Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-06-2009, 09:23 AM
Junior Member
 
Posts: 5
Default [SOLVED] Somebody is sending spam through my server??

In my administrator daily report I can see that someone is spamming through my server.

Most active senders
XXXXXX
2 jobnet@ams.dk
2 info@shapex.eu
2 bounce_79db54a0b2408fa8a98f843e83cb@...tromail s.com
1 japanesev42@schatz.de
1 fatties@sermicro.com
1 prepositioning@santiagoecintra.es
1 rapprochementsu2@securita.pl

I am not sure why they are able to send through my server, but i was told that one of my users probably have a virus of some sort.

I know that I should look at the log file, but I don’t know what to search for.

I have tried to search the forum, but i dont know any keywords for my problem.

Please, help me find the leak.
Reply With Quote
  #2 (permalink)  
Old 07-06-2009, 09:40 AM
Zimbra Consultant & Moderator
 
Posts: 12,392
Default

They are not sending spam through your server, that's a total for people sending spam TO your server.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 07-06-2009, 10:08 AM
Junior Member
 
Posts: 5
Default

Peew! Thanks Phoenix.

I have gotten some messages from my self, to my self. Do you know why that is happening?

Sorry for my newbie questions. I think thats something is wrong, but i don't know what. One of my messages was blocked by spamhouse.org
Reply With Quote
  #4 (permalink)  
Old 07-06-2009, 10:12 AM
Zimbra Consultant & Moderator
 
Posts: 12,392
Default

Quote:
Originally Posted by mazive View Post
Peew! Thanks Phoenix.
You can always check if you're an open relay (by default Zimbra is not an open relay) by using one of the internet check sites (do an internet search for them)

Quote:
Originally Posted by mazive View Post
I have gotten some messages from my self, to my self. Do you know why that is happening?

Sorry for my newbie questions. I think thats something is wrong, but i don't know what. One of my messages was blocked by spamhouse.org
Are the messages really from you? Perhaps they're NDR spam, have a look in the log files
and see what errors (if any) you're getting and post them here plus the headers from a message that was rejected by spamhaus.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 07-06-2009, 10:45 AM
Junior Member
 
Posts: 5
Default

It looked like the message was sent from me, to me, but sadly i have deleted the message.

The message returned from spamhouse was:
The mail system

<crj@itq.dk>: host relay.inet.tele.dk[194.182.148.151] said: 554 Service
unavailable; Client host [212.242.114.238] blocked using
rblplus.combined.foo; http://www.spamhaus.org/query/bl?ip=212.242.114.238
(in reply to RCPT TO command)

Reporting-MTA: dns; mail.mazive.dk
X-Postfix-Queue-ID: 9D7375A901
X-Postfix-Sender: rfc822; morten@azm.dk
Arrival-Date: Fri, 3 Jul 2009 16:09:39 +0200 (CEST)

Final-Recipient: rfc822; crj@itq.dk
Original-Recipient: rfc822;crj@itq.dk
Action: failed
Status: 5.0.0
Remote-MTA: dns; relay.inet.tele.dk
Diagnostic-Code: smtp; 554 Service unavailable; Client host [212.242.114.238]
blocked using rblplus.combined.foo;
http://www.spamhaus.org/query/bl?ip=212.242.114.238
Reply With Quote
  #6 (permalink)  
Old 07-06-2009, 11:16 AM
Junior Member
 
Posts: 5
Default

I tried: telnet relay-test.mail-abuse.org
and got this
System appeared to reject relay attempts
Connection closed by foreign host.

That should be ok, maybe i'm just paranoid.

Sadly i have deleted the spam message from myself to myself.

This is the MDS message i got.

The mail system

<crj@itq.dk>: host relay.inet.tele.dk[194.182.148.151] said: 554 Service
unavailable; Client host [212.242.114.238] blocked using
rblplus.combined.foo; http://www.spamhaus.org/query/bl?ip=212.242.114.238
(in reply to RCPT TO command)

Reporting-MTA: dns; mail.mazive.dk
X-Postfix-Queue-ID: 9D7375A901
X-Postfix-Sender: rfc822; morten@azm.dk
Arrival-Date: Fri, 3 Jul 2009 16:09:39 +0200 (CEST)

Final-Recipient: rfc822; crj@itq.dk
Original-Recipient: rfc822;crj@itq.dk
Action: failed
Status: 5.0.0
Remote-MTA: dns; relay.inet.tele.dk
Diagnostic-Code: smtp; 554 Service unavailable; Client host [212.242.114.238]
blocked using rblplus.combined.foo;
http://www.spamhaus.org/query/bl?ip=212.242.114.238
Reply With Quote
  #7 (permalink)  
Old 07-06-2009, 12:12 PM
Zimbra Consultant & Moderator
 
Posts: 12,392
Default

If you read the error message here: The Spamhaus Project - PBL it tells you that you must relay your outbound mail through your ISPs mail server. You might also be able to get it removed from the block list if you look at the second option on that page.
__________________
Regards


Bill

Last edited by phoenix : 07-06-2009 at 12:19 PM.
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com