• The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

plesk 1.0.18 spam problem.

karael

New Pleskian
Edit:topic: it's version 12 not 1

Hi everyone,

For 1 week a spammer is using our server to send a lot of messages.
I'm still looking how he does it? I have configured Qmail smtp so it need authentification to send.

I followed this tutorial : http://kb.odin.com/fr/766

then i got the header of my spammer messages :

[root@ns409421 var]# cat /var/qmail/queue/mess/22/119297917
Received: (qmail 30529 invoked from network); 13 Dec 2014 16:19:49 +0100
Received: from hosted-by.leaseweb.com (HELO test.com) (46.165.209.35)
by loc-ap.com with ESMTPA; 13 Dec 2014 16:19:49 +0100
From: Banca Popolare di Vicenza <[email protected]>
To: [email protected]
Subject: Attenzione: abbiamo provveduto a cancellare la tua utenza!
Date: 13 Dec 2014 16:04:34 +0100
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

This header shows something interesting : "qmail 30529 invoked from network". I don't know what this means.

On otherhand, i banned this ip and this domain on MagicSpam. I want to identify how the spammer send his messages using my smtp and the way to block him.

If you need any informations, just ask!
Thanks for help
 
Last edited:
Back
Top