All inbound mail to Messaging Gateway (SMG) is being deferred with SMTP response "421 4.3.2 MAX connections exceeded: - message rejected"
The Brightmail Engine / bmserver_log shows the following errors and warnings:
2021-05-03T16:12:43+02:00 (ERROR:7968.52459234562): [2083] DNS TXT query for "234.56.101.113.zodiac.brightmail.com" failed unexpectedly
2021-05-03T16:12:43+02:00 (WARNING:7968.52459234562): [2085] Latency threshold for feature "Symantec DNS Reputation Server: zodiac.brightmail.com" exceeded. Feature has been suspended.
Release :
Component : Brightmail Engine, Symantec Global Bad Sender IP List
The Symantec Global Bad Senders IP reputation service is unable to resolve DNS queries.
To restore mail flow, disable the Symantec Global Bad Sender IP feature while the DNS issue can be investigated.
Disabling the Global Bad Senders list will prevent DNS issues from causing mail acceptance to fail but the underlying DNS issues will need to be investigated and resolved.