1. Please take a little time for this simple survey! Thank you for participating!
    Dismiss Notice
  2. Dear Pleskians, please read this carefully! New attachments and other rules Thank you!
    Dismiss Notice
  3. Dear Pleskians, I really hope that you will share your opinion in this Special topic for chatter about Plesk in the Clouds. Thank you!
    Dismiss Notice

Outgoing Email Spam Issue

Discussion in 'Plesk 9.x for Linux Issues, Fixes, How-To' started by Dale Johnson, Apr 28, 2010.

  1. Dale Johnson

    Dale Johnson Guest

    0
     
    Hey Guys,

    Im not an expert by any means at this stuff, so I will try to provide as much information as possible and hopefully somebody will know what problem I am having.

    I have done a fair amount of searching and found examples of backscatter and joe job's, but don't think either of these are what im having.

    The Problem

    Lately, I have been getting bounced messaged that look like the following.

    ------------

    Hi. This is the qmail-send program at xxxxxxxxx.onlinehome-server.com.
    I'm afraid I wasn't able to deliver your message to the following addresses.
    This is a permanent error; I've given up. Sorry it didn't work out.

    <slqeloquent@channeltrend.co.uk>:
    Sorry, I couldn't find any host named channeltrend.co.uk. (#5.1.2)

    <slqevergreen@boygenius.co.uk>:
    209.85.223.55 does not like recipient.
    Remote host said: 550-5.1.1 The email account that you tried to reach does not exist. Please try
    550-5.1.1 double-checking the recipient's email address for typos or
    550-5.1.1 unnecessary spaces. Learn more at
    550 5.1.1 http://mail.google.com/support/bin/answer.py?answer=6596 27si17601392iwn.8
    Giving up on 209.85.223.55.

    <slqenigma@chickenjoes.co.uk>:
    217.8.243.182 does not like recipient.
    Remote host said: 550 <slqenigma@chickenjoes.co.uk> No such user here
    Giving up on 217.8.243.182.

    <slqfame@bsrla.org.uk>:
    213.171.206.109 does not like recipient.
    Remote host said: 550 <slqfame@bsrla.org.uk>: Recipient address rejected: User unknown in virtual mailbox table
    Giving up on 213.171.206.109.

    <slqfatigue@boygenius.co.uk>:
    209.85.223.84 does not like recipient.
    Remote host said: 550-5.1.1 The email account that you tried to reach does not exist. Please try
    550-5.1.1 double-checking the recipient's email address for typos or
    550-5.1.1 unnecessary spaces. Learn more at
    550 5.1.1 http://mail.google.com/support/bin/answer.py?answer=6596 16si4319588iwn.33
    Giving up on 209.85.223.84.

    <slqfanatic@chickenjoes.co.uk>:
    217.8.243.182 does not like recipient.
    Remote host said: 550 <slqfanatic@chickenjoes.co.uk> No such user here
    Giving up on 217.8.243.182.

    <slqferocious@bathandwest.co.uk>:
    82.69.206.26 failed after I sent the message.
    Remote host said: 571 Delivery not authorized, message refused

    <slqfeminism@blondeair.co.uk>:
    82.117.37.108 does not like recipient.
    Remote host said: 550 unknown user
    Giving up on 82.117.37.108.

    <slqfirefly@canadarentacar.co.uk>:
    74.52.18.2 does not like recipient.
    Remote host said: 550 Requested action not taken: mailbox unavailable or not local
    Giving up on 74.52.18.2.

    <slqfishery@birkdaleclinic.co.uk>:
    85.158.136.35 does not like recipient.
    Remote host said: 550-Invalid recipient <slqfishery@birkdaleclinic.co.uk>
    550 (#5.1.1)
    Giving up on 85.158.136.35.

    <slqforemost@bowski.co.uk>:
    Sorry, I couldn't find any host named bowski.co.uk. (#5.1.2)

    <slqfledgling@bikescene.co.uk>:
    91.151.209.68 does not like recipient.
    Remote host said: 550 5.1.1 <slqfledgling@bikescene.co.uk>... User unknown
    Giving up on 91.151.209.68.

    <slqfreshwater@blairhammond.co.uk>:
    Sorry, I couldn't find any host named blairhammond.co.uk. (#5.1.2)

    <slqfollower@checkwho.co.uk>:
    80.94.196.22 does not like recipient.
    Remote host said: 550 unknown user <slqfollower@checkwho.co.uk>
    Giving up on 80.94.196.22.

    <slqfrugal@campton.co.uk>:
    207.126.147.10 does not like recipient.
    Remote host said: 550 No such user - psmtp
    Giving up on 207.126.147.10.

    <slqglen@captor.co.uk>:
    217.112.88.147 does not like recipient.
    Remote host said: 550 <slqglen@captor.co.uk> No such user here
    Giving up on 217.112.88.147.

    <slqgopher@bemrose.derby.sch.uk>:
    217.33.44.2 does not like recipient.
    Remote host said: 550 5.1.1 <slqgopher@bemrose.derby.sch.uk>: Recipient address rejected: User unknown in relay recipient table
    Giving up on 217.33.44.2.

    <slqforeseen@dbgroup.co.uk>:
    90.152.57.70 failed after I sent the message.
    Remote host said: 550 Message refused

    <slqgvwd@felidae.co.uk>:
    93.93.131.52 does not like recipient.
    Remote host said: 550-Verification failed for <service.center@hsbc.co.uk>
    550-Previous (cached) callout verification failure
    550 Sender verify failed
    Giving up on 93.93.131.52.

    <slqfavorable@bmroofing.co.uk>:
    217.174.253.141 does not like recipient.
    Remote host said: 550 <slqfavorable@bmroofing.co.uk> No such user here
    Giving up on 217.174.253.141.

    --- Below this line is a copy of the message.

    Return-Path: <sender@whatever.com>
    Received: (qmail 27377 invoked by uid 0); 27 Apr 2010 20:39:01 -0700
    Date: 27 Apr 2010 20:39:01 -0700
    Message-ID: <20100428033901.27374.qmail@<hidden>.com>
    From: sender@whatever.com
    To: email@anotherserver.com
    Subject: Example Email Subject

    Example email Body

    -------------------------------------------------------------------

    The Circumstances

    I have noticed a pattern for this --> anytime an email is received by my server and has to redirect it to another ISP OR if my server itself has to send out a message it will successfully send the message, but also create a bounce record back to the original sender with the addresses of people they had no intention of sending the message to.

    The list above with all the bounced email addresses, I have no idea who they are or where they came from...for a while I thought perhaps it was the individual sending the email having some sort of virus on their end that was attempting to attach multiple EXTRA recipients to their email, but last night I had a Plesk notification sent to off-server admin account and I ALSO got a bounce message saying that it couldnt deliver to all of these extra accounts.

    If a Plesk email originating on a plesk setup is producing this, it makes me think that the qmail program might be compromised in some way. Again, Im not an expert, so i have no idea how this might be possible or what to do to fix it.

    ------------------------------------------------------------

    My Setup

    In my Plesk Mail config I have the following settings.

    Relaying: closed
    DomainKeys: OFF
    Switch on SPF spam protection: On
    SPF checking mode: Reject Mail when SPF resolves to "fail" (deny)
    SPF local rules: include:spf.trusted-forwarder.org
    DNS zones for DNSBL service: sbl.spamhaus.org;zen.spamhaus.org;dnsbl.ahbl.org;dnsbl.njabl.org;dnsbl.sorbs.net;blackholes.five-ten-sg.com

    ------------------------------------------------------------

    What Ive Done So Far

    When this problem originated I was using Plesk 8.4 and have since done incremental updates to Plesk 9.3 - my wishful thinking hoped that this problem would simply go away on its own by doing these updates, but clearly it hasnt.

    I have looked over qmail log files, but given that im not really sure what to be looking for i obviously havn't found much. Ive tried looking for the email addresses above, but they don't seem to appear in there anywhere.

    Ive also scoured the forums and Google looking for similar problems, but nobody has quite the same issue that im having (that ive been able to find)...I understand the concept of backscatter and joe job's, but again, this doesnt seem to be along the same lines


    If anyone has some understanding of what im experience your help would be GREATLY appreciated. If you need any more information please inform me and ill do what I can to provide you with what you need. This problem is of great importance and hopefully with your guys help I can get it resolved soon.

    Thank-you
     
    Last edited by a moderator: Apr 28, 2010
  2. Dale Johnson

    Dale Johnson Guest

    0
     
    Anyone? Help on this would be very much appreciated!
     
  3. raz3k

    raz3k Basic Pleskian

    23
    23%
    Joined:
    Nov 12, 2006
    Messages:
    25
    Likes Received:
    0
    Try to switch to postfix. Or i f you don't like postfix... switch to postfix and then back to qmail.
     
  4. 64bithost.com

    64bithost.com Regular Pleskian

    25
    57%
    Joined:
    Jul 30, 2007
    Messages:
    182
    Likes Received:
    0
    Do some research.

    onlinehome-server.com

    http://www.who.is/nameserver/u15391630.onlinehome-server.com/

    U15391630.ONLINEHOME-SERVER.COM SUMMARY
    Domain Name onlinehome-server.com
    IP 74.208.213.182
    Recursive No
    Complimentary Name Servers slv1.1and1.com


    SAMPLE OF DOMAINS USING U15391630.ONLINEHOME-SERVER.COM
    Domain Registrar Create Date Expire Date More Information
    craftout.com 1 & 1 INTERNET AG 2007-12-11 2010-12-11 DNS


    ONLINEHOME-SERVER.COM is a slave server better known as a parking server
     
  5. atlincan

    atlincan Guest

    0
     
    @Dale Johnson: I've just recently started having the exact issue as you. My host is blaming me, but I've never seen any of the email addresses before. Did you find a resolution?
     
  6. CatalinS

    CatalinS Basic Pleskian

    20
    40%
    Joined:
    Jan 21, 2010
    Messages:
    33
    Likes Received:
    0
    Hello,

    From what I can see your server is being used to send spam emails. I suggest checking http://kb.odin.com/766 to find out if one of your email accounts is compromised or a php script has been uploaded by a spammer.

    Cheers.
     
  7. linearstrategy

    linearstrategy Guest

    0
     
    Plesk email issues...need a Plesk IT person ASAP

    I am having the same problem. My server is a dedicated server that i lease but i own the plesk license. I am not a back end IT person at all and have more front end. I just got off the phone with my host and they basically said they had to shut down my server today because it was generating 50mb/s outgoing traffic. But they cant explain to me where it was being sent from. I only know how to check things from the control panel.

    The problem is no one (other then the guy that installed this) really knows the plesk system. I desperately need to find an Plesk IT person i can hire on an ongoing basis to trouble shoot this stuff.

    Does anyone know where i can find someone.

    my email may be buggy as they are trying to get it up so email me here

    iomegass@aol.com

    thanks
     
Loading...