On Fri, Jul 15, 2022 at 7:33 AM Claudio Kuenzler <ck@claudiokuenzler.com> wrote:
Datawire is off the hooks. Turning around the wheel and going North, towards the lands of Hetzner.

The MX-Record of bluwein.ch resolves to sendmailtoserver.bluwein.ch, which sometimes answers with a A record pointing to Hetzner, sometimes with a different A record pointing to I-Netpartner in Germany.
I didn't receive a confirmation that they forwarded my complaint/contact request to their customer. From I-Netpartner however I received a call today.
The domain "bluwein.ch" is indeed registered to the owners of the UCEProtect DNSBL and has been for many years. According to the infos I obtained, UCEProtect sometimes buys previously used domains, turns off any MX record for one year and then switch on the MX records again. All received mail is then immediately flagged as spam because "only spam systems would send e-mails to a previously unavailable domain".

Whether or not this domain is used for "catching typo errors" is speculation. I personally think the domain name is way too close to the widely used bluewin.ch domain. When I look at our relay, we see all kinds of typo errors relating to bluewin.ch, e.g. buewin.ch, bluwiin.ch and many more variations.

We have now internally resolved this blacklisting problem by adjusting our mail relay's (Postfix) transport rule, bouncing all e-mails destined to bluwein.ch:

# Do not send mails to the following domains
bluwein.ch error:Admiral Ackbar knows this is a trap

Maybe this solution comes in handy for others going down the same path.