Email Security.cloud

 View Only

  • 1.  CheckTLS testing blocked

    Posted Mar 28, 2019 09:09 AM

    Similar to other requests about legitimate emails being blocked by MessageLabs, it looks like some of your MX hosts are blocking testing from CheckTLS.com (see below, 5 of 8 are blocked).  Either that or you have some failing MX hosts.

    I understand why your automated systems may see testing from CheckTLS as a threat.

    CheckTLS users, which include some of the largest financial institutions, health systems, insurers, and law offices world wide, do thorough testing of domains, some of which are protected by MessageLabs.  These tests probe every MX they can find looking at security.  No test ever actually sends an email (we have a strong abuse policy).

    CheckTLS has been testing for 9 years, growing 50% per year, and is reaching critical mass in the industry.  We do over a million tests a month now.

    But from MessageLab's viewpoint, you see more and more tests, targeting every one of your hosts, that never send an email.  I suspect this looks like an attack to you.

    Let me assure you, these tests are not an attack.  They are not a threat.  In fact, they are good for MessageLabs and Symantec.  It means more and more people are checking you out.

    These are either paying customers verifying that MessageLabs is doing what they say they do, or

    outside companies who email MessageLabs paying customers who are verifying that MessageLabs is secure, or

    potential MessageLabs customers who are looking at how MessageLabs works.

    All this long message is to respectfully request that MessageLabs and Symantec white list CheckTLS.com.  In as many places as you can.  We do not send email, we do not spam, we are not a hacker site.  Our users only have access to the test we publish on our web site.

    Please contact me personally if you have any questions or concerns.

    Thank you.

    --- Steve Shoemaker

    Principal, CheckTLS

     

    MX Server

    Pref

    Answer

    Connect

    HELO

    TLS

    Cert

    Secure

    From

    cluster1.eu.messagelabs.com 
    [85.158.142.97:25]

    10

    OK 
    (86ms)

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    cluster1.eu.messagelabs.com 
    [46.226.52.193:25]

    10

    OK 
    (1,080ms)

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    cluster1.eu.messagelabs.com 
    [46.226.53.49:25]

    10

    OK 
    (79ms)

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    cluster1.eu.messagelabs.com 
    [85.158.142.196:25]

    10

    OK 
    (85ms)

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    cluster1.eu.messagelabs.com 
    [46.226.52.97:25]

    10

    OK 
    (80ms)

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    FAIL

    cluster1a.eu.messagelabs.com 
    [52.59.133.150:25]

    20

    OK 
    (92ms)

    OK 
    (96ms)

    OK 
    (93ms)

    FAIL

    FAIL

    FAIL

    OK 
    (375ms)

    cluster1a.eu.messagelabs.com 
    [18.194.106.207:25]

    20

    OK 
    (90ms)

    OK 
    (94ms)

    OK 
    (91ms)

    FAIL

    FAIL

    FAIL

    OK 
    (367ms)

    cluster1a.eu.messagelabs.com 
    [52.28.91.133:25]

    20

    OK 
    (92ms)

    OK 
    (94ms)

    OK 
    (93ms)

    FAIL

    FAIL

    FAIL

    OK 
    (371ms)

    Average

     

    100%

    38%

    38%

    0%

    0%

    0%

    38%

     



  • 2.  RE: CheckTLS testing blocked

    Broadcom Employee
    Posted Apr 05, 2019 10:17 AM

    Hi Steve

    Can you advise exactly what it was you are checking? I did a check on the checktls.com site for symantec.com just a moment ago and got the below response:

    MX Server Pref Answer Connect HELO TLS Cert Secure From
    cluster1.eu.messagelabs.com
    [85.158.142.97:25]
    10 OK
    (80ms)
    OK
    (160ms)
    OK
    (83ms)
    OK
    (93ms)
    OK
    (364ms)
    OK
    (80ms)
    OK
    (81ms)
    cluster1.eu.messagelabs.com
    [46.226.52.97:25]
    10 OK
    (80ms)
    OK
    (153ms)
    OK
    (81ms)
    OK
    (90ms)
    OK
    (441ms)
    OK
    (79ms)
    OK
    (80ms)
    cluster1.eu.messagelabs.com
    [46.226.53.49:25]
    10 OK
    (79ms)
    OK
    (147ms)
    OK
    (80ms)
    OK
    (89ms)
    OK
    (352ms)
    OK
    (81ms)
    OK
    (80ms)
    cluster1.eu.messagelabs.com
    [85.158.142.196:25]
    10 OK
    (81ms)
    OK
    (151ms)
    OK
    (81ms)
    OK
    (92ms)
    OK
    (371ms)
    OK
    (81ms)
    OK
    (82ms)
    cluster1.eu.messagelabs.com
    [46.226.52.193:25]
    10 OK
    (1,084ms)
    OK
    (145ms)
    OK
    (81ms)
    OK
    (91ms)
    OK
    (521ms)
    OK
    (80ms)
    OK
    (80ms)
    cluster1a.eu.messagelabs.com
    [52.28.91.133:25]
    20 OK
    (91ms)
    OK
    (93ms)
    OK
    (91ms)
    FAIL FAIL FAIL OK
    (365ms)
    cluster1a.eu.messagelabs.com
    [18.194.106.207:25]
    20 OK
    (86ms)
    OK
    (90ms)
    OK
    (88ms)
    FAIL FAIL FAIL OK
    (352ms)
    cluster1a.eu.messagelabs.com
    [52.59.133.150:25]
    20 OK
    (90ms)
    OK
    (94ms)
    OK
    (91ms)
    FAIL FAIL FAIL OK
    (366ms)
    Average   100% 100% 100% 63% 63% 63% 100%

    The only failures are the ones we would expect to see fail due to the way in which our infrastructure is set out so I'm not seeing the same failures that you are.

    Regards

    Ian



  • 3.  RE: CheckTLS testing blocked

    Posted Apr 05, 2019 11:18 AM

    Ian ---

    Hi.  As your test shows, the CheckTLS results now fine.  A few hours after I posted they became good again.

    The results showed many of your hosts as off-line when I posted.  I was alerted to the problem from a very large bank customer of yours who also contacted your support.

    Because email is so resiliant, I don't know of annyone who was seeing actual email failures, but test scores for a number of Symantec customers were way down.  We just assumed you were blocking CheckTLS.

    So I am relieved that Symantec/MessageLabs is not blocking CheckTLS.

    But I would request that you white-list us none the less, or put a note in your CRM to the effect that CheckTLS is one of the good guys, even if a ton of tests come your way for some reason.

    Thank you for your responses, and your efforts to secure the Internet and Internet email in particular!

    --- Steve

    CheckTLS Principal



  • 4.  RE: CheckTLS testing blocked

    Posted Apr 25, 2019 09:33 AM

    Ian and company ---

    It looks like CheckTLS got blacklisted at messagelabs.com again.

    I've heard from several of your large customers that CheckTLS monitoring is reporting failures.

    Can you let me know ASAP if we can fix this?  And how to prevent it in the future?

    Thank you!

    --- Steve



  • 5.  RE: CheckTLS testing blocked

    Posted Apr 26, 2019 10:23 AM

    Hi Steve,

     

    It looks working now. Could you kindly shre the error message that you have received from our towers when you tested?

     

    Jun



  • 6.  RE: CheckTLS testing blocked

    Posted Apr 26, 2019 11:41 AM
      |   view attached

    Hi Jun,

    To further iterate on this issue, we transact business over 1000s of emails on a daily basis and use the CheckTLS.com process before each transaction (due to the sensitivity of the data shared).

    If there is a failure or block here, our business transactions cease, so it's imperative these checks remain possible via your mail servers. 

    I've attached one example of many that caused problems for our business yesterday. 

     

    Is there anything further than can be done here?

     

    Michael

    Attachment(s)

    txt
    Example1.txt   6 KB 1 version