Discussion in 'Server Operation' started by mi-lan, Feb 19, 2012.

  mi-lan

    mi-lan

    Hello, I use Qmail on mail server. From today is my IP on many blacklist, reason is spam. In mail.log I find many spam from one IP, here is log:
    Feb 19 23:07:10 mailserver qmail-scanner[13046]: Clear:RC:0( 0.297978 1262 [email protected] [email protected] You_Have_One_New_Message <[email protected]> mailserver132968922977713046-unpacked:1262
    I stopped also apache, but spam go next.
  mi-lan

    mi-lan

    # cat /etc/tcp.smtp
    telnet mailserver 25
    Trying mailserver...
    Connected to mailserver.
    Escape character is '^]'.
    220 ESMTP
    helo test
    mail from: [email protected]
    250 ok
    rcpt to: [email protected]
    553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)
    Last edited: Feb 20, 2012
  falko

    falko

    As a first measure you can block that IP:

    Then find out if you are an open relay:

    If you are not, try to find out if the spammer is abusing a web application:

    If so, update your web applications. If that's not the case, the spammer probably knows the login details of an email account, so you might have to change your passwords.

