postfix maillog: does this look suspicious?

Discussion in 'Server Operation' started by vcha, May 31, 2014.

  1. vcha

    vcha New Member

    Hi, all. I went though the Virtual Users And Domains With Postfix, Courier, MySQL And SquirrelMail and everything seems to work fine. My setup should be exactly the same as the howto. It's a great howto.

    Even though everthing is working fine, email sending and recieving, I took a look at /var/log/maillog and found some suspecious lines.

    I checked with the Open Relay Checker at MxToolbox (http://mxtoolbox.com/diagnostic.aspx) and came back negative. Also, checked if my IP has been blacklisted, it's not.

    Here's a sample. Please let me know what you think. FYI, I slightly modified the urls, IPs, and time stamps.

    Code:
    May 29 12:00:00 myserver postfix/smtp[9761]: 8DFDXXXXD5: to=<operator603@msbraininjuQWERTYrylawyers.com>, relay=none, delay=65764, delays=65734/0.02/30/0, dsn=4.4.1, status=deferred (connect to mail.msbrQWERTYaininjurylawyers.com[111.131.29.170]:25: Connection timed out)
    
    May 29 12:00:00 myserver postfix/smtp[9790]: 6EBXXXX7D7: to=<operator961@blbQWERTYlawyers.com>, relay=smtp.secureserver.net[111.178.213.37]:25, delay=3.8, delays=0.01/0.01/3.7/0.08, dsn=5.1.0, status=bounced (host smtp.secureserver.net[68.178.213.37] said: 550 5.1.0 <> Blank From: addresses are not allowed. Please provide a valid From: IB501  <http://x.co/srbounce> (in reply to MAIL FROM command))
    
    May 29 12:00:00 myserver postfix/smtp[9726]: F0AXXXX078A: to=<noreply130@contractQWERTYlitigationlawyers.com>, relay=none, delay=172707, delays=172677/0.02/30/0, dsn=4.4.1, status=deferred (connect to nlmx1.ca.einsteinindustries.com[111.43.202.171]:25: Connection timed out
    
    May 29 12:00:00 myserver postfix/smtp[9726]: connect to nlmx1.ca.einsteiniQWERTYndustries.com[111.43.202.171]:25: Connection timed out
    
    May 29 12:00:00 myserver postfix/smtp[9721]: 044XXXX07D7: to=<customerssupport537@rwlaQWERTYwyers.com>, relay=mx01.263xmail.com[111.150.74.49]:25, delay=1.7, delays=0.01/0.01/0.85/0.84, dsn=5.0.0, status=bounced (host mx01.263xmail.com[111.150.74.49] said: 550 customerssupport537@rwlaQWERTYwyers.com:user not exist (in reply to RCPT TO command))
    The urls are related and can be within a couple seconds of eachother.

    A couple hundred, similar to the sample, over the last few days.
     

Share This Page