How can I fix the error: Client host [XXX] blocked using zen.spamhaus.org; Error: open resolver;

SpamHaus RBL is blocking all email if your server is using an open resolver. For example, public DNS resolvers like Google, Quad9, Cloudflare DNS or via any DNS server that is attempting a high volume of queries against SpamHaus without being registered with them. The SpamHaus RBL no longer accepts RBL DNS queries from any public resolver, including if you are using it as a forwarder. The mail logs will indicate the issue like this:

Client host [XXX.XXX.XXX.XXX] blocked using zen.spamhaus.org; Error: open resolver; https://www.spamhaus.org/returnc/pub/203.0.113.1

How To Fix

There are a number of options:

1. Replace any public DNS servers that your server is currently using with a local one, or your ISPs.
2. If you are using a local DNS resolver, remove the public DNS resolvers as forwarders.
3. As a last resort, you can remove zen.spamhaus.org from Warden ->  Mail Server Settings -> DNSBLs and replace it with alternatives like b.barracudacentral.org, bl.spamcop.net, psbl.surriel.com, or spam.spamrats.com. More information about DNSBLs we recommend can be found here.

  • zen.spamhaus.org, open resolver
  • 6 Users Found This Useful
Was this answer helpful?

Related Articles

How can I fix the error: Host '127.0.0.1' is not allowed to connect to this MariaDB server?

When looking at the server mail log you see this: Apr 4 11:01:15 alma amavis[3540852]:...

ClamAV will not start. How can I fix the ClamAV error: daily.{c[vl]d,inc} was not met?

ClamAV refuses to start and when viewing the status you see...

How can I fix any statistics generation problems?

Missing the Warden Crontab Entry There is a crontab entry that will update Warden statistics...

How can I fix the error: "milter-reject: END-OF-MESSAGE from..." in the log and found the AV in error (cannot read /etc/clam.d/scan.conf).

Cloudlinux / Imunify360 added their own version of ClamAV to their repo which accidentally...

How can I fix the error: Can't connect to TCP port 10024 on 127.0.0.0 [Address already in use] when trying to start Amavis?

When trying to start Amavis you see this in the mail log: Oct 02 03:20:15 condor3648 systemd[1]:...