F
FrancescoF
Guest
Hi all,
My server IP is being blacklisted by spamhaus,live,... because it's apparently sending spam.
I'm using Plesk 10 with Qmail.
So i manage to invistigate this and log all outgoing mail with the sendmail-wrapper. All mail are correctly logged (SMTP and mail sent by script) but there is no trace of spamming mail. I also analysed the maillog and nothing strange, no trace of spamming...
Here is an abuse report with headers of mail being apparently sent by my server:
Then i tried to find the UID 732 in my passwd file
but it's not present...
Have you some other ideas where the problem is? Is my IP being spoofed?
Thanks in advance for your help!
My server IP is being blacklisted by spamhaus,live,... because it's apparently sending spam.
I'm using Plesk 10 with Qmail.
So i manage to invistigate this and log all outgoing mail with the sendmail-wrapper. All mail are correctly logged (SMTP and mail sent by script) but there is no trace of spamming mail. I also analysed the maillog and nothing strange, no trace of spamming...
Here is an abuse report with headers of mail being apparently sent by my server:
Delivery-date: Tue, 26 Jun 2012 14:22:47 -0700
Received: from mon.domaine.com ([XX.XXX.XX.XX])
by pascal.junkemailfilter.com with smtp (Exim 4.77)
id 1SjdDT-0005yJ-J9 on interface=184.105.182.180
for [email protected]; Tue, 26 Jun 2012 14:22:47 -0700
Received: (qmail 11472 invoked by uid 732); 27 Jun 2012 00:27:11 -0000
Date: 27 Jun 2012 00:27:11 -0000
Message-ID: <[email protected]>
From: "Dionna" <[email protected]>
To: "XXXX" <[email protected]>
Subject: You have got a private message from Lilu
Mime-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
X-Sender-Domain: mon.domaine.com
X-Spamfilter-host: pascal.junkemailfilter.com - http://www.junkemailfilter.com
X-Mail-from: [email protected]
X-Relay-Countries: CODE_PAYS
X-Spam-Report: SpamAssassin 3.3.2 (2011-06-06) on spamd3.ctyme.com
Spam Tests:
* 6.0 BAYES_99 BODY: Bayes spam probability is 99 to 100%
* [score: 0.9994]
* 4.5 DATE_IN_FUTURE_03_06 Date: is 3 to 6 hours after Received: date
* 0.0 HTML_EXTRA_CLOSE BODY: HTML contains far too many close tags
* 0.0 HTML_MESSAGE BODY: HTML included in message
* 10 NIXSPAM_IXHASH BODY: iXhash found @ ix.dnsbl.manitu.net
* 1.0 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
* -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
* trust
* [XX.XXX.XX.XX listed in list.dnswl.org]
* 3.0 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
* above 50%
* [cf: 100]
* 3.0 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
* [cf: 100]
* 3.0 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
X-Spam-Class: SPAM-HIGH - SpamAssassin - Score=35 [3 Spam]
X-Spam-Class: SPAM-HIGH - SpamAssassin rejected - Score=35 (15) X=pascal H=mon.domaine.com [XX.XXX.XX.XX] HELO=[mon.domaine.com] F=[[email protected]] T=[[email protected]] S=[You have got a private message from Lilu] - X=pascal H=mon.domaine.com [XX.XXX.XX.XX] HELO=[mon.domaine.com] F=[[email protected]] T=[[email protected]] S=[You have got a private message from Lilu]
X-Spamsave: Yes - SpamAssassin rejected - Score=35 (15) X=pascal H=mon.domaine.com [XX.XXX.XX.XX] HELO=[mon.domaine.com] F=[[email protected]] T=[[email protected]] S=[You have got a private message from Lilu] - X=pascal H=mon.domaine.com [XX.XXX.XX.XX] HELO=[mon.domaine.com] F=[[email protected]] T=[[email protected]] S=[You have got a private message from Lilu]
X-Sender-Host-Address: XX.XXX.XX.XX
X-Sender-Host-Name: mon.domaine.com
X-Spam-Flag: yes
Then i tried to find the UID 732 in my passwd file
Received: (qmail 11472 invoked by uid 732); 27 Jun 2012 00:27:11 -0000
but it's not present...
Have you some other ideas where the problem is? Is my IP being spoofed?
Thanks in advance for your help!