Christopher McBride
Basic Pleskian
Hi,
My server has recently seen a drop in IP reputation, which has led me to investigate legitimate email accounts being compromised on my server.
I know the server isnt acting as a relay and can only assume either a script on the server or an email account is being unknowingly abused to send out mass emails.
I'm looking to get a list of all emails originating from the server and the account they were sent by.
I believe this is farily straight forward with Qmail (and the qmail-scanner), but I've been unable to find anything on the internet or these forums regarding the same for Postfix.
I've been manually looking through the mail logs, but I can't seem to figure out where the "sent" messages slot into it.
Can anyone offer any advice on this?
Thanks in advance.
My server has recently seen a drop in IP reputation, which has led me to investigate legitimate email accounts being compromised on my server.
I know the server isnt acting as a relay and can only assume either a script on the server or an email account is being unknowingly abused to send out mass emails.
I'm looking to get a list of all emails originating from the server and the account they were sent by.
I believe this is farily straight forward with Qmail (and the qmail-scanner), but I've been unable to find anything on the internet or these forums regarding the same for Postfix.
I've been manually looking through the mail logs, but I can't seem to figure out where the "sent" messages slot into it.
Can anyone offer any advice on this?
Thanks in advance.