Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-02-2010, 09:56 PM
Intermediate Member
 
Posts: 23
Default Zimbra Spam problem

Hello,

I've been having spam come in lately from just IP addresses (not reporting any hostname and no reverse lookup entries).

The zimbra.log shows entries such as this:
Code:
Feb  2 18:05:57 mail postfix/smtpd[2716]: connect from unknown[109.94.16.70]
Feb  2 18:06:00 mail amavis[7072]: (07072-18) Checking: NqysLox9Q3J2 [109.94.16.70] <email@domainname> -> <email@domainname>
Feb  2 18:06:00 mail amavis[7072]: (07072-18) Passed BAD-HEADER, [109.94.16.70][109.94.16.70] <email@domainname> -> <email@domainname>, quarantine: badh-NqysLox9Q3J2, mail_id: NqysLox9Q3J2, Hits: -, size: 697, queued_as: 658EE685401A,
628 ms
I've replaced the email address with just email@domainname. I left the incoming IP as it is.

Zimbra is configured so it requires a FQDN and reverse DNS lookup. It doesn't seem to be taking that into account as it allows the email attempt to go through.

Any hints of what I would need to change to prevent these from going through?

Thanks.
Reply With Quote
  #2 (permalink)  
Old 02-02-2010, 10:06 PM
Moderator
 
Posts: 7,928
Default

Code:
su - zimbra
zmlocalconfig | grep -i restriction
__________________
Reply With Quote
  #3 (permalink)  
Old 02-03-2010, 12:19 AM
Intermediate Member
 
Posts: 23
Default

Here are results from that

Code:
postfix_smtpd_client_restrictions = reject_unauth_pipelining
postfix_smtpd_data_restrictions = reject_unauth_pipelining
Reply With Quote
  #4 (permalink)  
Old 02-03-2010, 12:24 AM
Moderator
 
Posts: 7,928
Default

And the following please
Code:
su - zimbra
zmprov gacf | grep -i mtarestriction
__________________
Reply With Quote
  #5 (permalink)  
Old 02-03-2010, 07:03 AM
Intermediate Member
 
Posts: 23
Default

Code:
zimbraMtaRestriction: reject_invalid_hostname
zimbraMtaRestriction: reject_non_fqdn_hostname
zimbraMtaRestriction: reject_non_fqdn_sender
zimbraMtaRestriction: reject_rbl_client dnsbl.njabl.org
zimbraMtaRestriction: reject_rbl_client cbl.abuseat.org
zimbraMtaRestriction: reject_rbl_client zen.spamhaus.org
zimbraMtaRestriction: reject_rbl_client bl.spamcop.net
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.