Hi,
Someone is faking smtp authentication on our server and sending out emails. This is from header of one of such emails -
---------------
Received: from 178.89.32.193 (account <info@domain.com> HELO domain.com) by domain.com (CommuniGate Pro SMTP 5.2.3) with ESMTPA id 086072675 for <info@domain.com>; Fri, 7 Oct 2011 16:35:15 +0600
(our actual domain name substituted by domain.com)
---------------
Even the maillog shows
info@domain.com as authenticated but there is no such user as
info@domain.com in our user list. I checked main.cf, it seems normal.
Any clues on how this is happening. I need to block it immediately before our domain gets marked for spamming.
Thanks in advance for helping.
Regards
Gorav
Recent comments
1 day 14 hours ago
1 day 23 hours ago
2 days 2 hours ago
2 days 3 hours ago
2 days 4 hours ago
2 days 6 hours ago
2 days 8 hours ago
2 days 9 hours ago
3 days 1 hour ago
3 days 2 hours ago