Page 2 of 2 FirstFirst 12
Results 11 to 15 of 15

Thread: Block sending mails to specific domain

  1. #11
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,568
    Rep Power
    57

    Default

    Quote Originally Posted by Rk_Raj View Post
    They are telling that lots of spam mails are comming from our server.
    Who is telling you that spam is coming from your server? How do they know? What evidence do you have that spam is coming from your server? You need to provide some more details than just 'our server sends spam', do some investigation in the log files to see what's happening. Check the headers of some of these 'spam'' emails to see what they are. Ask for some evidence from the person telling you that you're sending spam
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  2. #12
    Rk_Raj is offline Active Member
    Join Date
    May 2011
    Location
    Chennai Madras
    Posts
    36
    Rep Power
    4

    Default why these messages are comming from my mail server

    If those mails are not sent from our mail server then what is that from<> and why it is comming in the daily mail admin report.

    Here is the example of log,

    Dec 18 11:27:56 mail postfix/smtpd[13350]: disconnect from ims-m12.mx.aol.com[64.12.207.145]
    Dec 18 11:27:58 mail postfix/cleanup[23374]: 196B2224585: message-id=<8CE8B60E2EA1278-C28-DF80@webmail-d085.sysops.aol.com>
    Dec 18 11:37:54 mail postfix/smtpd[26177]: connect from imr-da04.mx.aol.com[205.188.105.146]
    Dec 18 11:37:55 mail postfix/smtpd[26177]: 5FEC2224585: client=imr-da04.mx.aol.com[205.188.105.146]
    Dec 18 11:37:56 mail postfix/qmgr[4127]: 5FEC2224585: from=<geaneym@aol.com>, size=8945, nrcpt=1 (queue active)
    Dec 18 11:37:57 mail postfix/qmgr[4127]: 0372B224586: from=<geaneym@aol.com>, size=9535, nrcpt=1 (queue active)
    Dec 18 11:38:01 mail postfix/smtpd[26177]: disconnect from imr-da04.mx.aol.com[205.188.105.146]
    Dec 18 11:38:01 mail postfix/qmgr[4127]: EDFCF224587: from=<geaneym@aol.com>, size=10349, nrcpt=1 (queue active)
    Dec 18 12:13:22 mail postfix/smtp[27432]: 2C50C22458E: to=<GeaneyM@aol.com>, relay=127.0.0.1[127.0.0.1]:9026, delay=1.1, delays=1.1/0/0.01/0.05, dsn=2.0.0, status=sent (250 2.0.0 Ok (2.0.0 Ok: queued as D4DED22458F ))
    Dec 18 12:13:27 mail postfix/smtp[27456]: D4DED22458F: to=<GeaneyM@aol.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=4.9, delays=0.04/0/0/4.9, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=16624-16, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as B90D822458E)
    Dec 18 12:13:29 mail postfix/smtp[14070]: > smtp.netcare.com[208.165.242.182]:25: RCPT TO:<GeaneyM@aol.com> ORCPT=rfc822;GeaneyM@aol.com
    Dec 18 12:13:30 mail postfix/smtp[14070]: B90D822458E: to=<GeaneyM@aol.com>, relay=smtp.netcare.com[208.165.242.182]:25, delay=2.6, delays=0.01/0.02/1.5/1.1, dsn=2.0.0, status=sent (250 2.0.0 smtp.netcare.com Ok: queued as ACC1329EEE)
    Dec 18 13:52:52 mail postfix/smtp[10766]: 9B307224595: to=<a2877cake@aol.com>, relay=127.0.0.1[127.0.0.1]:9026, delay=4.8, delays=4.7/0/0.01/0.13, dsn=2.0.0, status=sent (250 2.0.0 Ok (2.0.0 Ok: queued as 3728B224596 ))
    Dec 18 13:52:52 mail postfix/smtp[10766]: 9B307224595: to=<a28nyc@aol.com>, relay=127.0.0.1[127.0.0.1]:9026, delay=4.8, delays=4.7/0/0.01/0.13, dsn=2.0.0, status=sent (250 2.0.0 Ok (2.0.0 Ok: queued as 3728B224596 ))
    Dec 18 13:52:52 mail postfix/smtp[10766]: 9B307224595: to=<a2chuck@aol.com>, relay=127.0.0.1[127.0.0.1]:9026, delay=4.8, delays=4.7/0/0.01/0.13, dsn=2.0.0, status=sent (250 2.0.0 Ok (2.0.0 Ok: queued as 3728B224596 ))
    Dec 18 13:52:52 mail postfix/smtp[10766]: 9B307224595: to=<a2consultants@aol.com>, relay=127.0.0.1[127.0.0.1]:9026, delay=4.8, delays=4.7/0/0.01/0.13, dsn=2.0.0, status=sent (250 2.0.0 Ok (2.0.0 Ok: queued as 3728B224596 ))
    Dec 18 13:52:52 mail postfix/smtp[10766]: 9B307224595: to=<a2e2@aol.com>, relay=127.0.0.1[127.0.0.1]:9026, delay=4.8, delays=4.7/0/0.01/0.13, dsn=2.0.0, status=sent (250 2.0.0 Ok (2.0.0 Ok: queued as 3728B224596 ))


    Please explain me what these logs says. Not only aol.com like these there are yahoo.com, gmail.com etc., smtp.netcare.com is our. mail relay service provider

  3. #13
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,568
    Rep Power
    57

    Default

    I told you earlier that Zimbra is not an open relay unless you've made any modification to make it one, have you made any changes that would cause this? Have you actually checked some of the on-line test sites that will test your server to see if it's an open relay? Have you checked to see if there's any compromised accounts on your server? Have you actually checked to see if there's any infected machines on your LAN?
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

  4. #14
    Rk_Raj is offline Active Member
    Join Date
    May 2011
    Location
    Chennai Madras
    Posts
    36
    Rep Power
    4

    Default mail is not modified to openrelay

    Yes, I checked with some sites and it told that the mail server is not openrelay. What is meant by compramised account and how to check that?

  5. #15
    phoenix is offline Zimbra Consultant & Moderator
    Join Date
    Sep 2005
    Location
    Vannes, France
    Posts
    23,568
    Rep Power
    57

    Default

    Quote Originally Posted by Rk_Raj View Post
    Yes, I checked with some sites and it told that the mail server is not openrelay.
    Then you possibly have other problems on your server or LAN.

    Quote Originally Posted by Rk_Raj View Post
    What is meant by compromised account and how to check that?
    Search the forums (or the internet) for that phrase.
    Regards


    Bill


    Acompli: A new adventure for Co-Founder KevinH.

Page 2 of 2 FirstFirst 12

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. sending all mails to smart relay host
    By th27 in forum Administrators
    Replies: 1
    Last Post: 06-10-2011, 08:57 AM
  2. Replies: 2
    Last Post: 11-15-2010, 01:19 AM
  3. Replies: 4
    Last Post: 02-20-2009, 01:29 AM
  4. Replies: 5
    Last Post: 06-18-2008, 01:50 AM
  5. Replies: 20
    Last Post: 03-18-2008, 05:37 AM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •