Unkown SPAM in Postfix mail queue

Discussion in 'Server Operation' started by flameproof, Nov 8, 2014.

  1. flameproof

    flameproof Member

    I just wonder, I found following entry (actually a few) in the Postfix mail queue:


    Code:
    apache@159159_vps-host.com 	hilkias-melo@bol.com.br 	1.17 kB 	host mx3.bol.com.br[200.147.36.13] said: 450 4.7.1 Client host rejected: cannot find your hostname, [211.111.169.169] (in reply to RCPT TO command)
    159159_vps-host.com (changed) resolves to my VPS IP. Obviously the email is not from me. I presume a spammer tries to use my MX to send spam. What worries me of course is if there are successful attempts to spam via my MX.

    In the maillog I find entries like this one (50 per Minute):

    Code:
    Nov  8 03:21:56 159159_vps postfix/smtp[7683]: AD30C506001E: to=<hilkias-melo@bol.com.br>, relay=mx3.bol.com.br[200.147.36.13]:25, delay=187781, delays=187773/2.4/5/0.19, dsn=4.7.1, status=deferred (host mx3.bol.com.br[200.147.36.13] said: 450 4.7.1 Client host rejected: cannot find your hostname, [211.111.169.169] (in reply to RCPT TO command))
    [211.111.169.169] (changed) is my IP.

    My question is, is everything normal or do I need to worry?
     
  2. srijan

    srijan New Member HowtoForge Supporter

    Do u have reverse DNS setup correctly ?
     
  3. mmidgett

    mmidgett Member

    That looks like they are sending email from your server. Might want to fix that. You should be able to pinpoint the authencated sender in the system logs and then shutdown that account.
     
  4. flameproof

    flameproof Member

    Sorry for the long silence. I changed VPS to one with more space, more RAM, more OS selection, and still cheaper. It seems on the new server (CentOS 6.6) I don't have that problem. So I don't really bother to look into the old servers issue.

    But I get sometimes that dreadfull type=AAAA: Host not found when I use my servers SMTP (I usually use the ISPs SMTP).

    But I should probably open another thread for that issue.


    Code:
    Dec  2 09:12:02 vps postfix/qmgr[5608]: 753DBCB6: from=<justme@mydomain.com>, size=737896, nrcpt=1 (queue active)
    Dec  2 09:12:02 vps postfix/smtp[16993]: 753DBCB6: to=<receiver@email.com>, relay=none, delay=0.07, delays=0.07/0/0/0, dsn=5.4.4, status=bounced (Host or domain name not found. Name service error for name=email.com type=AAAA: Host not found)
    Dec  2 09:12:02 vps postfix/cleanup[16992]: 86C16CC3: message-id=<20141202141202.86C16CC3@vps.mydomain.com>
    Dec  2 09:12:02 vps postfix/qmgr[5608]: 86C16CC3: from=<>, size=2400, nrcpt=1 (queue active)
    Dec  2 09:12:02 vps postfix/bounce[16998]: 753DBCB6: sender non-delivery notification: 86C16CC3
    Dec  2 09:12:02 vps postfix/qmgr[5608]: 753DBCB6: removed
    Dec  2 09:12:02 vps dovecot: imap(justme.mydomain): Connection closed bytes=738126/741574
     

Share This Page