Hi Ewilen, thanks for your suggestion. The IP address I found in the log file all point to our router gateway instead of the individual PCs. So I won't be able to pinpoint which PC is it. But at least it's an improvement over Zimbra Admin's 127.0.0.1 local loop which doesn't make sense at all.
Will it be helpful if I post the spam message header? (Note that I have replace our domain for security reason)
Received: from 192.168.100.99 (LHLO mail.mydomain.com) (192.168.100.99) by
mail.mydomain.com with LMTP; Fri, 24 Sep 2010 01:56:30 +0800 (SGT)
Received: from localhost (localhost.localdomain [127.0.0.1])
by mail.mydomain.com (Postfix) with ESMTP id 2789E54061
for <user@mydomain.com>; Fri, 24 Sep 2010 01:56:21 +0800 (SGT)
X-Virus-Scanned: amavisd-new at mail.mydomain.com
X-Spam-Flag: NO
X-Spam-Score: 6.525
X-Spam-Level: ******
X-Spam-Status: No, score=6.525 tagged_above=-10 required=6.6
tests=[ALL_TRUSTED=-1.8, AWL=-3.997, BASE64_LENGTH_79_INF=1.496,
BAYES_50=0.001, FH_FROMEML_NOTLD=2.696, HTML_IMAGE_ONLY_24=1.552,
HTML_MESSAGE=0.001, HTML_TAG_BALANCE_HEAD=1.334,
NORMAL_HTTP_TO_IP=0.001, URIBL_BLACK=1.955, URIBL_PH_SURBL=1.787,
URIBL_SBL=1.499] autolearn=spam
Received: from mail.mydomain.com ([127.0.0.1])
by localhost (mail.mydomain.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id rK3zfTTQb0j9; Fri, 24 Sep 2010 01:56:19 +0800 (SGT)
Received: from mail.mydomain.com (localhost.localdomain [127.0.0.1])
by mail.mydomain.com (Postfix) with ESMTP id 1854F5405D
for <spam._napzjmlc@mail.mydomain.com>; Fri, 24 Sep 2010 01:56:19 +0800 (SGT)
To:
spam._napzjmlc@mail.mydomain.com
Message-ID: <5162268.14.1285264579097.JavaMail.root@mail.mydom ain.com>
Subject: zimbra-spam-report:
user@mydomain.com: spam
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_Part_13_23348857.1285264579096"
X-Zimbra-Spam-Report-Sender:
user@mydomain.com
X-Zimbra-Spam-Report-Type: spam
X-Originating-IP: [192.168.100.99]
Date: Fri, 24 Sep 2010 01:56:19 +0800 (SGT)
From:
MAILER-DAEMON@mail.mydomain.com
------=_Part_13_23348857.1285264579096
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Content-Description: Zimbra spam classification report
Classified-By:
user@mydomain.com
Classified-As: spam
------=_Part_13_23348857.1285264579096
Content-Type: message/rfc822
Content-Disposition: attachment
Return-Path:
sicurezza@relaxbanking.it
Received: from 192.168.100.99 (LHLO mail.mydomain.com) (192.168.100.99) by
mail.mydomain.com with LMTP; Fri, 24 Sep 2010 01:55:14 +0800 (SGT)
Received: from localhost (localhost.localdomain [127.0.0.1])
by mail.mydomain.com (Postfix) with ESMTP id 5D60E54053
for <user@mydomain.com>; Fri, 24 Sep 2010 01:55:09 +0800 (SGT)
X-Quarantine-ID: <5Opk53+4pvz2>
X-Virus-Scanned: amavisd-new at mail.mydomain.com
X-Amavis-Alert: BAD HEADER SECTION, Non-encoded 8-bit data (char E8 hex):
Subject: ...Per ragioni di sicurezza \350 necessario con[...]
X-Spam-Flag: NO
X-Spam-Score: 4.922
X-Spam-Level: ****
X-Spam-Status: No, score=4.922 tagged_above=-10 required=6.6
tests=[ALL_TRUSTED=-1.8, AWL=-2.904, BASE64_LENGTH_79_INF=1.496,
BAYES_50=0.001, HTML_IMAGE_ONLY_24=1.552, HTML_MESSAGE=0.001,
HTML_TAG_BALANCE_HEAD=1.334, NORMAL_HTTP_TO_IP=0.001,
URIBL_BLACK=1.955, URIBL_PH_SURBL=1.787, URIBL_SBL=1.499] autolearn=no
Received: from mail.mydomain.com ([127.0.0.1])
by localhost (mail.mydomain.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 5Opk53+4pvz2; Fri, 24 Sep 2010 01:55:08 +0800 (SGT)
Received: from relaxbanking.it (unknown [208.93.150.136])
by mail.mydomain.com (Postfix) with ESMTPA id E996E5405D
for <anaminsantiago@hotmail.com>; Fri, 24 Sep 2010 01:55:03 +0800 (SGT)
From: Relax Banking <sicurezza@relaxbanking.it>
To:
anaminsantiago@hotmail.com
Subject: =?utf-8?Q?Spam?=
Per ragioni di sicurezza � necessario confermare il tuo account.
Date: 23 Sep 2010 12:52:56 -0500
Message-ID: <20100923125256.F0BF418597DAD7AF@relaxbanking.it >
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0012_EAA65E99.2DE55BDB"
X-SpamInfo: FortiGuard - AntiSpam ip, connection black ip 208.93.150.136