Linux - ServerThis forum is for the discussion of Linux Software used in a server related context.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
I have currently running a server that has Centos 5.2 on it. I am using Postfix 2.3.3 for mail as well as Dovecot for POP3/IMAP.
First thing which may be the cause of a lot of the delay is that I may have a spammer taking up a bunch of resources. All the errors show that they are timing out or denied but I am constantly receiving mailer deamons in my root email box.
Here is some of the lines from maillog:
Quote:
Dec 8 15:41:46 postfix/qmgr[10757]: 3CAAF86CB27B: to=<ceo.cheng@msa.hinet.net>, relay=none, delay=254354, delays=254354/0.04/0/0, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to msa-smtp-mx2.hinet.net[168.95.6.66]: Connection timed out)
Dec 8 15:41:46 postfix/qmgr[10757]: 3CAAF86CB27B: to=<chi.tei@msa.hinet.net>, relay=none, delay=254354, delays=254354/0.04/0/0, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to msa-smtp-mx2.hinet.net[168.95.6.66]: Connection timed out)
Dec 8 15:41:46 postfix/qmgr[10757]: 3CAAF86CB27B: to=<cl103.huang@msa.hinet.net>, relay=none, delay=254354, delays=254354/0.05/0/0, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to msa-smtp-mx2.hinet.net[168.95.6.66]: Connection timed out)
Dec 8 15:41:46 postfix/qmgr[10757]: 3CAAF86CB27B: to=<cydan.home@msa.hinet.net>, relay=none, delay=254354, delays=254354/0.05/0/0, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to msa-smtp-mx2.hinet.net[168.95.6.66]: Connection timed out)
Dec 8 15:41:46 postfix/qmgr[10757]: 3CAAF86CB27B: to=<a0915631636@yahoo.com.tw>, relay=none, delay=254354, delays=254354/0.05/0/0, dsn=4.7.1, status=deferred (delivery temporarily suspended: host mx1.mail.tw.yahoo.com[203.188.197.119] refused to talk to me: 421 4.7.1 [TS03] All messages from 200.35.145.118 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html)
Dec 8 15:41:46 postfix/qmgr[10757]: 3CAAF86CB27B: to=<chareking.tw@yahoo.com.tw>, relay=none, delay=254354, delays=254354/0.05/0/0, dsn=4.7.1, status=deferred (delivery temporarily suspended: host mx1.mail.tw.yahoo.com[203.188.197.119] refused to talk to me: 421 4.7.1 [TS03] All messages from 200.35.145.118 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html)
Dec 8 15:41:46 postfix/qmgr[10757]: 3CAAF86CB27B: to=<csg0g0g0@yahoo.com.tw>, relay=none, delay=254354, delays=254354/0.05/0/0, dsn=4.7.1, status=deferred (delivery temporarily suspended: host mx1.mail.tw.yahoo.com[203.188.197.119] refused to talk to me: 421 4.7.1 [TS03] All messages from 200.35.145.118 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html)
Dec 8 15:41:46 postfix/qmgr[10757]: 37CBC2248BBE: from=<>, size=4483, nrcpt=1 (queue active)
Dec 8 15:41:46 postfix/qmgr[10757]: 37CBC2248BBE: to=<eiokprqgyj@yahoo.com.tw>, relay=none, delay=253264, delays=253264/0.02/0/0, dsn=4.7.1, status=deferred (delivery temporarily suspended: host mx1.mail.tw.yahoo.com[203.188.197.119] refused to talk to me: 421 4.7.1 [TS03] All messages from 200.35.145.118 will be permanently deferred; Retrying will NOT succeed. See http://postmaster.yahoo.com/421-ts03.html)
Dec 8 15:41:46 postfix/qmgr[10757]: 3D02086C989B: from=<hzsmwk@yahoo.com.tw>, size=2227, nrcpt=14 (queue active)
Mail delivery just seems extremly slow compared to how it ran just a few days ago. It can take a few hours to receive an email when sending from the server to an outside email address.
If I try to send the email from an aol account back to an account on the server I get "undelivered mail return to sender" error. Inside that error it says "mail for ... loops back to myself".
If I try to send the email from an account on the server to another account on the server nothing shows up.
If any other logs are needed to help please let me know.
If you go to the help page link in the log message you can check the reason, here's the page: http://help.yahoo.com/l/us/yahoo/mai.../421-ts03.html It basically tells you that no further email to their mail servers will be accepted from your mail server, the reason for that is that your server seems to be sending high volumes of mail that appear to be symptomatic of 'spam'.
The very first place to start is with data! Are you running sar or some other tool that's continuously recording what your system is doing? If so, are you recording at 5-10 second sampling rates? If not, try installing collectl.
In any event, compare the times in the maillog with collectl (or sar or whatever) log and you'll at least be able to begin to tell is something is hogging the cpu, disk, network or whatever. w/o data, you're only guessing...
I am not running sar or collectl. I will look into these as well.
However it seems that no matter what I try there are constant emails being sent out that are not by me (I am the only one using the server too). I did find a few sites to test for an open relay but they said I do not have an open relay. Mail does seem to work for the most part just very delayed at times and I think once I can get this spammer off it will clear a lot of it up.
I do know when I run the command host <IP Address> I get a result of <IP Address> .in-addr.arpa domain name pointer www1communicqationsgalores.com. www1communicqationsgalores.com is not my domain name so I am not sure if this has something to do with the issue.
Well I have the spam issue solved, at least so far. It seems that the emails were queued before getting some of the security in place. Once I deleted the emailed in the queue the emails stopped.
I do still have a questions about why my domain point is showing as that www1communicqationsgalores.com.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.