| Welcome to the Zimbra :: Forums! | |
Welcome, if you would like to post a comment please register.
We also encourage you to explore all things Zimbra with our team and members of the community.
|  | 
08-22-2010, 12:20 PM
| | | Strange email from MAILER-DAEMON One of our customers received a strange email from MAILER-DAEMON.
It is a spam-mail forwarded by the zimbra mailerdaemon.
Whats going wrong here? Quote:
Received: from mail.mydomain.xy (LHLO mail.mydomain.xy) (192.168.100.95) by
mail.mydomain.xy with LMTP; Sat, 21 Aug 2010 20:45:11 +0200 (CEST)
Received: from localhost (localhost.localdomain [127.0.0.1])
by mail.mydomain.xy (Postfix) with ESMTP id 065F03E8002
for <customer@mydomain.xy>; Sat, 21 Aug 2010 20:45:11 +0200 (CEST)
X-Virus-Scanned: amavisd-new at mydomain.xy
X-Spam-Flag: NO
X-Spam-Score: 3.892
X-Spam-Level: ***
X-Spam-Status: No, score=3.892 tagged_above=-10 required=5
tests=[BAYES_00=-1.9, FH_FROMEML_NOTLD=1.082,
MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_NJABL_PROXY=2.224,
RCVD_IN_RP_RNBL=1.31, RCVD_NUMERIC_HELO=1.164, T_FRT_CONTACT=0.01,
UNPARSEABLE_RELAY=0.001] autolearn=no
Received: from mail.mydomain.xy ([127.0.0.1])
by localhost (mail.mydomain.xy [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 078Nx1QqwR7r for <customer@mydomain.xy>;
Sat, 21 Aug 2010 20:45:07 +0200 (CEST)
Received: from mi-ob.rzone.de (mi-ob.rzone.de [81.169.146.149])
by mail.mydomain.xy (Postfix) with ESMTPS id 624F33E8001
for <customer@mydomain.xy>; Sat, 21 Aug 2010 20:45:05 +0200 (CEST)
X-RZG-FWD-BY: customer@mydomain.xy
Received: from RZmta-internal (client mail forwarder)
by mailin.webmailer.de (voltan mi19) (RZmta 23.5)
for <customer@mydomain.xy>; Sat, 21 Aug 2010 20:44:25 +0200 (MEST)
Message-ID: <R05c32m7LIZXjG.RZmta@mailin.rzone.de>
X-RZG-CLASS-ID: mi
Received: from apple2.w3link.net ([198.252.166.91])
by mailin.webmailer.de (voltan mi19) (RZmta 23.5)
with ESMTP id R05c32m7LIZXjG for <customer@mydomain.xy>;
Sat, 21 Aug 2010 20:44:25 +0200 (MEST)
Date: Sat, 21 Aug 2010 14:44:01 -0400
Received: from 84.122.131.85 ([84.122.131.85])
(authenticated user robblackey@protectplus.com)
by apple2.w3link.net (Kerio MailServer 6.6.2)
for customer@mydomain.xy;
Sat, 21 Aug 2010 14:43:48 -0400
To: customer@mydomain.xy
Subject: Die Vakanz fur Sie,Vakanz, Die Vakanz von Grand Exchange, Job als Testkaufer.
From: MAILER-DAEMON@mail.mydomain.xy | | 
08-23-2010, 02:08 AM
| | | more information Where to change the behavier, that emails without sender-adresses are forwarded by the Mailer-Daemon?
Thats no good. Especially in case of spam-mails.
Our customer ist very surprised receiving spam mails from the own zimbra-system (he thinks..)
Here some more information from the logfile: Quote:
Aug 21 20:44:03 post zmmailboxdmgr[6444]: status requested
Aug 21 20:44:03 post zmmailboxdmgr[6444]: status OK
Aug 21 20:45:05 post postfix/smtpd[7111]: connect from mi-ob.rzone.de[81.169.146.149]
Aug 21 20:45:05 post postfix/smtpd[7111]: setting up TLS connection from mi-ob.rzone.de[81.169.146.149]
Aug 21 20:45:05 post postfix/smtpd[7111]: Anonymous TLS connection established from mi-ob.rzone.de[81.169.146.149]: TLSv1 with cipher EDH-RSA-DES-CBC3-SHA (168/168 bits)
Aug 21 20:45:05 post postfix/smtpd[7111]: 624F33E8001: client=mi-ob.rzone.de[81.169.146.149]
Aug 21 20:45:05 post postfix/cleanup[7140]: 624F33E8001: message-id=<R05c32m7LIZXjG.RZmta@mailin.rzone.de>
Aug 21 20:45:05 post postfix/qmgr[29976]: 624F33E8001: from=<>, size=1432, nrcpt=1 (queue active)
Aug 21 20:45:05 post postfix/smtpd[7111]: disconnect from mi-ob.rzone.de[81.169.146.149]
Aug 21 20:45:07 post amavis[13131]: (13131-03) ESMTP::10024 /opt/zimbra/data/amavisd/tmp/amavis-20100820T134831-13131: <> -> <customer@indiray.de> SIZE=1432 Received: from post.indiray.de ([127.0.0.1]) by localhost (post.indiray.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP for <customer@indiray.de>; Sat, 21 Aug 2010 20:45:07 +0200 (CEST)
Aug 21 20:45:07 post amavis[13131]: (13131-03) Checking: 078Nx1QqwR7r [81.169.146.149] <> -> <customer@indiray.de>
Aug 21 20:45:09 post zmmailboxdmgr[7410]: status requested
Aug 21 20:45:09 post zmmailboxdmgr[7410]: status OK
Aug 21 20:45:10 post zmmailboxdmgr[7471]: status requested
Aug 21 20:45:10 post zmmailboxdmgr[7471]: status OK
Aug 21 20:45:11 post postfix/smtpd[7504]: connect from localhost.localdomain[127.0.0.1]
Aug 21 20:45:11 post postfix/smtpd[7504]: 065F03E8002: client=localhost.localdomain[127.0.0.1]
Aug 21 20:45:11 post postfix/cleanup[7140]: 065F03E8002: message-id=<R05c32m7LIZXjG.RZmta@mailin.rzone.de>
Aug 21 20:45:11 post postfix/smtpd[7504]: disconnect from localhost.localdomain[127.0.0.1]
Aug 21 20:45:11 post postfix/qmgr[29976]: 065F03E8002: from=<>, size=2229, nrcpt=1 (queue active)
Aug 21 20:45:11 post amavis[13131]: (13131-03) FWD via SMTP: <> -> <customer@indiray.de>,BODY=7BIT 250 2.0.0 Ok, id=13131-03, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as 065F03E8002
Aug 21 20:45:11 post amavis[13131]: (13131-03) Passed CLEAN, [81.169.146.149] [84.122.131.85] <> -> <customer@indiray.de>, Message-ID: <R05c32m7LIZXjG.RZmta@mailin.rzone.de>, mail_id: 078Nx1QqwR7r, Hits: 3.892, size: 1432, queued_as: 065F03E8002, 4641 ms
Aug 21 20:45:11 post postfix/smtp[7146]: 624F33E8001: to=<customer@indiray.de>, relay=127.0.0.1[127.0.0.1]:10024, delay=5.7, delays=0.09/0/2/3.7, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=13131-03, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as 065F03E8002)
Aug 21 20:45:11 post postfix/qmgr[29976]: 624F33E8001: removed
Aug 21 20:45:11 post postfix/lmtp[7508]: 065F03E8002: to=<customer@indiray.de>, relay=post.indiray.de[192.168.100.95]:7025, delay=0.17, delays=0.06/0/0/0.1, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)
Aug 21 20:45:11 post postfix/qmgr[29976]: 065F03E8002: removed
Aug 21 20:46:03 post zmmailboxdmgr[7780]: status requested
Aug 21 20:46:03 post zmmailboxdmgr[7780]: status OK
| | | Thread Tools | Search this Thread | | | | | Display Modes | Linear Mode | | Why Join? Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.  |