Results 1 to 5 of 5

Thread: mailer-daemon sending email, server has been spofed?

  1. #1
    p_nyet is offline Loyal Member
    Join Date
    May 2009
    Location
    Jakarta
    Posts
    86
    Rep Power
    6

    Default mailer-daemon sending email, server has been spofed?

    My zimbra version:
    Release 6.0.2_GA_1912.RHEL5_20091020185714 CentOS5 FOSS edition.

    My server trying to sending email with using mail-daemon as sender to some one [not local user], and this is queue message:

    Code:
    Sender: mailer-daemon
    From host: localhost.localdomain
    From domain: 
    From IP: 127.0.0.1
    Recepients: anon@xx.com
    To domain:
    Content filter:
    possible my server has been spoofed? how to fixed?
    Please advise....

  2. #2
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,569
    Rep Power
    57

    Default

    Quote Originally Posted by p_nyet View Post
    My server trying to sending email with using mail-daemon as sender to some one [not local user], and this is queue message:
    Sitting in the queue does not mean that it's been sent anywhere. Is there just one message or more than one?

    Quote Originally Posted by p_nyet View Post
    possible my server has been spoofed? how to fixed?
    Please advise....
    What errors do you see in the log files that relate to these messages?
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  3. #3
    p_nyet is offline Loyal Member
    Join Date
    May 2009
    Location
    Jakarta
    Posts
    86
    Rep Power
    6

    Default

    Quote Originally Posted by phoenix View Post
    Sitting in the queue does not mean that it's been sent anywhere. Is there just one message or more than one?

    Two messages, and can't sent to recepients because network connections time out.

    What errors do you see in the log files that relate to these messages?
    I don't get any error here..

    Please advise.....

  4. #4
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,569
    Rep Power
    57

    Default

    Quote Originally Posted by p_nyet View Post
    I don't get any error here..
    You must have some information in the logs about that message, what do you see and what about the other part of my question?
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  5. #5
    p_nyet is offline Loyal Member
    Join Date
    May 2009
    Location
    Jakarta
    Posts
    86
    Rep Power
    6

    Default

    Bill,
    Thanks for your advise..

    There is message log:

    Nov 9 20:03:57 MAIL amavis[1283]: (01283-11) SEND via SMTP: <> -> <acceleratingkl34@orses.com>,ENVID=AM..20091109T13 0357Z@mail.mycompany.com 250 2.0.0 Ok, id=01283-11, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as 14BC4AF0006
    Nov 9 20:03:57 MAIL amavis[1283]: (01283-11) Blocked BANNED (.exe,.exe-ms,WU_Details_5a41d.exe), [201.252.108.128] [201.252.108.128] <acceleratingkl34@orses.com> -> <myuser@mycompany.com>, quarantine: banned-Lsi1Ju3kqjkP, Message-ID: <000d01ca613b$ff04f480$6400a8c0@acceleratingkl34 >, mail_id: Lsi1Ju3kqjkP, Hits: -, size: 32806, 150 ms
    Nov 9 20:03:57 MAIL postfix/smtp[10051]: B74D8AF0001: to=<myuser@mycompany.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=11, delays=11/0/0/0.15, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=01283-11, BOUNCE)
    Nov 9 20:03:57 MAIL postfix/qmgr[368]: B74D8AF0001: removed
    Nov 9 20:03:57 MAIL postfix/lmtp[8785]: 0DD89AF0002: to=<postmaster@mycompany.com>, relay=mail.mycompany.com[202.1.2.100]:7025, delay=0.06, delays=0.01/0/0/0.05, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)
    Nov 9 20:03:57 MAIL postfix/qmgr[368]: 0DD89AF0002: removed
    Nov 9 20:03:57 MAIL postfix/lmtp[14591]: 1172BAF0003: to=<myuser@mycompany.com>, relay=mail.mycompany.com[202.1.2.100]:7025, delay=0.07, delays=0/0/0/0.06, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)
    Nov 9 20:03:57 MAIL postfix/qmgr[368]: 1172BAF0003: removed
    Nov 9 20:03:58 MAIL postfix/smtp[14594]: connect to mx.quigibo.com[67.15.76.50]:25: Connection refused
    Nov 9 20:03:58 MAIL postfix/smtp[14594]: 14BC4AF0006: to=<acceleratingkl34@orses.com>, relay=none, delay=1.1, delays=0.01/0/1.1/0, dsn=4.4.1, status=deferred (connect to mx.quigibo.com[67.15.76.50]:25: Connection refused)
    Nov 9 20:03:58 MAIL postfix/smtpd[8777]: disconnect from host128.201-252-108.telecom.net.ar[201.252.108.128]


    Sitting in the queue does not mean that it's been sent anywhere. Is there just one message or more than one?
    Two messages, and can't sent to recepients because network connections time out.
    Last edited by p_nyet; 11-12-2009 at 02:09 AM.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. MTA service stopping and 1m later starting again?
    By ArcaneMagus in forum Administrators
    Replies: 5
    Last Post: 03-23-2010, 08:43 AM
  2. Problem in sending mails at Hosted Mail server
    By Unix Anand in forum Administrators
    Replies: 5
    Last Post: 03-26-2009, 06:51 AM
  3. Replies: 9
    Last Post: 02-25-2009, 04:39 AM
  4. failed to install zimbra cos of zmmailboxd
    By aljoshab in forum Installation
    Replies: 4
    Last Post: 12-09-2008, 02:33 AM
  5. Zimbra fails after working for 2 weeks
    By Linsys in forum Administrators
    Replies: 10
    Last Post: 10-07-2008, 12:42 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •