What do these messages in the Qmail maillog indicate?
Posted
by
Griffo
on Server Fault
See other posts from Server Fault
or by Griffo
Published on 2011-06-30T22:13:51Z
Indexed on
2011/07/01
0:23 UTC
Read the original article
Hit count: 459
There seems to be an endless supply of messages in the Qmail maillog for a single address. Can anyone shed some light on why this might be and whether it is a problem? To me it looks like either spam or some sort of unhandled problem. It strikes me as unusual that the 'from=' field is blank. This is on a VPS using Plesk in case that's important.
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23593]: [email protected]
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23586]: from=
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23586]: [email protected]
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23585]: from=
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23585]: [email protected]
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23584]: from=
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23584]: [email protected]
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23583]: from=
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23583]: [email protected]
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23600]: from=
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23600]: [email protected]
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23599]: from=
Jun 30 15:10:17 vps-1001108-595 qmail-remote-handlers[23599]: [email protected]
EDIT Here's a sample of one of the emails:
Received: (qmail 5603 invoked for bounce); 29 Jun 2011 07:46:31 +0100
Date: 29 Jun 2011 07:46:31 +0100
From: [email protected]
To: [email protected]
Subject: failure notice
Hi. This is the qmail-send program at vps-1001108-595.cp.blacknight.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<[email protected]>:
200.147.36.13 does not like recipient.
Remote host said: 450 4.7.1 Client host rejected: cannot find your hostname, [78.153.208.195]
Giving up on 200.147.36.13.
I'm not going to try again; this message has been in the queue too long.
--- Below this line is a copy of the message.
Return-Path: <[email protected]>
Received: (qmail 15585 invoked by uid 48); 22 Jun 2011 07:38:26 +0100
Date: 22 Jun 2011 07:38:26 +0100
Message-ID: <[email protected]>
To: [email protected]
Subject: Cadastre-se e Concorra ? um Carro!
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: Cielo Fidelidade <[email protected]>
<!DOCTYPE HTML>
<html>
... <body text removed>
<html>
If I understand this correctly, this is saying that an email sent by my server, from address [email protected], could not be delivered. However, [email protected] is not a valid email address on my server, so how can email be sent from this address on my server? I have tested whether my server is acting as an open relay, and it isn't. So how else could this be happening? I am getting thousands of these every day. What can I do to prevent it?
© Server Fault or respective owner