- 論壇徽章:
- 0
|
下面是一封郵件的一部分, 對于smtp 協(xié)議 我的了解不多 求解釋。
發(fā)送端 163.com
接受端 emc.com
Received: from mxhub36.corp.emc.com (10.253.xxx.xxx) by MXHUB202.corp.emc.com
(10.253.xxx.xxx) with Microsoft SMTP Server (TLS) id 14.3.266.1; Wed, 28 Oct
2015 23:01:00 -0400
Received: from mailusrhubprd54.lss.emc.com (10.106.xx.xx) by
mxhub36.corp.emc.com (10.254.xx.xx) with Microsoft SMTP Server id 8.3.327.1;
Wed, 28 Oct 2015 23:00:38 -0400
Received: from mailusrigwprd53.lss.emc.com (mailusrigwprd53.lss.emc.com
[128.221.234.31]) by mailusrhubprd54.lss.emc.com
(Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.0) with ESMTP id t9T30bfD023745
(version=TLSv1.2 cipher=xxxxxxxx bits=256 verify=OK) for
<xxx@emc.com>; Wed, 28 Oct 2015 23:00:38 -0400
Received: from mx0a-00154901.pphosted.com (mx0a-00154901.pphosted.com
[67.231.149.39]) by mailusrigwprd53.lss.emc.com
(Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.0) with ESMTP id t9T30atk025034
(version=TLSv1.2 cipher=xxxxxxx bits=256 verify=NO) for
<xxx@emc.com>; Wed, 28 Oct 2015 23:00:37 -0400
Received: from pps.filterd (m0075501.ppops.net [127.0.0.1]) by
mx0a-00154901.pphosted.com (8.15.0.59/8.15.0.59) with SMTP id t9T2waj0025295
for <xxx@emc.com>; Wed, 28 Oct 2015 23:00:36 -0400
Received: from m50-138.163.com (m50-138.163.com [123.125.50.138]) by
mx0a-00154901.pphosted.com with ESMTP id 1xu1tx21cc-1 for
<xxx@emc.com>; Wed, 28 Oct 2015 23:00:36 -0400
可以看到郵件先被 m50-138.163.com [123.125.50.138]拿到了, 然后 m0075501.ppops.net [127.0.0.1] 本機轉(zhuǎn)了一下 就到來 mx0a-00154901.pphosted.com[67.231.149.39]
按照理解 163 應該直接和emc 的smtp 服務器建立連接,但是它沒有這么做,是轉(zhuǎn)到了一個pphosted.com的服務器,由它幫忙轉(zhuǎn)出去,這樣做應該可以,因為國內(nèi)的ip 被封鎖得差不多了吧。
有一個問題 接受方為什么會收這封郵件?
因為這個ip 屬于pphosted.com 而不是163.com 這相當于 有人的**顯示它是山東人發(fā)信,但它自稱是 廣東人,然后就按照廣東人的發(fā)件地址收下來了,如果這樣很容易做到 垃圾郵件應該很容易吧! 比如 我自稱是yahoo.com 發(fā)信服務器 給google 的每個用戶發(fā)廣告信息。
root@xxx:/var/log/exim4# dig -x 67.231.149.39
; <<>> DiG 9.8.1-P1 <<>> -x 67.231.149.39
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6427
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 6, ADDITIONAL: 4
;; QUESTION SECTION:
;39.149.231.67.in-addr.arpa. IN PTR
;; ANSWER SECTION:
39.149.231.67.in-addr.arpa. 1800 IN PTR mx0a-00154901.pphosted.com.
;; AUTHORITY SECTION:
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.net.
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.com.
149.231.67.in-addr.arpa. 1800 IN NS ns1.proofpoint.com.
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.org.
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.biz.
149.231.67.in-addr.arpa. 1800 IN NS ns3.proofpoint.com.
;; ADDITIONAL SECTION:
ns1.proofpoint.com. 848 IN A 208.84.67.208
ns1.proofpoint.com. 847 IN AAAA 2620:100:9000:1::d0
ns3.proofpoint.com. 847 IN A 208.84.66.208
ns3.proofpoint.com. 847 IN AAAA 2620:100:9004:1::d0
下面一步 我沒看懂 接收方 mailusrigwprd53.lss.emc.com [128.221.234.31]
因為我的理解 服務器先查看mx 紀錄 日志如下
root@xxx:/var/log/exim4# dig -t mx emc.com
; <<>> DiG 9.8.1-P1 <<>> -t mx emc.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29816
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 5, ADDITIONAL: 0
;; QUESTION SECTION:
;emc.com. IN MX
;; ANSWER SECTION:
emc.com. 120 IN MX 10 mailhub.lss.emc.com.
emc.com. 120 IN MX 20 mailhubwc.lss.emc.com.
;; AUTHORITY SECTION:
emc.com. 600 IN NS duribgm2.isus.emc.com.
emc.com. 600 IN NS corkibgm1.isus.emc.com.
emc.com. 600 IN NS hopibgm2.isus.emc.com.
emc.com. 600 IN NS duribgm1.isus.emc.com.
emc.com. 600 IN NS hopibgm1.isus.emc.com.
mx 紀錄是2條
emc.com. 120 IN MX 10 mailhub.lss.emc.com.
emc.com. 120 IN MX 20 mailhubwc.lss.emc.com.
那么 它應該發(fā)給 mailhub.lss.emc.com. 或者 mailhubwc.lss.emc.com. 這2個服務器, 不知道 如何來了一臺 mailusrigwprd53.lss.emc.com [128.221.234.31] 服務器?
也就是說最終接收方的 郵件地址應該是 mailhub.lss.emc.com. 或者 mailhubwc.lss.emc.com. 的IP, 但是目前看來也不是的? 這是為什么呢?
是因為dns 的原因嗎?
root@xxx:/var/log/exim4# dig mailhub.lss.emc.com.
; <<>> DiG 9.8.1-P1 <<>> mailhub.lss.emc.com.
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24083
;; flags: qr rd ra; QUERY: 1, ANSWER: 20, AUTHORITY: 5, ADDITIONAL: 2
;; QUESTION SECTION:
;mailhub.lss.emc.com. IN A
;; ANSWER SECTION:
mailhub.lss.emc.com. 95 IN A 10.253.24.25
mailhub.lss.emc.com. 95 IN A 10.253.24.26
mailhub.lss.emc.com. 95 IN A 10.253.24.51
mailhub.lss.emc.com. 95 IN A 10.253.24.52
mailhub.lss.emc.com. 95 IN A 10.253.24.63
mailhub.lss.emc.com. 95 IN A 10.253.24.64
mailhub.lss.emc.com. 95 IN A 10.253.24.70
mailhub.lss.emc.com. 95 IN A 10.253.24.71
mailhub.lss.emc.com. 95 IN A 10.106.48.26
mailhub.lss.emc.com. 95 IN A 10.106.48.27
mailhub.lss.emc.com. 95 IN A 10.106.48.28
mailhub.lss.emc.com. 95 IN A 10.106.48.29
mailhub.lss.emc.com. 95 IN A 10.106.48.137
mailhub.lss.emc.com. 95 IN A 10.106.48.138
mailhub.lss.emc.com. 95 IN A 10.106.83.170
mailhub.lss.emc.com. 95 IN A 10.106.83.171
mailhub.lss.emc.com. 95 IN A 10.106.83.172
mailhub.lss.emc.com. 95 IN A 10.106.83.173
mailhub.lss.emc.com. 95 IN A 10.253.24.23
mailhub.lss.emc.com. 95 IN A 10.253.24.24
;; AUTHORITY SECTION:
lss.emc.com. 575 IN NS hopibgm1.isus.emc.com.
lss.emc.com. 575 IN NS duribgm1.isus.emc.com.
lss.emc.com. 575 IN NS duribgm2.isus.emc.com.
lss.emc.com. 575 IN NS hopibgm2.isus.emc.com.
lss.emc.com. 575 IN NS corkibgm1.isus.emc.com.
;; ADDITIONAL SECTION:
duribgm1.isus.emc.com. 275 IN A 10.106.48.248
duribgm2.isus.emc.com. 275 IN A 10.106.48.249
root@xxx:/var/log/exim4# dig mailhubwc.lss.emc.com.
; <<>> DiG 9.8.1-P1 <<>> mailhubwc.lss.emc.com.
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60198
;; flags: qr rd ra; QUERY: 1, ANSWER: 8, AUTHORITY: 5, ADDITIONAL: 5
;; QUESTION SECTION:
;mailhubwc.lss.emc.com. IN A
;; ANSWER SECTION:
mailhubwc.lss.emc.com. 600 IN A 10.253.24.71
mailhubwc.lss.emc.com. 600 IN A 10.106.83.170
mailhubwc.lss.emc.com. 600 IN A 10.106.83.171
mailhubwc.lss.emc.com. 600 IN A 10.106.83.172
mailhubwc.lss.emc.com. 600 IN A 10.106.83.173
mailhubwc.lss.emc.com. 600 IN A 10.253.24.51
mailhubwc.lss.emc.com. 600 IN A 10.253.24.52
mailhubwc.lss.emc.com. 600 IN A 10.253.24.70
;; AUTHORITY SECTION:
lss.emc.com. 507 IN NS duribgm2.isus.emc.com.
lss.emc.com. 507 IN NS hopibgm2.isus.emc.com.
lss.emc.com. 507 IN NS duribgm1.isus.emc.com.
lss.emc.com. 507 IN NS corkibgm1.isus.emc.com.
lss.emc.com. 507 IN NS hopibgm1.isus.emc.com.
;; ADDITIONAL SECTION:
duribgm1.isus.emc.com. 207 IN A 10.106.48.248
duribgm2.isus.emc.com. 207 IN A 10.106.48.249
hopibgm1.isus.emc.com. 207 IN A 10.253.24.147
hopibgm2.isus.emc.com. 207 IN A 10.253.24.148
corkibgm1.isus.emc.com. 207 IN A 10.73.241.44
求高手指導 dns smtp 工作原理 以及原因 謝謝
|
|