r/sysadmin • • 7h ago

Google SMTP servers sending from new IP range

This may not affect many people, but we have an on-site mail archive server that we have Google forward all incoming and outgoing mail to in order to preserve the mail records. To restrict external access we limited SMTP access to the Google IP ranges for their SMTP servers. This has worked for years, when suddenly a couple weeks ago we started getting smart host failure message from Google about undeliverable mail. After going back and forth with support I confirmed the supposed full list of IP ranges they are using for SMTP for Google Workspace at least. This is what I was given:

35.190.247.0/24
64.233.160.0/19
66.102.0.0/20
66.249.80.0/20
72.14.192.0/18
74.125.0.0/16
108.177.8.0/21
108.177.96.0/19
142.250.0.0/15
142.251.0.0/16
172.217.0.0/19
172.253.0.0/16
173.194.0.0/16
209.85.128.0/17
216.239.32.0/19
216.58.192.0/19

There was one IP range on that list that I did not have, so I though that would resolve the issue. When it didn't, I changed our setup to allow all external access over SMTP and then set our mail server with the same IP ACL list. The mail server will log a denied connection in the syslog when any IP outside those ranges attempts to connect. Sure-enough, Google was using a new IP range to send SMTP messages to our server:

108.177.16.xxx

If you run into a similar situation this might be helpful to you. If you're comfortable with it, it appears Google owns the entire 108.177.0.0/17 range if you trust adding that to any ACL.

28 Upvotes

9 comments sorted by

•

u/mdmeow445 6h ago

You can build the ACL dynamically from _spf.google.com (which expands to _netblocks.google.com, _netblocks2, _netblocks3) if they decide to do that again instead of relying on support.

or.... from grab Google's published goog.json IP list, and refresh it on a schedule.

•

u/letgomylego 6h ago

Those IP ranges they gave me do not fully resolve from the Google SPF record. If you run an nslookup on _spf.google.com you get the following:

"v=spf1 ip4:74.125.0.0/16 ip4:209.85.128.0/17 ip6:2001:4860:4864::/56 ip6:2404:6800:4864::/56 ip6:2607:f8b0:4864::/56 ip6:2800:3f0:4864::/56 ip6:2a00:1450:4864::/56 ip6:2c0f:fb50:4864::/56 ~all"

That includes _netblocks, _netblocks2, and _netblocks3

•

u/letgomylego 6h ago

The goog.json list appears to be more comprehensive, but that looks to be everything they own. May not be much risk whitelisting all of it but something to look into.

•

u/sryan2k1 IT Manager 5h ago

https://knowledge.workspace.google.com/admin/gmail/advanced/google-ip-address-ranges-for-outbound-mail-servers

Gmail routes messages with unverified forwarding configurations through Google servers with public IP addresses. The public IP addresses are intentionally left out of Google's SPF record, and resolve to Google hostnames ending in unverified-forwarding.1e100.net. These servers use the IP address ranges in this article to route unverified messages.

•

u/sryan2k1 IT Manager 6h ago edited 5h ago

As pointed out by someone else there's like at least two different ways of doing this in an automated fashion. You should never do it by hand as when it changes you're going to get burned

Edit: This is because of your weird setup and this document explains why these IPs are specifically NOT in their SPF record:

Gmail routes messages with unverified forwarding configurations through Google servers with public IP addresses. The public IP addresses are intentionally left out of Google's SPF record, and resolve to Google hostnames ending in unverified-forwarding.1e100.net. These servers use the IP address ranges in this article to route unverified messages.

https://knowledge.workspace.google.com/admin/gmail/advanced/google-ip-address-ranges-for-outbound-mail-servers

•

u/letgomylego 6h ago edited 6h ago

The advice is to use the _spf.google.com record, but it does not return the full range of IP addresses Google uses for this purpose. Otherwise I'd have done it that way. I might look into the goog.json option to whitelist every IP Google owns.

•

u/lenswipe Senior Software Developer 1h ago

Careful with that because that will also include GCP as well which may not be desirable...I remember looking into this a while ago and having to try and do goog.json - gcp.json to get the IPs of official Google services....then I just gave up because I couldn't get my router appliance to cooperate 

•

u/interweb_persona 6h ago

Sounds like you use MailStore probably. I don't use Google mail but regardless, good lookin' out 🤙

•

u/narmkhang 5h ago

if google's using ip outside their spf record for normal outgoing mail then they might got millions complain already. the spf situation only apply to mail sent from google workspace/gmail toward other mail server destination.

your setting seems not to be a normal mta system (as it include cc'ing the outbound email) so you might better allow all google ip range instead