• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved Blacklisted, and the sky is falling

NateWon

Basic Pleskian
Hello I hope this is ok to post here,

Ive been blacklisted by spamhaus, and it appears that this may be the case:

"If this IP address is NOT a shared hosting IP address, this IP address is infected with/emitting spamware/spamtrojan traffic and needs to be fixed. Find and remove the virus/spamware problem then use the CBL delisting link below. "

Ive disabled postfix whilst I try and find the cause, as it kept ranking up scores (bad idea, not sure?)

Ive run clamav, maldetect, chkroot, and rkhunter, only clamav had positives all from the mail drive, Ive tested sending the Eicar virus test file and that doesn't get through SMTP.

Ill be updating Plesk onyx to the latest version later tonight, but was wondering if anyone had any advice.
The sending appears to be hourly for the last day or so,

We a;lso get a 97% score from Vircom test,

Any tips in solving this issue would be appreicated
Thanks
 
Ok so this took a long time to workout. Was looking for something to do what this does, was able to solve it quickly when could check the effect of the change
The CBL

Turns out, the settings in main.cf where correct but Plesk has another set of settings, "Use IP Addresses and Domain for Greeting", I needed to disable that option to ensure that my config wasn't overwritten. Our servers are setup to use a single secure domain for hosting mail.domain.com, instead of every clients domains for that (does the newer version allow for lets encrypt certificates on mail accounts?).

Sorted now,
 
Back
Top