168.9.2]:25: Remote host closed
connection in response to end of data
14:01:19.469 28665 ok=0 send_quit=0 send_rset=1 continue_more=0 yield=0
first_address is NULL
14:01:19.469 28665 SMTP(close)>>
14:01:19.469 28665 cmdlog:
'220:EHLO:250-:STARTTLS:220:EHLO:250-:MAIL|:RCPT|:DATA:250:250:354:.'
14:01:19.469 28665 set_process_info: 28665 delivering 1qxQSQ-0000I8-1U: just
tried mail.domain.tld [192.168.9.2] for user@domain.tld: result OK
14:01:19.469 28665 added retry item for
T:mail.domain.tld:192.168.9.2:1qxQSQ-0000I8-1U: errno=-18 more_errno=0,A
flags=6
14:01:19.469 28665 all IP addresses skipped or deferred at least one address
14:01:19.469 28665 Leaving remote_smtp transport
14:01:19.469 28665 set_process_info: 28665 delivering 1qxQSQ-0000I8-1U (just
run remote_smtp for user@domain.tld in subprocess)
14:01:19.469 28665 search_tidyup called
14:01:19.470 28665 header write id:S,subid:0,size:4,final:S000004
14:01:19.470 28665 header write id:X,subid:1,size:127,final:X100127
14:01:19.470 28665 header write id:X,subid:2,size:3027,final:X203027
14:01:19.470 28665 header write id:X,subid:4,size:2,final:X400002
14:01:19.470 28665 header write id:D,subid:0,size:4,final:D000004
14:01:19.470 28665 header write id:R,subid:0,size:152,final:R000152
14:01:19.470 28661 reading pipe for subprocess 28665 (not ended yet)
14:01:19.470 28665 header write id:R,subid:0,size:156,final:R000156
14:01:19.470 28665 non-continued-connection
14:01:19.470 28665 header write id:A,subid:3,size:1,final:A300001
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28665 header write id:A,subid:0,size:128,final:A000128
14:01:19.470 28665 header write id:I,subid:0,size:21,final:I000021
14:01:19.470 28665 header write id:Z,subid:0,size:1,final:Z000001
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 4 bytes (pipedata) from transport process 28665
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 127 bytes (pipedata) from transport process 28665
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 3027 bytes (pipedata) from transport process 28665
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 2 bytes (pipedata) from transport process 28665
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 4 bytes (pipedata) from transport process 28665
14:01:19.470 28661 DSN read: addr->dsn_aware = 2
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 152 bytes (pipedata) from transport process 28665
14:01:19.470 28661 reading retry information for
T:mail.domain.tld:192.168.9.2:1qxQSQ-0000I8-1U from subprocess
14:01:19.470 28661 added retry item
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 156 bytes (pipedata) from transport process 28665
14:01:19.470 28661 reading retry information for
T:mail.domain.tld:192.168.9.100:1qxQSQ-0000I8-1U from subprocess
14:01:19.470 28661 added retry item
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 1 bytes (pipedata) from transport process 28665
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 128 bytes (pipedata) from transport process 28665
14:01:19.470 28661 A0 user@domain.tld tret 1
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 21 bytes (pipedata) from transport process 28665
14:01:19.470 28661 expect 7 bytes (pipeheader) from tpt process 28665
14:01:19.470 28661 got 7 bytes (pipeheader) from transport process 28665
14:01:19.470 28661 expect 1 bytes (pipedata) from transport process 28665
14:01:19.470 28661 Z00 item read
14:01:19.471 28661 remote delivery process 28665 ended
14:01:19.471 28661 set_process_info: 28661 delivering 1qxQSQ-0000I8-1U
14:01:19.471 28661 post-process user@domain.tld (1)
14:01:19.472 28661 LOG: MAIN
14:01:19.472 28661 == user@domain.tld R=inst_route T=remote_smtp defer (-18)
H=mail.domain.tld [192.168.9.2]:25 I=[192.168.104.33]:64602 DT=0.194s: Remote
host closed connection in response to end of data
14:01:19.475 28661 >>>>>>>>>>>>>>>> deliveries are done >>>>>>>>>>>>>>>>
14:01:19.476 28661 changed uid/gid: post-delivery tidying
14:01:19.476 28661 uid=100 gid=100 pid=28661
14:01:19.476 28661 auxiliary group list: <none>
14:01:19.476 28661 set_process_info: 28661 tidying up after delivering
1qxQSQ-0000I8-1U
14:01:19.476 28661 Processing retry items
14:01:19.476 28661 Succeeded addresses:
14:01:19.476 28661 Failed addresses:
14:01:19.476 28661 Deferred addresses:
14:01:19.476 28661 user@domain.tld
14:01:19.476 28661 locking /var/spool/exim/db/retry.lockfile
14:01:19.476 28661 locked /var/spool/exim/db/retry.lockfile
14:01:19.476 28661 EXIM_DBOPEN: file </var/spool/exim/db/retry> dir
</var/spool/exim/db> flags=O_RDWR
14:01:19.476 28661 returned from EXIM_DBOPEN: 69d900
14:01:19.476 28661 opened hints database /var/spool/exim/db/retry:
flags=O_RDWR
14:01:19.476 28661 address match test: subject=*@mail.domain.tld
pattern=domain.tld
14:01:19.476 28661 mail.domain.tld in "domain.tld"? no (end of list)
14:01:19.476 28661 *@mail.domain.tld in "domain.tld"? no (end of list)
14:01:19.476 28661 address match test: subject=*@domain.tld pattern=domain.tld
14:01:19.476 28661 domain.tld in "domain.tld"? yes (matched "domain.tld")
14:01:19.476 28661 *@domain.tld in "domain.tld"? yes (matched "domain.tld")
14:01:19.476 28661 retry for T:mail.domain.tld:192.168.9.100:1qxQSQ-0000I8-1U
(domain.tld) = domain.tld 0 0
14:01:19.476 28661 dbfn_read:
key=T:mail.domain.tld:192.168.9.100:1qxQSQ-0000I8-1U
14:01:19.476 28661 failing_interval=0 message_age=5517
14:01:19.476 28661 Writing retry data for
T:mail.domain.tld:192.168.9.100:1qxQSQ-0000I8-1U
14:01:19.476 28661 first failed=1698670879 last try=1698670879 next
try=1698670939 expired=0
14:01:19.476 28661 errno=-18 more_errno=0,A H=mail.domain.tld
[192.168.9.100]: Remote host closed connection in response to end of data
14:01:19.476 28661 dbfn_write:
key=T:mail.domain.tld:192.168.9.100:1qxQSQ-0000I8-1U
14:01:19.477 28661 address match test: subject=*@mail.domain.tld
pattern=domain.tld
14:01:19.477 28661 mail.domain.tld in "domain.tld"? no (end of list)
14:01:19.477 28661 *@mail.domain.tld in "domain.tld"? no (end of list)
14:01:19.477 28661 address match test: subject=*@domain.tld pattern=domain.tld
14:01:19.477 28661 domain.tld in "domain.tld"? yes (matched "domain.tld")
14:01:19.477 28661 *@domain.tld in "domain.tld"? yes (matched "domain.tld")
14:01:19.477 28661 retry for T:mail.domain.tld:192.168.9.2:1qxQSQ-0000I8-1U
(domain.tld) = domain.tld 0 0
14:01:19.477 28661 dbfn_read:
key=T:mail.domain.tld:192.168.9.2:1qxQSQ-0000I8-1U
14:01:19.477 28661 failing_interval=0 message_age=5517
14:01:19.477 28661 Writing retry data for
T:mail.domain.tld:192.168.9.2:1qxQSQ-0000I8-1U
14:01:19.477 28661 first failed=1698670879 last try=1698670879 next
try=1698670939 expired=0
14:01:19.477 28661 errno=-18 more_errno=0,A H=mail.domain.tld [192.168.9.2]:
Remote host closed connection in response to end of data
14:01:19.477 28661 dbfn_write:
key=T:mail.domain.tld:192.168.9.2:1qxQSQ-0000I8-1U
14:01:19.477 28661 EXIM_DBCLOSE(69d900)
14:01:19.509 28661 closed hints database and lockfile
14:01:19.509 28661 end of retry processing
14:01:19.509 28661 ?considering: ${if
match{$h_precedence:}{(?i)bulk|list|junk}{no}{yes}}
14:01:19.509 28661 ?considering:
$h_precedence:}{(?i)bulk|list|junk}{no}{yes}}
14:01:19.509 28661 ?considering: }{(?i)bulk|list|junk}{no}{yes}}
14:01:19.509 28661 ???expanding: $h_precedence:
14:01:19.509 28661 ??????result:
14:01:19.509 28661 ?considering: (?i)bulk|list|junk}{no}{yes}}
14:01:19.509 28661 ????????text: (?i)bulk|list|junk
14:01:19.509 28661 ?considering: }{no}{yes}}
14:01:19.509 28661 ???expanding: (?i)bulk|list|junk
14:01:19.509 28661 ??????result: (?i)bulk|list|junk
14:01:19.509 28661 ???condition: match{$h_precedence:}{(?i)bulk|list|junk}
14:01:19.509 28661 ??????result: false
14:01:19.509 28661 ????scanning: no}{yes}}
14:01:19.509 28661 ????????text: no
14:01:19.509 28661 ????scanning: }{yes}}
14:01:19.509 28661 ???expanding: no
14:01:19.509 28661 ??????result: no
14:01:19.509 28661 ????skipping: result is not used
14:01:19.509 28661 ?considering: yes}}
14:01:19.509 28661 ????????text: yes
14:01:19.509 28661 ?considering: }}
14:01:19.509 28661 ???expanding: yes
14:01:19.509 28661 ??????result: yes
14:01:19.509 28661 ???expanding: ${if
match{$h_precedence:}{(?i)bulk|list|junk}{no}{yes}}
14:01:19.509 28661 ??????result: yes
14:01:19.509 28661 time on queue = 1h31m57s id 1qxQSQ-0000I8-1U addr
user@domain.tld
14:01:19.509 28661 warning counts: required 0 done 0
14:01:19.509 28661 delivery deferred: update_spool=0 header_rewritten=0
14:01:19.509 28661 end delivery of 1qxQSQ-0000I8-1U
14:01:19.509 28661 search_tidyup called
14:01:19.509 28661 search_tidyup called
14:01:19.509 28661 >>>>>>>>>>>>>>>> Exim pid=28661 (fresh-exec) terminating
with rc=0 >>>>>>>>>>>>>>>>

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
[Bug 3042] EXim closes connection direct after end of DATA (.) [ In reply to ]
https://bugs.exim.org/show_bug.cgi?id=3042

--- Comment #6 from Jeremy Harris <jgh146exb@wizmail.org> ---
What did the destination (internal) MTA log?
Does it's config have any deliberate connection drops?
Is it crashing on the message reception (check paniclog)?
Can you get debug from it (if you can spot suspect messages in ACL, use
ACL-initiated debug)?

--
You are receiving this mail because:
You are on the CC list for the bug.

--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-dev.lists.exim.org/
## unsubscribe (doesn't require an account):
## exim-dev-unsubscribe@lists.exim.org
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/