Hi,
Someone is faking smtp authentication on our server and sending out emails. This is from header of one of such emails -
---------------
Received: from 178.89.32.193 (account <info@domain.com> HELO domain.com) by domain.com (CommuniGate Pro SMTP 5.2.3) with ESMTPA id 086072675 for <info@domain.com>; Fri, 7 Oct 2011 16:35:15 +0600
(our actual domain name substituted by domain.com)
---------------
Even the maillog shows
info@domain.com as authenticated but there is no such user as
info@domain.com in our user list. I checked main.cf, it seems normal.
Any clues on how this is happening. I need to block it immediately before our domain gets marked for spamming.
Thanks in advance for helping.
Regards
Gorav
Recent comments
10 hours 22 min ago
12 hours 49 min ago
1 day 44 min ago
1 day 3 hours ago
1 day 7 hours ago
1 day 13 hours ago
1 day 23 hours ago
2 days 1 hour ago
2 days 9 hours ago
2 days 10 hours ago