-
-
Notifications
You must be signed in to change notification settings - Fork 2k
Sending SPAM #628
Copy link
Copy link
Closed
Description
Greetings
First of all, thanks for the great job you've been putting in this project !
The issue
My server is sending out SPAM. Or at least tries to. I don't really get how this is possible.
It seems to allow to send emails from "localhost" but how does emails even ended up coming from localhost, no clue there.
By the way, would it be better to update:
smtpd_recipient_restrictions =
reject_rbl_client zen.spamhaus.org, # this is already there
reject_rhsbl_reverse_client dbl.spamhaus.org, # to add ?
reject_rhsbl_helo dbl.spamhaus.org, # to add ?
reject_rhsbl_sender dbl.spamhaus.org # to add ?
Log of a SPAM trying to go out
Jun 8 06:28:46 post postfix/smtpd[1933]: 49ED9862737: client=localhost[127.0.0.1]
Jun 8 06:28:46 post postfix/cleanup[1973]: 49ED9862737: message-id=<pth7j94exf2pe0v11h3jj58t.1939171108191@MY_DOMAIN.COM>
Jun 8 06:28:46 post postfix/qmgr[1261]: 49ED9862737: from=<kmyu@MY_DOMAIN.COM>, size=1916, nrcpt=7 (queue active)
Jun 8 06:28:46 post amavis[1962]: (01962-12) Passed CLEAN {RelayedOpenRelay}, [61.91.169.238]:55145 [61.91.169.238] <kmyu@MY_DOMAIN.COM> -> <1@something.com>,<2@something.com>,<3@something.com>,<4@something.com>,<5@something.com>,<6@something.com>,<1@something.com
1@something.com
7@something.com>, Queue-ID: 6428786272C, Message-ID: <pth7j94exf2pe0v11h3jj58t.1939171108191@MY_DOMAIN.COM>, mail_id: klc4vFn2xxxH, Hits: -1.098, size: 1572, queued_as: 49ED9862737, dkim_sd=mail:swanest.com, 992 ms
Jun 8 06:28:46 post postfix/smtp[2017]: 6428786272C: to=<1@something.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=67, delays=66/0/0/0.99, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 49ED9862737)
Jun 8 06:28:46 post postfix/smtp[2017]: 6428786272C: to=<2@something.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=67, delays=66/0/0/0.99, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 49ED9862737)
Jun 8 06:28:46 post postfix/smtp[2017]: 6428786272C: to=<3@something.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=67, delays=66/0/0/0.99, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 49ED9862737)
Jun 8 06:28:46 post postfix/smtp[2017]: 6428786272C: to=<4@something.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=67, delays=66/0/0/0.99, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 49ED9862737)
Jun 8 06:28:46 post postfix/smtp[2017]: 6428786272C: to=<5@something.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=67, delays=66/0/0/0.99, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 49ED9862737)
Jun 8 06:28:46 post postfix/smtp[2017]: 6428786272C: to=<6@something.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=67, delays=66/0/0/0.99, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 49ED9862737)
Jun 8 06:28:46 post postfix/smtp[2017]: 6428786272C: to=<1@something.com
1@something.com
7@something.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=67, delays=66/0/0/0.99, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 49ED9862737)
Jun 8 06:28:47 post postfix/smtp[2033]: 49ED9862737: host mx.spamexperts.com[31.204.154.237] said: 451-91.134.254.3 is not yet authorized to deliver mail from <kmyu@MY_DOMAIN.COM> 451 to <1@something.com
1@something.com
7@something.com>. Please try later. (in reply to RCPT TO command)
Jun 8 06:28:47 post postfix/smtp[2055]: 49ED9862737: to=<5@something.com>, relay=spamfilter.lhric.org[166.109.20.141]:25, delay=1, delays=0/0/0.69/0.32, dsn=2.0.0, status=sent (250 2.0.0 Message received OK [id=C0291062296@LH-SPAMFILTER2.LHRIC.local])
Jun 8 06:28:48 post postfix/smtp[2037]: 49ED9862737: to=<3@something.com>, relay=hawaiianelectric-com.mail.protection.outlook.com[216.32.180.42]:25, delay=2.6, delays=0/0/1.3/1.4, dsn=2.6.0, status=sent (250 2.6.0 <pth7j94exf2pe0v11h3jj58t.1939171108191@MY_DOMAIN.COM> [InternalId=4037269261920, Hostname=MWHPR03MB2701.namprd03.prod.outlook.com] 10080 bytes in 0.194, 50.676 KB/sec Queued mail for delivery)
Jun 8 06:28:49 post postfix/smtp[2043]: 49ED9862737: to=<6@something.com>, relay=southplainscollege-edu.mail.protection.outlook.com[207.46.163.42]:25, delay=3.6, delays=0/0/2.2/1.4, dsn=2.6.0, status=sent (250 2.6.0 <pth7j94exf2pe0v11h3jj58t.1939171108191@MY_DOMAIN.COM> [InternalId=71051643978381, Hostname=DM3PR1101MB1181.namprd11.prod.outlook.com] 10029 bytes in 0.186, 52.623 KB/sec Queued mail for delivery)
Jun 8 06:28:50 post postfix/smtp[2036]: 49ED9862737: to=<4@something.com>, relay=locke.lewiscenter.org[163.150.129.103]:25, delay=3.8, delays=0/0/2.5/1.3, dsn=2.0.0, status=sent (250 Ok: queued as A92CD362842)
Jun 8 06:29:00 post postfix/smtp[2035]: 49ED9862737: to=<1@something.com>, relay=mail.bookrescue.com[66.147.242.173]:25, delay=14, delays=0/0/8.7/5.2, dsn=5.0.0, status=bounced (host mail.bookrescue.com[66.147.242.173] said: 550 No Such User Here (in reply to RCPT TO command))
Jun 8 06:29:04 post postfix/smtp[2033]: 49ED9862737: to=<1@something.com
1@something.com
7@something.com>, relay=mx.spamexperts.com[198.7.58.151]:25, delay=18, delays=0/0/2.7/16, dsn=4.0.0, status=deferred (host mx.spamexperts.com[198.7.58.151] said: 451-91.134.254.3 is not yet authorized to deliver mail from <kmyu@MY_DOMAIN.COM> 451 to <1@something.com
1@something.com
7@something.com>. Please try later. (in reply to RCPT TO command))
Jun 8 06:29:28 post postfix/smtp[2025]: 49ED9862737: to=<2@something.com>, relay=gpepublishing.com[72.52.226.16]:25, delay=43, delays=0/0/22/21, dsn=2.0.0, status=sent (250 OK id=1dIqwc-000Jod-Kv)
Jun 8 06:29:28 post postfix/bounce[2060]: 49ED9862737: sender non-delivery notification: E33AF86273B
Jun 8 06:37:02 post postfix/smtp[1613]: 49ED9862737: host mx.spamexperts.com[69.64.57.52] said: 451-91.134.254.3 is not yet authorized to deliver mail from <kmyu@MY_DOMAIN.COM> 451 to <1@something.com
1@something.com
7@something.com>. Please try later. (in reply to RCPT TO command)
Jun 8 06:37:04 post postfix/smtp[1613]: 49ED9862737: to=<1@something.com
1@something.com
7@something.com>, relay=mx.spamexperts.com[198.7.58.151]:25, delay=498, delays=483/0.07/14/1.1, dsn=4.0.0, status=deferred (host mx.spamexperts.com[198.7.58.151] said: 451-91.134.254.3 is not yet authorized to deliver mail from <kmyu@MY_DOMAIN.COM> 451 to <1@something.com
1@something.com
7@something.com>. Please try later. (in reply to RCPT TO command))
I just removed email addresses to protect privacy. The email seems to come from "kmyu@MY_DOMAIN.COM" which does not even exists...
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels