Your whole subnet is not on the Global Bad Sender list. For instance, if I look up 2.59.168.150, it has no bad reputation. However, if I look up 2.59.168.20 it shows:
- The host has been observed sending spam in a format that is similar to snow shoe spamming techniques.
- The host is unauthorized to send email directly to email servers.
Which typically means that the IP has had detections associated with it in the past and it is very likely not a static IP, so does not have confidence. You can request removal of IPs with the above detections and they will be removed, but they often get re-listed quickly due to being associated with a block of IPs that problematic activity is detected from (snowshoe spam attacks). The best recourse is to use a business class static IP (to get rid of the low confidence "The host is unauthorized to send email directly to email servers."), or otherwise continue requesting delisting.
------------------------------
---------------------------------------------
Support Engineer
* Integrated Cyber Defense Exchange
* Messaging Gateway
* Packet Shaper
Symantec Enterprise Division
Broadcom Software
------------------------------
Original Message:
Sent: Dec 20, 2022 09:53 AM
From: Walter Russo
Subject: ip reputation investigation doesn't work
Hi Community,
I want to know how to delist my entire subnet 2.59.168.0/24 from **** because I have switched to new subnet last August but there is no way to delist entire subnet or also single ip from ip reputation investigation portal. I think reputation data is not update because my entire infrastructure is clean. My colocation provider Worldstream has tried to delist entire subnet without success.
I have worked for Symantec in Italy for some years but my contacts don't work anymore in Broadcom and it is difficult to solve the situation.
Unfortunately I'm not a customer but I'm a service provider.
Can you help me?
Thanks in advance.
Best regards
Walter