Answer the question
In order to leave comments, you need to log in
Exim sending spam, how to overcome?
Good afternoon. Exim question. I got it by inheritance. The problem is that [email protected] started receiving non-delivery reports. Letters are spam. Moreover, these letters are not in the Exim logs, only non-delivery reports. But there are other sent letters from the [email protected] mailbox, which does not exist at all.
piece of log
2016-12-18 12:15:35 no host name found for IP address 192.168.61.21
2016-12-18 12:15:35 1cITot-0001eu-77 spam acl condition: warning - spamd connection to 127.0.0.1, port 783 failed: Connection refused
2016-12-18 12:15:35 1cITot-0001eu-77 spam acl condition: all spamd servers failed
2016-12-18 12:15:35 1cITot-0001eu-77 H=(mydomain.ru) [192.168.61.21] I=[82....]:25 Warning: ACL "warn" statement skipped: condition test deferred
2016-12-18 12:15:35 1cITot-0001eu-77 <= [email protected] H=(mydomain.ru) [192.168.61.21] I=[82...]:25 P=esmtp S=1336 [email protected] from <[email protected]> for [email protected]
2016-12-18 12:15:37 1cITot-0001eu-77 SMTP error from remote mail server after MAIL FROM:<[email protected]> SIZE=2399: host mta7.am0.yahoodns.net [66.196.118.37]: 421 4.7.0 [GL01] Message from (82...) temporarily deferred - 4.16.50. Please refer to http://postmaster.yahoo.com/errors/postmaster-21.html
2016-12-18 12:15:38 no host name found for IP address 192.168.61.21
2016-12-18 12:15:38 H=(mydomain.ru) [192.168.61.21] I=[82...]:25 sender verify fail for <[email protected]>: Unrouteable address
2016-12-18 12:15:38 H=(mydomain.ru) [192.168.61.21] I=[82...]:25 F=<[email protected]> rejected RCPT <[email protected]>: Sender verify failed
2016-12-18 12:15:38 unexpected disconnection while reading SMTP command from (mydomain.ru) [192.168.61.21] I=[82...]:25
2016-12-18 12:15:42 1cITot-0001eu-77 => [email protected] R=dnslookup T=remote_smtp H=mta7.am0.yahoodns.net [98.138.112.37] X=TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128 C="250 ok dirdel"
2016-12-18 12:15:42 1cITot-0001eu-77 Completed
Answer the question
In order to leave comments, you need to log in
Judging by the logs, the mail comes from the host 192.168.61.21
Look for changes in the files, temporarily block the receipt of mail from this host or even temporarily put a mail service on it so that spam does not go. And keep looking for holes in your site.
However, someone may use your 192.168.61.21 as a smart host. Is it open to the outside by any chance?
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question