Digital Ocean, G Suite, SendGrid, Namecheap

Sto avendo un bel po’ di problemi a far funzionare l’email con il mio nuovo server Discourse.

Sto utilizzando DigitalOcean per l’hosting. Non sembra esserci alcun problema da quella parte: il server è attivo e riesco ad accedere.

Utilizzo G Suite come email di amministrazione, ma non per gestire le email del sito.

Per DNS e registrazione del dominio uso Namecheap.

Utilizzo SendGrid come provider SMTP per il sito. Ho provato ogni combinazione di verifica possibile che mi è venuta in mente: usando il dominio di primo livello, usando il sottodominio, rimuovendo i nomi di dominio dalle informazioni DNS fornite da SendGrid per inserirle in Namecheap, aggiungendo il dominio a un whitelist di G Suite (è davvero necessario?).

Riesco a far inviare le email. Dai log di SendGrid vedo che le email di test sono state inviate da Discourse, ma non vengono mai recapitate. Sul messaggio di errore di SendGrid appare la seguente informazione:

Ricevuto da gmail-smtp-in.l.google.com

Bloccato

Il server Gmail ha bloccato il recapito di questo messaggio. Anche se non riproveremo a inviare questo messaggio, tenteremo di inviare nuovi messaggi a questo indirizzo in futuro.

Puoi visualizzare tutti gli indirizzi nel tuo [Blocchi]
Risposta completa dal server Gmail:

550 5.7.1 Email non autenticata da do.c non è accettata a causa della policy DMARC 5.7.1 del dominio. Contatta l’amministratore del dominio do.c se si tratta di una email legittima. Visita 5.7.1 per saperne di più sull’iniziativa DMARC. m55-v6si4266550qtc.214 - gsmtp

Questo restringe il problema esclusivamente a SendGrid e alla verifica del dominio, o c’è qualcos’altro? In ogni caso, SendGrid non vuole mai verificare la configurazione una volta che ho incollato le informazioni fornite nella sezione DNS di Namecheap.

As it says, Your dmarc record is not correct.
You can find the correct dmarc value in sendgrid and that should be updated into your dns.
Please correct it or contact sendgrid for assistance.

Just by chance, is it a one-click install app from DO?

@itsbhanusharma, yes. I did the one-click Discourse setup. Everything went very smoothly up until the SMTP setup. I’ve put in a ticket with SendGrid and am waiting for their response.

What is the notification email in your discourse admin? I think that needs to be corrected.

It is currently set at noreply@unconfigured.discourse.org.

When going through the setup wizard I chose for the system to handle mail so the one G Suite account I have to accompany the site info@mydomain.com is not flooded with messages, if I’m even understanding it correctly.

It can’t be @unconfigured.discourse.org in any case.

Please change it to @(your-discourse-domain) or the domain that’s verified with sparkpost first. I hope that’ll fix it.

Also, you may have to tweak your smtp port as DO may be blocking common SMTP ports on your account.

@itsbhanusharma, I made your suggested changes and it worked, although the message did go to my spam folder and is still showing “via SendGrid”. I’m guessing the way to solve that is through domain verification with SendGrid and that will be between me and them.

Exactly. They should have provided you some DNS records to create. Those records take care of the whole verification process.

Great. Thanks so much for the help. Now I’m wondering if I need to go back and undo some of the things I did like whitelisting my G Suite account with SendGrid and stuff like that.

Not immediately, first step that I’d take is to make sure sendgrid is happy with my domain and then I’d test the quality of emails sent using mail-tester.com or similar service.

Once that’s all fixed then only I’d lax any whitelist

As it’s set up now, while going through all the various forums trying to troubleshoot my problem I followed one tutorial that had me go into my G Suite settings and whitelist Digital Ocean, not SendGrid like I said. Because that wasn’t related to my actual problem is it necessary anymore or could it cause any problems in the future?

It actually wasn’t even whitelisting. It was SMTP relay service where I added my droplet IP address.

While it won’t really cause any problems as long as you retain the IP it can possibly cause spam whitelist if you leave the IP and other owner is a notorious spammer.

So it’s okay to remove it. Also, DO is not sending emails from it’s own IP either. Those are sent from sendgrid.

Great. Thanks again for the help.

While I’m able to get emails delivered to people who register for the forum now (albeit in their spam folder), I now am having trouble sending admin emails. When I attempt to make a member of the forum and admin, I get the message saying to check my email. My single G suite email address is info@mydomain.com. SendGrid can never seem to send a message from info@mydomain.com to info@mydomain.com. This is quite a problem because I can’t make anyone else an admin because I can never finish the process. There error I get from SendGrid is:

The mydomain.com server blocked this message from being delivered. While we won’t try to send this message again, we will attempt to send new messages to this address in the future.

You can view all addresses in your Blocks suppression group. Learn more.

Full response from the mydomain.com server:

error dialing remote address: dial tcp 167.89.106.64:0->162.255.119.167:25: i/o timeout

You should check the mail debugging document. The problem is between sendgrid and your mail server that is refusing connections from sendgrid.

I’m using Namecheap, so I had set up all of my SendGrid information CNAME records, but in the “Mail Settings” portion of the Advanced DNS page I didn’t have anything selected. Once I selected Gmail everything began to work. I swear I’d thought I had read something about if you’re setting up SendGrid you don’t need anything the Mail Settings section. Things appear to be working now.