LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 01-15-2013, 10:34 PM   #1
karprav
LQ Newbie
 
Registered: Jan 2013
Posts: 7

Rep: Reputation: Disabled
Spam Emails - Sendmail


For the past 3 days, from lot of US ip's emails are sent to other domains from our domain as it is sent from our's. But when we check we are not a open relay. But still, we tried a lot to stop it, it is not stopping. Any help will be very thankful.

-Sobhanadri
 
Old 01-16-2013, 02:39 AM   #2
karprav
LQ Newbie
 
Registered: Jan 2013
Posts: 7

Original Poster
Rep: Reputation: Disabled
Below is the out for the above issue:
++++++++++++++++
Jan 16 13:58:29 mail sendmail[31922]: r0G8SSub031922: ruleset=check_rcpt, arg1=<banheirovirtual@catanduva.sescsp.org.br>, relay=67.228.212.186-static.reverse.softlayer.com [67.228.212.186], reject=550 5.7.1 <banheirovirtual@catanduva.sescsp.org.br>... Relaying denied. Proper authentication required.

Jan 16 13:58:29 mail sendmail[31922]: r0G8SSub031922: from=<mbqj@imagine.co.in>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=67.228.212.186-static.reverse.softlayer.com [67.228.212.186]

++++++++++++++++
our secondary domain is imagine.co.in. So, it is trying to send the email, but relaying denied. But immediately the 2nd option is starts working and email comes into queue and the same is happening for lot emails. Can any one help out to fix this issue.

Thank you advance.
 
Old 01-16-2013, 08:21 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
First things would be to temporarily shut down your MTA (or block offenders via the firewall using 'ipset' and the raw table PREROUTING chain), then check for the cause, then restrict who can send email and then add an anti-spam filter before starting the MTA again. If this machine, or machines it receives email from, are web servers there may be a dynamically rendered page (often but not limited to PHP) or script somewhere that allows spammers to inject spam. Enumerate software that runs on top of the web server and check their versions (including any plugins) with what the vendor sees as current, check web server access and error logs for seemingly odd requests (also see Logwatch) and check directories the web server can read from or write to for any anomalous files. Please reply verbosely and add any information you think pertinent.
 
Old 01-21-2013, 09:31 PM   #4
m1rr0rm3
LQ Newbie
 
Registered: Jan 2013
Location: Planet Earth
Distribution: RHEL v7.6
Posts: 28

Rep: Reputation: Disabled
Blacklisted

Listing in the Barracuda Blacklist could indicate any number of issues that need to be addressed in your network including but not limited to: virus-generated spam, poor server configuration, dynamic IP Addresses previously used by spammers, bulk mail sending that does not comply with the CAN-SPAM Act.

http://www.mxtoolbox.com/SuperTool.a...67.228.212.186

http://www.mxtoolbox.com/Public/Blac...x?bl=BARRACUDA

http://www.mxtoolbox.com/Public/Blac...l=Spamhaus-ZEN
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sending emails - Going to spam folders tech_paul Linux - Server 3 07-28-2009 11:13 PM
Did I send 1000+ spam emails this morning? khinch Linux - Newbie 5 09-30-2007 01:17 PM
Problem about spam emails kkeith Linux - Newbie 1 09-06-2006 03:30 AM
All my outgoing emails suddenly bounce as spam! ivj Linux - Software 5 05-18-2006 01:22 PM
Rejecting Spam Emails vk1985 Linux - Networking 3 04-11-2003 04:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 04:13 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration