On 7/7/2014 1:45 PM, Noel Jones wrote: > On 7/7/2014 11:56 AM, Leonardo Rodrigues wrote: >> Em 07/07/14 13:24, Ben Johnson escreveu: >>> Hello! >>> >>> I've noticed increased Postfix activity as of late and am >>> concerned that >>> something is configured inadequately (i.e., open-relay). For >>> "postconf >>> -n" output, please skip to the end of this message. >>> >> >> It's much easier that you had some account hijacked and bots are >> using it to send the messages. Check the queueids of some messages >> looking for the sasl_username used for sending it. If you find lots >> of suspect messages sent by the same user, then you find your problem ! >> > > > And it's not unusual to find spammers abusing some web form to send > spam. Check your web server logs for evidence. > > > > -- Noel Jones > >
Thanks, Leonardo and Noel! I really appreciate the prompt replies. Leonardo, I see no indication that whomever is sending this mail has authenticated. And given that local connections are permitted to send mail without authenticating on this server, I will pursue Noel's suggested course of action next. I'll let you know if I can't find the source... Thanks again, -Ben