• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved Receiving wrong mails

JordyB

New Pleskian
Hi there,

One of my customers are forwarding mails from his mailbox each day to other mail addresses. But strange enough, when those recipients sent out an auto-reply, the auto-reply is also sended to me (server administrator, [email protected]). Forwarding is off in Plesk, and also on the customer his PC forwarding is deactivated.

Here are some logs:

Code:
Mar 19 13:59:09 srv01 dk_check[26202]: Starting the dk_check filter...
Mar 19 13:59:09 srv01 dk_check[26202]: DKIM verify result: DKIM verification (d=basecone.nl, 1024-bit key) succeeded
Mar 19 13:59:09 srv01 dmarc[26203]: Starting the dmarc filter...
Mar 19 13:59:09 srv01 spamd[6526]: prefork: child states: II
Mar 19 13:59:09 srv01 dmarc[26203]: DMARC: PASS message for [email protected]
Mar 19 13:59:09 srv01 journal: plesk sendmail[26208]: handlers_stderr: PASS
Mar 19 13:59:09 srv01 journal: plesk sendmail[26208]: PASS during call 'limit-out' handler
Mar 19 13:59:09 srv01 check-quota[26210]: Starting the check-quota filter...
Mar 19 13:59:09 srv01 journal: plesk sendmail[26208]: handlers_stderr: SKIP
Mar 19 13:59:09 srv01 journal: plesk sendmail[26208]: SKIP during call 'check-quota' handler
Mar 19 13:59:09 srv01 postfix/pickup[24659]: 7AD1085BD30: uid=30 from=<bounces+1919634-7895-factuur=debourgondischekeuken.nl@sgmail.basecone.nl>
Mar 19 13:59:09 srv01 postfix/cleanup[26112]: 7AD1085BD30: message-id=<[email protected]>
Mar 19 13:59:09 srv01 dovecot: service=lda, [email protected], ip=[]. sieve: msgid=<[email protected]>: forwarded to <[email protected]>
Mar 19 13:59:09 srv01 dovecot: service=lda, [email protected], ip=[]. sieve: msgid=<[email protected]>: stored mail into mailbox 'INBOX'
Mar 19 13:59:09 srv01 postfix/pipe[26119]: 0DECE85E989: to=<[email protected]>, relay=plesk_virtual, delay=1.8, delays=0.92/0/0/0.87, dsn=2.0.0, status=sent (delivered via plesk_virtual service)
Mar 19 13:59:09 srv01 postfix/qmgr[9483]: 0DECE85E989: removed
Mar 19 13:59:09 srv01 /usr/lib64/plesk-9.0/psa-pc-remote[5144]: handlers_stderr: SKIP
Mar 19 13:59:09 srv01 /usr/lib64/plesk-9.0/psa-pc-remote[5144]: SKIP during call 'limit-out' handler
Mar 19 13:59:09 srv01 check-quota[26216]: Starting the check-quota filter...
Mar 19 13:59:09 srv01 /usr/lib64/plesk-9.0/psa-pc-remote[5144]: handlers_stderr: SKIP
Mar 19 13:59:09 srv01 /usr/lib64/plesk-9.0/psa-pc-remote[5144]: SKIP during call 'check-quota' handler
Mar 19 13:59:09 srv01 spf[26218]: Starting the spf filter...
Mar 19 13:59:09 srv01 spf[26218]: SPF result: pass
Mar 19 13:59:09 srv01 spf[26218]: SPF status: PASS
Mar 19 13:59:09 srv01 /usr/lib64/plesk-9.0/psa-pc-remote[5144]: handlers_stderr: PASS
Mar 19 13:59:09 srv01 /usr/lib64/plesk-9.0/psa-pc-remote[5144]: PASS during call 'spf' handler
Mar 19 13:59:09 srv01 postfix/qmgr[9483]: 7AD1085BD30: from=<bounces+1919634-7895-factuur=debourgondischekeuken.nl@sgmail.basecone.nl>, size=15477, nrcpt=1 (queue active)
Mar 19 13:59:10 srv01 postfix/smtpd[25999]: disconnect from o1678978x89.outbound-mail.sendgrid.net[167.89.78.89]
Mar 19 13:59:10 srv01 dovecot: imap-login: Disconnected (no auth attempts in 0 secs): user=<>, rip=185.208.210.201, lip=149.210.169.196, TLS, session=<pfw5EnKEuMm50NLJ>
Mar 19 13:59:10 srv01 dovecot: imap-login: Disconnected (no auth attempts in 0 secs): user=<>, rip=2a0b:3c40:15:0:185:208:210:201, lip=2a01:7c8:aaac:130::1, TLS, session=<oHk9EnKEINAqCzxAABUAAAGFAggCEAIB>
Mar 19 13:59:21 srv01 postfix/smtp[26219]: 7AD1085BD30: to=<[email protected]>, relay=webprepare-nl.mail.protection.outlook.com[104.47.13.36]:25, delay=12, delays=0.22/0.02/0.82/11, dsn=2.6.0, status=sent (250 2.6.0 <[email protected]> [InternalId=11063835762846, Hostname=DB7PR02MB3978.eurprd02.prod.outlook.com] 23154 bytes in 9.171, 2.465 KB/sec Queued mail for delivery)
Mar 19 13:59:21 srv01 postfix/qmgr[9483]: 7AD1085BD30: removed
Mar 19 13:59:31 srv01 postfix/smtpd[22876]: connect from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:31 srv01 postfix/smtpd[25367]: connect from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:31 srv01 postfix/smtpd[19632]: connect from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:34 srv01 postfix/smtpd[25367]: lost connection after CONNECT from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:34 srv01 postfix/smtpd[25367]: disconnect from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:34 srv01 postfix/smtpd[22876]: lost connection after CONNECT from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:34 srv01 postfix/smtpd[22876]: disconnect from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:34 srv01 dovecot: imap-login: Disconnected (no auth attempts in 3 secs): user=<>, rip=2a01:7c8::ba11, lip=2a01:7c8:aaac:130::1, session=<Iq6nE3KEWv8qAQfIAAAAAAAAAAAAALoR>
Mar 19 13:59:34 srv01 dovecot: pop3-login: Disconnected (no auth attempts in 3 secs): user=<>, rip=2a01:7c8::ba11, lip=2a01:7c8:aaac:130::1, session=<frSnE3KEWf8qAQfIAAAAAAAAAAAAALoR>
Mar 19 13:59:34 srv01 postfix/smtpd[19632]: SSL_accept error from sms-monitor.transip.nl[2a01:7c8::ba11]: lost connection
Mar 19 13:59:34 srv01 postfix/smtpd[19632]: lost connection after CONNECT from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:34 srv01 postfix/smtpd[19632]: disconnect from sms-monitor.transip.nl[2a01:7c8::ba11]
Mar 19 13:59:34 srv01 dovecot: imap-login: Disconnected (no auth attempts in 3 secs): user=<>, rip=2a01:7c8::ba11, lip=2a01:7c8:aaac:130::1, TLS handshaking: Connection closed, session=<bl6sE3KEVv8qAQfIAAAAAAAAAAAAALoR>

Does anyone have an idea what is going on?

Thanks in advance!
 
This behavior can occur when an e-mail is sent to any of these addresses:
  • anonymous@...
  • drweb@...
  • drweb-daemon@...
  • kluser@...
  • mailer-daemon@...
  • mailman@...
  • postmaster@...
  • root@...
Some users create addresses like
root@user's-domain.tld
so that anything that goes to that mailbox is automatically delivered to the "real" root user, too.
 
Thanks Peter. I have solved this issue in the meantime. I accidentally set a rule in the webmail interface for this customer which forward all e-mail to my email address. Stupid, though it has been solved.

Thanks for your help!
 
Back
Top