- 论坛徽章:
- 0
|
下面是一封邮件的一部分, 对于smtp 协议 我的了解不多 求解释。
发送端 163.com
接受端 emc.com
Received: from mxhub36.corp.emc.com (10.253.xxx.xxx) by MXHUB202.corp.emc.com
(10.253.xxx.xxx) with Microsoft SMTP Server (TLS) id 14.3.266.1; Wed, 28 Oct
2015 23:01:00 -0400
Received: from mailusrhubprd54.lss.emc.com (10.106.xx.xx) by
mxhub36.corp.emc.com (10.254.xx.xx) with Microsoft SMTP Server id 8.3.327.1;
Wed, 28 Oct 2015 23:00:38 -0400
Received: from mailusrigwprd53.lss.emc.com (mailusrigwprd53.lss.emc.com
[128.221.234.31]) by mailusrhubprd54.lss.emc.com
(Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.0) with ESMTP id t9T30bfD023745
(version=TLSv1.2 cipher=xxxxxxxx bits=256 verify=OK) for
<xxx@emc.com>; Wed, 28 Oct 2015 23:00:38 -0400
Received: from mx0a-00154901.pphosted.com (mx0a-00154901.pphosted.com
[67.231.149.39]) by mailusrigwprd53.lss.emc.com
(Sentrion-MTA-4.3.1/Sentrion-MTA-4.3.0) with ESMTP id t9T30atk025034
(version=TLSv1.2 cipher=xxxxxxx bits=256 verify=NO) for
<xxx@emc.com>; Wed, 28 Oct 2015 23:00:37 -0400
Received: from pps.filterd (m0075501.ppops.net [127.0.0.1]) by
mx0a-00154901.pphosted.com (8.15.0.59/8.15.0.59) with SMTP id t9T2waj0025295
for <xxx@emc.com>; Wed, 28 Oct 2015 23:00:36 -0400
Received: from m50-138.163.com (m50-138.163.com [123.125.50.138]) by
mx0a-00154901.pphosted.com with ESMTP id 1xu1tx21cc-1 for
<xxx@emc.com>; Wed, 28 Oct 2015 23:00:36 -0400
可以看到邮件先被 m50-138.163.com [123.125.50.138]拿到了, 然后 m0075501.ppops.net [127.0.0.1] 本机转了一下 就到来 mx0a-00154901.pphosted.com[67.231.149.39]
按照理解 163 应该直接和emc 的smtp 服务器建立连接,但是它没有这么做,是转到了一个pphosted.com的服务器,由它帮忙转出去,这样做应该可以,因为国内的ip 被封锁得差不多了吧。
有一个问题 接受方为什么会收这封邮件?
因为这个ip 属于pphosted.com 而不是163.com 这相当于 有人的**显示它是山东人发信,但它自称是 广东人,然后就按照广东人的发件地址收下来了,如果这样很容易做到 垃圾邮件应该很容易吧! 比如 我自称是yahoo.com 发信服务器 给google 的每个用户发广告信息。
root@xxx:/var/log/exim4# dig -x 67.231.149.39
; <<>> DiG 9.8.1-P1 <<>> -x 67.231.149.39
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6427
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 6, ADDITIONAL: 4
;; QUESTION SECTION:
;39.149.231.67.in-addr.arpa. IN PTR
;; ANSWER SECTION:
39.149.231.67.in-addr.arpa. 1800 IN PTR mx0a-00154901.pphosted.com.
;; AUTHORITY SECTION:
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.net.
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.com.
149.231.67.in-addr.arpa. 1800 IN NS ns1.proofpoint.com.
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.org.
149.231.67.in-addr.arpa. 1800 IN NS pdns99.ultradns.biz.
149.231.67.in-addr.arpa. 1800 IN NS ns3.proofpoint.com.
;; ADDITIONAL SECTION:
ns1.proofpoint.com. 848 IN A 208.84.67.208
ns1.proofpoint.com. 847 IN AAAA 2620:100:9000:1::d0
ns3.proofpoint.com. 847 IN A 208.84.66.208
ns3.proofpoint.com. 847 IN AAAA 2620:100:9004:1::d0
下面一步 我没看懂 接收方 mailusrigwprd53.lss.emc.com [128.221.234.31]
因为我的理解 服务器先查看mx 纪录 日志如下
root@xxx:/var/log/exim4# dig -t mx emc.com
; <<>> DiG 9.8.1-P1 <<>> -t mx emc.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 29816
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 5, ADDITIONAL: 0
;; QUESTION SECTION:
;emc.com. IN MX
;; ANSWER SECTION:
emc.com. 120 IN MX 10 mailhub.lss.emc.com.
emc.com. 120 IN MX 20 mailhubwc.lss.emc.com.
;; AUTHORITY SECTION:
emc.com. 600 IN NS duribgm2.isus.emc.com.
emc.com. 600 IN NS corkibgm1.isus.emc.com.
emc.com. 600 IN NS hopibgm2.isus.emc.com.
emc.com. 600 IN NS duribgm1.isus.emc.com.
emc.com. 600 IN NS hopibgm1.isus.emc.com.
mx 纪录是2条
emc.com. 120 IN MX 10 mailhub.lss.emc.com.
emc.com. 120 IN MX 20 mailhubwc.lss.emc.com.
那么 它应该发给 mailhub.lss.emc.com. 或者 mailhubwc.lss.emc.com. 这2个服务器, 不知道 如何来了一台 mailusrigwprd53.lss.emc.com [128.221.234.31] 服务器?
也就是说最终接收方的 邮件地址应该是 mailhub.lss.emc.com. 或者 mailhubwc.lss.emc.com. 的IP, 但是目前看来也不是的? 这是为什么呢?
是因为dns 的原因吗?
root@xxx:/var/log/exim4# dig mailhub.lss.emc.com.
; <<>> DiG 9.8.1-P1 <<>> mailhub.lss.emc.com.
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24083
;; flags: qr rd ra; QUERY: 1, ANSWER: 20, AUTHORITY: 5, ADDITIONAL: 2
;; QUESTION SECTION:
;mailhub.lss.emc.com. IN A
;; ANSWER SECTION:
mailhub.lss.emc.com. 95 IN A 10.253.24.25
mailhub.lss.emc.com. 95 IN A 10.253.24.26
mailhub.lss.emc.com. 95 IN A 10.253.24.51
mailhub.lss.emc.com. 95 IN A 10.253.24.52
mailhub.lss.emc.com. 95 IN A 10.253.24.63
mailhub.lss.emc.com. 95 IN A 10.253.24.64
mailhub.lss.emc.com. 95 IN A 10.253.24.70
mailhub.lss.emc.com. 95 IN A 10.253.24.71
mailhub.lss.emc.com. 95 IN A 10.106.48.26
mailhub.lss.emc.com. 95 IN A 10.106.48.27
mailhub.lss.emc.com. 95 IN A 10.106.48.28
mailhub.lss.emc.com. 95 IN A 10.106.48.29
mailhub.lss.emc.com. 95 IN A 10.106.48.137
mailhub.lss.emc.com. 95 IN A 10.106.48.138
mailhub.lss.emc.com. 95 IN A 10.106.83.170
mailhub.lss.emc.com. 95 IN A 10.106.83.171
mailhub.lss.emc.com. 95 IN A 10.106.83.172
mailhub.lss.emc.com. 95 IN A 10.106.83.173
mailhub.lss.emc.com. 95 IN A 10.253.24.23
mailhub.lss.emc.com. 95 IN A 10.253.24.24
;; AUTHORITY SECTION:
lss.emc.com. 575 IN NS hopibgm1.isus.emc.com.
lss.emc.com. 575 IN NS duribgm1.isus.emc.com.
lss.emc.com. 575 IN NS duribgm2.isus.emc.com.
lss.emc.com. 575 IN NS hopibgm2.isus.emc.com.
lss.emc.com. 575 IN NS corkibgm1.isus.emc.com.
;; ADDITIONAL SECTION:
duribgm1.isus.emc.com. 275 IN A 10.106.48.248
duribgm2.isus.emc.com. 275 IN A 10.106.48.249
root@xxx:/var/log/exim4# dig mailhubwc.lss.emc.com.
; <<>> DiG 9.8.1-P1 <<>> mailhubwc.lss.emc.com.
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60198
;; flags: qr rd ra; QUERY: 1, ANSWER: 8, AUTHORITY: 5, ADDITIONAL: 5
;; QUESTION SECTION:
;mailhubwc.lss.emc.com. IN A
;; ANSWER SECTION:
mailhubwc.lss.emc.com. 600 IN A 10.253.24.71
mailhubwc.lss.emc.com. 600 IN A 10.106.83.170
mailhubwc.lss.emc.com. 600 IN A 10.106.83.171
mailhubwc.lss.emc.com. 600 IN A 10.106.83.172
mailhubwc.lss.emc.com. 600 IN A 10.106.83.173
mailhubwc.lss.emc.com. 600 IN A 10.253.24.51
mailhubwc.lss.emc.com. 600 IN A 10.253.24.52
mailhubwc.lss.emc.com. 600 IN A 10.253.24.70
;; AUTHORITY SECTION:
lss.emc.com. 507 IN NS duribgm2.isus.emc.com.
lss.emc.com. 507 IN NS hopibgm2.isus.emc.com.
lss.emc.com. 507 IN NS duribgm1.isus.emc.com.
lss.emc.com. 507 IN NS corkibgm1.isus.emc.com.
lss.emc.com. 507 IN NS hopibgm1.isus.emc.com.
;; ADDITIONAL SECTION:
duribgm1.isus.emc.com. 207 IN A 10.106.48.248
duribgm2.isus.emc.com. 207 IN A 10.106.48.249
hopibgm1.isus.emc.com. 207 IN A 10.253.24.147
hopibgm2.isus.emc.com. 207 IN A 10.253.24.148
corkibgm1.isus.emc.com. 207 IN A 10.73.241.44
求高手指导 dns smtp 工作原理 以及原因 谢谢
|
|