<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MTA &amp;quot;Received:&amp;quot; header in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/231333#M44588</link>
    <description>&lt;P&gt;One day later (after turning off the Anti-Spam and using the SPF) I realized that&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;in &lt;STRONG&gt;MTA blade logs&lt;/STRONG&gt; (Email Headers tab) string (localhost [127.0.0.1]) doesn't occur anymore&lt;/LI&gt;&lt;LI&gt;but the gateway still &lt;STRONG&gt;adds the &lt;FONT color="#FF0000"&gt;(localhost [127.0.0.1])&lt;/FONT&gt;&lt;/STRONG&gt; string to email header &lt;STRONG&gt;when sending it to the next hop&lt;/STRONG&gt; (this can be easily checked by showing the email header on the next hop)&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Thu, 31 Oct 2024 10:14:54 GMT</pubDate>
    <dc:creator>benko2</dc:creator>
    <dc:date>2024-10-31T10:14:54Z</dc:date>
    <item>
      <title>MTA "Received:" header</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/203506#M38345</link>
      <description>&lt;P&gt;I'm running Check Point MTA version 8120.991002021 on active-standby cluster (R81.20 JHF Take 41). It runs as the organization MX record. Only myhostname=gw.example.com configured in $FWDIR/conf/mta_postfix_options.cf. No changes in $FWDIR/conf/mail_security_config.&lt;/P&gt;&lt;P&gt;MTA is working as expected. But for every email from internet to our organization MTA adds headers like this:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Received: from localhost (localhost [127.0.0.1])&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;by gw.example.com (Postfix) with ESMTP id 4T7zDy6xdyz6PXZ&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;for &amp;lt;info@example.com&amp;gt;; Mon, 8 Jan 2024 16:56:02 +0100 (CET)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;X-MTA-CheckPoint: {659C1B12-0-F35B6A0A-33EA}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Category=, control=Content Anti Spam&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;X-Control-Analysis: str=0001.0A682F22.659C1B13.0003,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Received: from mail-il1-f170.google.com &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;(localhost [127.0.0.1])&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;by gw.example.com (Postfix) with ESMTPS id 4T7zDy5jnKz6PXY&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;for &amp;lt;info@example.com&amp;gt;; Mon, 8 Jan 2024 16:56:02 +0100 (CET)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Received: by mail-il1-f170.google.com with SMTP id e9e14a558f8ab-3608bd50cbeso4579985ab.3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;for &amp;lt;info@example.com&amp;gt;; Mon, 08 Jan 2024 07:56:02 -0800 (PST)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;The problem for me is the red text. Why MTA doesn't fill the real IP address of the google mail server and uses the localhost [127.0.0.1] instead?&lt;/P&gt;&lt;P&gt;Emails with such headers are marked as spam when they are forwared to Office 365.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 15:22:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/203506#M38345</guid>
      <dc:creator>benko2</dc:creator>
      <dc:date>2024-01-18T15:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: MTA "Received:" header</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/204103#M38500</link>
      <description>&lt;P&gt;If I had to guess, it's because of how traffic is directed to Postfix (the underlying MTA used).&lt;BR /&gt;In any case, this is probably worth a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 22:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/204103#M38500</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-24T22:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: MTA "Received:" header</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/229047#M44133</link>
      <description>&lt;P&gt;This is the response from the Check Point Support case:&lt;/P&gt;&lt;P&gt;The MTA header is modified because of the AntiSpam blade, it cannot inspect the encrypted emails, AntiSpam cannot process encrypted emails and instead forwards them to the gateway at 127.0.0.1 and it is a limitation.&lt;/P&gt;&lt;P&gt;The AntiSpam flow is as follows&lt;/P&gt;&lt;P&gt;Internet -&amp;gt; Gateway AntiSpam -&amp;gt; MTA -&amp;gt; next hop&lt;/P&gt;&lt;P&gt;AntiSpam inspects the mail before it gets decrypted by MTA.&lt;/P&gt;&lt;P&gt;The R&amp;amp;D team confirmed this requirement needs to be addressed over an RFE [Ref: sk71840]. You can contact your Local Sales Engineer/Team, who may help submit a Request for Enhancement (RFE), per sk71840.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 08:32:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/229047#M44133</guid>
      <dc:creator>benko2</dc:creator>
      <dc:date>2024-10-07T08:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: MTA "Received:" header</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/231250#M44551</link>
      <description>&lt;P&gt;At the moment I resolved my problem by:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;turning off the &lt;STRONG&gt;Anti-Spam &amp;amp; Email Security blade&lt;/STRONG&gt; and&lt;/LI&gt;&lt;LI&gt;activating the &lt;STRONG&gt;SPF&lt;/STRONG&gt; according to sk146412&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 30 Oct 2024 13:07:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/231250#M44551</guid>
      <dc:creator>benko2</dc:creator>
      <dc:date>2024-10-30T13:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: MTA "Received:" header</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/231333#M44588</link>
      <description>&lt;P&gt;One day later (after turning off the Anti-Spam and using the SPF) I realized that&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;in &lt;STRONG&gt;MTA blade logs&lt;/STRONG&gt; (Email Headers tab) string (localhost [127.0.0.1]) doesn't occur anymore&lt;/LI&gt;&lt;LI&gt;but the gateway still &lt;STRONG&gt;adds the &lt;FONT color="#FF0000"&gt;(localhost [127.0.0.1])&lt;/FONT&gt;&lt;/STRONG&gt; string to email header &lt;STRONG&gt;when sending it to the next hop&lt;/STRONG&gt; (this can be easily checked by showing the email header on the next hop)&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 31 Oct 2024 10:14:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-quot-Received-quot-header/m-p/231333#M44588</guid>
      <dc:creator>benko2</dc:creator>
      <dc:date>2024-10-31T10:14:54Z</dc:date>
    </item>
  </channel>
</rss>

