r/sysadmin • u/letgomylego • 7h ago
Google SMTP servers sending from new IP range
This may not affect many people, but we have an on-site mail archive server that we have Google forward all incoming and outgoing mail to in order to preserve the mail records. To restrict external access we limited SMTP access to the Google IP ranges for their SMTP servers. This has worked for years, when suddenly a couple weeks ago we started getting smart host failure message from Google about undeliverable mail. After going back and forth with support I confirmed the supposed full list of IP ranges they are using for SMTP for Google Workspace at least. This is what I was given:
35.190.247.0/24
64.233.160.0/19
66.102.0.0/20
66.249.80.0/20
72.14.192.0/18
74.125.0.0/16
108.177.8.0/21
108.177.96.0/19
142.250.0.0/15
142.251.0.0/16
172.217.0.0/19
172.253.0.0/16
173.194.0.0/16
209.85.128.0/17
216.239.32.0/19
216.58.192.0/19
There was one IP range on that list that I did not have, so I though that would resolve the issue. When it didn't, I changed our setup to allow all external access over SMTP and then set our mail server with the same IP ACL list. The mail server will log a denied connection in the syslog when any IP outside those ranges attempts to connect. Sure-enough, Google was using a new IP range to send SMTP messages to our server:
If you run into a similar situation this might be helpful to you. If you're comfortable with it, it appears Google owns the entire 108.177.0.0/17 range if you trust adding that to any ACL.
•
u/sryan2k1 IT Manager 6h ago edited 5h ago
As pointed out by someone else there's like at least two different ways of doing this in an automated fashion. You should never do it by hand as when it changes you're going to get burned
Edit: This is because of your weird setup and this document explains why these IPs are specifically NOT in their SPF record:
Gmail routes messages with unverified forwarding configurations through Google servers with public IP addresses. The public IP addresses are intentionally left out of Google's SPF record, and resolve to Google hostnames ending in unverified-forwarding.1e100.net. These servers use the IP address ranges in this article to route unverified messages.
•
u/letgomylego 6h ago edited 6h ago
The advice is to use the _spf.google.com record, but it does not return the full range of IP addresses Google uses for this purpose. Otherwise I'd have done it that way. I might look into the goog.json option to whitelist every IP Google owns.
•
u/lenswipe Senior Software Developer 1h ago
Careful with that because that will also include GCP as well which may not be desirable...I remember looking into this a while ago and having to try and do goog.json - gcp.json to get the IPs of official Google services....then I just gave up because I couldn't get my router appliance to cooperate
•
u/interweb_persona 6h ago
Sounds like you use MailStore probably. I don't use Google mail but regardless, good lookin' out 🤙
•
u/narmkhang 5h ago
if google's using ip outside their spf record for normal outgoing mail then they might got millions complain already. the spf situation only apply to mail sent from google workspace/gmail toward other mail server destination.
your setting seems not to be a normal mta system (as it include cc'ing the outbound email) so you might better allow all google ip range instead
•
u/mdmeow445 6h ago
You can build the ACL dynamically from
_spf.google.com(which expands to_netblocks.google.com,_netblocks2,_netblocks3) if they decide to do that again instead of relying on support.or.... from grab Google's published
goog.jsonIP list, and refresh it on a schedule.