• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Resolved Blacklisted, and the sky is falling

NateWon

Basic Pleskian
Hello I hope this is ok to post here,

Ive been blacklisted by spamhaus, and it appears that this may be the case:

"If this IP address is NOT a shared hosting IP address, this IP address is infected with/emitting spamware/spamtrojan traffic and needs to be fixed. Find and remove the virus/spamware problem then use the CBL delisting link below. "

Ive disabled postfix whilst I try and find the cause, as it kept ranking up scores (bad idea, not sure?)

Ive run clamav, maldetect, chkroot, and rkhunter, only clamav had positives all from the mail drive, Ive tested sending the Eicar virus test file and that doesn't get through SMTP.

Ill be updating Plesk onyx to the latest version later tonight, but was wondering if anyone had any advice.
The sending appears to be hourly for the last day or so,

We a;lso get a 97% score from Vircom test,

Any tips in solving this issue would be appreicated
Thanks
 
Ok so this took a long time to workout. Was looking for something to do what this does, was able to solve it quickly when could check the effect of the change
The CBL

Turns out, the settings in main.cf where correct but Plesk has another set of settings, "Use IP Addresses and Domain for Greeting", I needed to disable that option to ensure that my config wasn't overwritten. Our servers are setup to use a single secure domain for hosting mail.domain.com, instead of every clients domains for that (does the newer version allow for lets encrypt certificates on mail accounts?).

Sorted now,
 
Back
Top