HI Robert,
Please find mail.info of my mail server.
--
From
Kamlesh Verma
On 11/21/2012 08:26 PM, Robert Schetterer wrote:
Am 21.11.2012 15:46, schrieb Robert Schetterer:
Am 21.11.2012 14:45, schrieb kamleshverma:
Every day i m seeing hundreds of mails in mailq, all they are having
unknown domain name
how did they get in your server ?
show logs
try using
reject_unknown_sender_domain
Reject the request when Postfix is not final destination for the
sender address, and the MAIL FROM domain has 1) no DNS A or MX record,
or 2) a malformed MX record such as a record with a zero-length MX
hostname (Postfix version 2.3 and later).
The unknown_address_reject_code parameter specifies the numerical
response code for rejected requests (default: 450). The response is
always 450 in case of a temporary DNS error.
The unknown_address_tempfail_action parameter specifies the action
after a temporary DNS error (default: defer_if_permit)
ups i see you allready use this, so how are you getting these mails
look in your logs for analyse
anyway sometimes users make typos , but these typo domains have A
entries, therefor simply use an error transport etc
Best Regards
MfG Robert Schetterer
Best Regards
MfG Robert Schetterer
root@webmail:/var/log# tail -100 mail.info
Nov 22 10:37:30 webmail postfix/local[6852]: 023851E0059:
to=<gsr...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=24, delays=0.45/0.02/0/24, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:30 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56795
Nov 22 10:37:30 webmail spamd[4342]: spamd: setuid to mallikarjuna succeeded
Nov 22 10:37:30 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for mallikarjuna:1314
Nov 22 10:37:30 webmail dovecot: imap-login: Login: user=<harid>, method=PLAIN,
rip=178.239.86.217, lip=192.168.1.12
Nov 22 10:37:30 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
mallikarjuna:1314 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:30 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=mallikarjuna,uid=1314,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56795,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:30 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:30 webmail postfix/local[6852]: 023851E0059:
to=<mallikarj...@webmail.srishtisoft.com>,
orig_to=<paras_test...@srishtisoft.com>, relay=local, delay=25,
delays=0.45/0.02/0/24, dsn=2.0.0, status=sent (delivered to command: procmail
-a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:30 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56796
Nov 22 10:37:30 webmail spamd[4342]: spamd: setuid to smitha succeeded
Nov 22 10:37:30 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for smitha:1076
Nov 22 10:37:30 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
smitha:1076 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:30 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=smitha,uid=1076,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56796,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:30 webmail postfix/local[6852]: 023851E0059:
to=<smi...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=25, delays=0.45/0.02/0/25, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:30 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:31 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56797
Nov 22 10:37:31 webmail spamd[4342]: spamd: setuid to yaswanth succeeded
Nov 22 10:37:31 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for yaswanth:1171
Nov 22 10:37:31 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
yaswanth:1171 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:31 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=yaswanth,uid=1171,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56797,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:31 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:31 webmail postfix/local[6852]: 023851E0059:
to=<yaswa...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=25, delays=0.45/0.02/0/25, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:31 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56798
Nov 22 10:37:31 webmail spamd[4342]: spamd: setuid to gautam succeeded
Nov 22 10:37:31 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for gautam:1018
Nov 22 10:37:31 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
gautam:1018 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:31 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=gautam,uid=1018,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56798,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:31 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:31 webmail postfix/local[6852]: 023851E0059:
to=<gau...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=26, delays=0.45/0.02/0/25, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:31 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56799
Nov 22 10:37:31 webmail spamd[4342]: spamd: setuid to avay succeeded
Nov 22 10:37:31 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for avay:1017
Nov 22 10:37:31 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
avay:1017 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:31 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=avay,uid=1017,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56799,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:31 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:31 webmail postfix/local[6852]: 023851E0059:
to=<a...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=26, delays=0.45/0.02/0/25, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:31 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56800
Nov 22 10:37:31 webmail spamd[4342]: spamd: setuid to manoj succeeded
Nov 22 10:37:31 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for manoj:1020
Nov 22 10:37:32 webmail dovecot: IMAP(harid): Disconnected: Logged out
bytes=206/2265
Nov 22 10:37:32 webmail spamd[4342]: spamd: clean message (-1.5/3.5) for
manoj:1020 in 0.6 seconds, 17182 bytes.
Nov 22 10:37:32 webmail spamd[4342]: spamd: result: . -1 -
ALL_TRUSTED,BAYES_00,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.6,size=17182,user=manoj,uid=1020,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56800,mid=<50adaed2.4060...@srishtisoft.com>,bayes=0.000000,autolearn=no
Nov 22 10:37:32 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:32 webmail postfix/local[6852]: 023851E0059:
to=<ma...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=27, delays=0.45/0.02/0/26, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:32 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56801
Nov 22 10:37:32 webmail spamd[4342]: spamd: setuid to prashanth succeeded
Nov 22 10:37:32 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for prashanth:1025
Nov 22 10:37:32 webmail spamd[4342]: spamd: clean message (-1.5/3.5) for
prashanth:1025 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:32 webmail spamd[4342]: spamd: result: . -1 -
ALL_TRUSTED,BAYES_00,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=prashanth,uid=1025,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56801,mid=<50adaed2.4060...@srishtisoft.com>,bayes=0.000000,autolearn=no
Nov 22 10:37:32 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:32 webmail postfix/local[6852]: 023851E0059:
to=<prasha...@webmail.srishtisoft.com>,
orig_to=<paras_test...@srishtisoft.com>, relay=local, delay=27,
delays=0.45/0.02/0/26, dsn=2.0.0, status=sent (delivered to command: procmail
-a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:32 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56802
Nov 22 10:37:32 webmail spamd[4342]: spamd: setuid to reena succeeded
Nov 22 10:37:32 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for reena:1037
Nov 22 10:37:33 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
reena:1037 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:33 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=reena,uid=1037,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56802,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:33 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:33 webmail postfix/local[6852]: 023851E0059:
to=<re...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=27, delays=0.45/0.02/0/27, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:33 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56803
Nov 22 10:37:33 webmail spamd[4342]: spamd: setuid to anvesh succeeded
Nov 22 10:37:33 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for anvesh:1317
Nov 22 10:37:33 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
anvesh:1317 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:33 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=anvesh,uid=1317,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56803,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:33 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:33 webmail postfix/local[6852]: 023851E0059:
to=<anv...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=28, delays=0.45/0.02/0/27, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:33 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56804
Nov 22 10:37:33 webmail spamd[4342]: spamd: setuid to vijya succeeded
Nov 22 10:37:33 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for vijya:1041
Nov 22 10:37:33 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
vijya:1041 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:33 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=vijya,uid=1041,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56804,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:33 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:33 webmail postfix/local[6852]: 023851E0059:
to=<vi...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=28, delays=0.45/0.02/0/27, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:33 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56805
Nov 22 10:37:33 webmail spamd[4342]: spamd: setuid to anshujit succeeded
Nov 22 10:37:33 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for anshujit:1042
Nov 22 10:37:34 webmail postfix/smtpd[6676]: connect from
whr3.whrcisp3.com[199.119.102.57]
Nov 22 10:37:34 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
anshujit:1042 in 0.4 seconds, 17182 bytes.
Nov 22 10:37:34 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.4,size=17182,user=anshujit,uid=1042,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56805,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:34 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:34 webmail postfix/local[6852]: 023851E0059:
to=<anshu...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=28, delays=0.45/0.02/0/28, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:34 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56806
Nov 22 10:37:34 webmail spamd[4342]: spamd: setuid to issan succeeded
Nov 22 10:37:34 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for issan:1073
Nov 22 10:37:34 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
issan:1073 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:34 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=issan,uid=1073,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56806,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:34 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:34 webmail postfix/local[6852]: 023851E0059:
to=<is...@webmail.srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=29, delays=0.45/0.02/0/28, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:34 webmail spamd[4342]: spamd: connection from localhost
[127.0.0.1] at port 56807
Nov 22 10:37:34 webmail spamd[4342]: spamd: setuid to adarsha succeeded
Nov 22 10:37:34 webmail spamd[4342]: spamd: processing message
<50adaed2.4060...@srishtisoft.com> for adarsha:1097
Nov 22 10:37:34 webmail postfix/smtpd[6676]: setting up TLS connection from
whr3.whrcisp3.com[199.119.102.57]
Nov 22 10:37:34 webmail spamd[4342]: spamd: clean message (-0.3/3.5) for
adarsha:1097 in 0.2 seconds, 17182 bytes.
Nov 22 10:37:34 webmail spamd[4342]: spamd: result: . 0 -
ALL_TRUSTED,HTML_IMAGE_ONLY_28,HTML_MESSAGE
scantime=0.2,size=17182,user=adarsha,uid=1097,required_score=3.5,rhost=localhost,raddr=127.0.0.1,rport=56807,mid=<50adaed2.4060...@srishtisoft.com>,autolearn=no
Nov 22 10:37:34 webmail spamd[3264]: prefork: child states: II
Nov 22 10:37:34 webmail postfix/local[6852]: 023851E0059:
to=<adar...@srishtisoft.com>, orig_to=<paras_test...@srishtisoft.com>,
relay=local, delay=29, delays=0.45/0.02/0/28, dsn=2.0.0, status=sent (delivered
to command: procmail -a "$EXTENSION" DEFAULT=$HOME/Maildir/)
Nov 22 10:37:34 webmail postfix/qmgr[30835]: 023851E0059: removed
Nov 22 10:37:35 webmail postfix/smtpd[6676]: Anonymous TLS connection
established from whr3.whrcisp3.com[199.119.102.57]: TLSv1 with cipher
DHE-RSA-AES256-SHA (256/256 bits)
Nov 22 10:37:36 webmail postfix/smtpd[6676]: NOQUEUE: reject: RCPT from
whr3.whrcisp3.com[199.119.102.57]: 550 5.1.1
<viagra-soft.s...@srishtisoft.com>: Recipient address rejected: User unknown in
local recipient table; from=<> to=<viagra-soft.s...@srishtisoft.com>
proto=ESMTP helo=<whr3.whrcisp3.com>
Nov 22 10:37:36 webmail postfix/smtpd[6676]: disconnect from
whr3.whrcisp3.com[199.119.102.57]
root@webmail:/var/log#