• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Help w/ Possible Spam Issue

C

C4talyst

Guest
Hello,

I've inherited a plesk 8.6 server recently and in the past week it's been exhibiting slowness. It has around 300 websites on it and "top" has been showing me a lot of mail related activity (qmail, spamd, etc).

Today I noticed there were 9000 mails in the queue. Usually a busy day sees around 100-200 mails in the queue at any given time. I started doing some digging on the forums here and have some questions about my findings.

I ran /var/qmail/bin/qmail-qread and am seeing a lot of activity for non-existent email accounts that seem to follow a uniform naming convention. Here's a snippet:

9 Jun 2009 17:43:52 GMT #13245516 10235 <>
local [email protected]
9 Jun 2009 17:43:52 GMT #13245355 19450 <>
local [email protected]
9 Jun 2009 17:54:06 GMT #13242388 7323 <>
local [email protected]
9 Jun 2009 17:33:09 GMT #13240801 9590 <>
local [email protected]
9 Jun 2009 17:43:52 GMT #13245999 8097 <>
local [email protected]
9 Jun 2009 18:04:06 GMT #13238455 7619 <>
local [email protected]
9 Jun 2009 17:43:52 GMT #13245332 10201 <>
local [email protected]
9 Jun 2009 17:33:09 GMT #13240686 2215 <>
local [email protected]
9 Jun 2009 17:43:52 GMT #13245309 7673 <>
local [email protected]
9 Jun 2009 17:43:52 GMT #13245401 11489 <>
local [email protected]
9 Jun 2009 17:54:06 GMT #13247563 2224 <>
remote [email protected]
9 Jun 2009 17:54:06 GMT #13247471 8598 <>
local [email protected]
9 Jun 2009 17:33:09 GMT #13241698 6744 <>
local [email protected]
9 Jun 2009 18:04:06 GMT #13244412 5751 <>
local [email protected]

What's going on here? The 54-thampl user does not exist, neither do the other odd named users listed here.
 
Hello,

First check that all domains have the option 'Mail to non-existing user' set to 'reject' but not to 'forward'. You can change this setting to all domains using "Group Operations" in the "Domains" tab in Parallels Plesk Control Panel. The option "Reject mail to nonexistent user" is available since Parallels Plesk Panel 7.5.3.

Also, please, check that all the IPs and networks in the white lists are reliable and familiar to you.

If the queue has too many messages, try to discover the source of SPAM. To do it, please, perform the steps provided at the following article:

http://kb.odin.com/en/766
 
Back
Top