Barracuda blacklists are badly broken
Filed under: barracudaI've gotten two bounced emails in the last two days from two different hosting companies using Barracuda appliances. I was a little baffled when I read the bounce report:
<address@domain.com>: host apollo.utilicomnet.com[209.4.188.122] said: 554 Service unavailable; Client host [mail.develix.com] blocked using Barracuda Reputation; http://www.barracudanetworks.com/reputation/?r=1&ip=74.92.173.86 (in reply to end of DATA command)
Now what's interesting is that 74.92.173.86 is not the IP address of mail.develix.com:
$ host mail.develix.com mail.develix.com has address 69.168.53.29
Also we can verify that Barracuda doesn't really block mail.develix.com by checking mxtoolbox.
This lead me to inspect the mail headers, where it became obvious that Barracuda is checking the IP address of the MUA, not the IP address of the MTA. I think this qualifies as completely busted. It also appears to be an upstream issue since I received two bounces from two separate ISP's in two different countries. My guess is that Barracuda pushed an update out a few days ago and now millions of emails will be incorrectly bounced.
In any case, while this is nice case of fail, it gets better when I tried to report the issue to Barracuda: "Sorry, but you'll have to report it to the ISP". Um, yeah, I should worry about your customers? Don't think so champ. In any case, I did notify the ISP, cause I'm a nice guy, but I suspect that they will be clueless (otherwise why did they buy a Barracuda?) so I'm not hopeful.






