Brian Candler B.Candler at pobox.com
Thu Oct 21 14:41:39 EAT 2004

Mail to afnog at afnog.org is being rejected when it hits 'ensim.cfi.co.ug'
with a 'relaying denied' error - see bounce attached.

This is a good example of why it's *bad* to have backup MX machines if
they've not been correctly configured :-)

afnog.org       preference = 10, mail exchanger = gemin.cfi.co.ug
afnog.org       preference = 20, mail exchanger = ensim.cfi.co.ug
afnog.org       preference = 30, mail exchanger = ip.cfi.co.ug
afnog.org       preference = 5, mail exchanger = wawa.eahd.or.ug

Of these four MX records, gemin.cfi.co.ug does not have a A record,
ensim at cfi.co.ug rejects mail to afnog at afnog.org with 'relay denied', and
so does ip.cfi.co.ug

I suggest you either remove all the backup MX records, or else modify the
configurations on the those mailservers. Use telnet to test them (see



# telnet ensim.cfi.co.ug 25
Connected to ensim.cfi.co.ug.
Escape character is '^]'.
220 ensim.cfi.co.ug ESMTP Sendmail 8.11.6/8.11.6; Thu, 21 Oct 2004 09:13:22 +0300
helo wombat
250 ensim.cfi.co.ug Hello dsl-212-74-113-65.access.uk.tiscali.com [], pleased to meet you
mail from:<>
250 2.1.0 <>... Sender ok
rcpt to:<afnog at afnog.org>
550 5.7.1 <afnog at afnog.org>... Relaying denied
