Nami_Abdelmoula
New Pleskian
Hello
when i check my server with this command
netstat -tn 2>/dev/null | grep :143 | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr | head
I get this:
16 204.93.188.100
1 41.xx.xx.xx.xx(my ip)
So i take look on mail outgoing i found this
statistics: max connection rate 1/60s for (smtp:194.63.142.101) at Apr 11 09:28:44
Apr 11 09:32:05 myserver postfix/anvil[13245]: statistics: max connection count 1 for (smtp:194.63.142.101) at Apr 11 09:28:44
Apr 11 09:32:05 vmyserver postfix/anvil[13245]: statistics: max cache size 1 at Apr 11 09:28:44
and this
connection from localhost [127.0.0.1] at port 42887
Apr 11 09:00:02 vps10039-cloud spamd[9334]: spamd: using default config for user@mydomain: /var/qmail/mailnames/plc-c.com/kamal/.spamassassin/user_pr efs
Apr 11 09:00:02 vps10039-cloud spamd[9334]: spamd: processing message <[email protected]> for user@mydomain:30
Apr 11 09:00:07 vps10039-cloud spamd[9334]: spamd: clean message (0.8/7.0) for user@mydomain:30 in 5.1 seconds, 1164 bytes.
Apr 11 09:00:07 vps10039-cloud spamd[9334]: spamd: result: . 0 - DKIM_ADSP_NXDOMAIN,NO_RELAYS scantime=5.1,size=1164,user=[email protected],uid=30,requir ed_score=7.0,rhost=localhost,raddr=127.0.0.1,rport=42887,mid=<[email protected]>,autolearn=no
Apr 11 09:00:07 vps10039-cloud spamd[9329]: prefork: child states: II
Apr 11 09:00:07 vps10039-cloud postfix/pipe[11789]: 13CD9108E23: to=<user@mydomain>, orig_to=<root>, relay=plesk_virtual, delay=5.4, delays=0/0.03/0/ 5.4, dsn=2.0.0, status=sent (delivered via plesk_virtual service)
Apr 11 09:00:07 vps10039-cloud postfix/qmgr[23080]: 13CD9108E23: removed
Apr 11 09:00:10 vps10039-cloud courier-pop3s: Connection, ip=[::ffff:92.99.167.210]
Apr 11 09:00:11 vps10039-cloud courier-pop3s: LOGIN, user=user@mydomain, ip=[::ffff:92.99.167.210], port=[50945]
Apr 11 09:00:23 vps10039-cloud courier-pop3s: LOGOUT, user=user@mydomain, ip=[::ffff:92.99.167.210], port=[50945], top=0, retr=1400, rcvd=34, sent=20 330, time=12, stls=1
Any advise please
when i check my server with this command
netstat -tn 2>/dev/null | grep :143 | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr | head
I get this:
16 204.93.188.100
1 41.xx.xx.xx.xx(my ip)
So i take look on mail outgoing i found this
statistics: max connection rate 1/60s for (smtp:194.63.142.101) at Apr 11 09:28:44
Apr 11 09:32:05 myserver postfix/anvil[13245]: statistics: max connection count 1 for (smtp:194.63.142.101) at Apr 11 09:28:44
Apr 11 09:32:05 vmyserver postfix/anvil[13245]: statistics: max cache size 1 at Apr 11 09:28:44
and this
connection from localhost [127.0.0.1] at port 42887
Apr 11 09:00:02 vps10039-cloud spamd[9334]: spamd: using default config for user@mydomain: /var/qmail/mailnames/plc-c.com/kamal/.spamassassin/user_pr efs
Apr 11 09:00:02 vps10039-cloud spamd[9334]: spamd: processing message <[email protected]> for user@mydomain:30
Apr 11 09:00:07 vps10039-cloud spamd[9334]: spamd: clean message (0.8/7.0) for user@mydomain:30 in 5.1 seconds, 1164 bytes.
Apr 11 09:00:07 vps10039-cloud spamd[9334]: spamd: result: . 0 - DKIM_ADSP_NXDOMAIN,NO_RELAYS scantime=5.1,size=1164,user=[email protected],uid=30,requir ed_score=7.0,rhost=localhost,raddr=127.0.0.1,rport=42887,mid=<[email protected]>,autolearn=no
Apr 11 09:00:07 vps10039-cloud spamd[9329]: prefork: child states: II
Apr 11 09:00:07 vps10039-cloud postfix/pipe[11789]: 13CD9108E23: to=<user@mydomain>, orig_to=<root>, relay=plesk_virtual, delay=5.4, delays=0/0.03/0/ 5.4, dsn=2.0.0, status=sent (delivered via plesk_virtual service)
Apr 11 09:00:07 vps10039-cloud postfix/qmgr[23080]: 13CD9108E23: removed
Apr 11 09:00:10 vps10039-cloud courier-pop3s: Connection, ip=[::ffff:92.99.167.210]
Apr 11 09:00:11 vps10039-cloud courier-pop3s: LOGIN, user=user@mydomain, ip=[::ffff:92.99.167.210], port=[50945]
Apr 11 09:00:23 vps10039-cloud courier-pop3s: LOGOUT, user=user@mydomain, ip=[::ffff:92.99.167.210], port=[50945], top=0, retr=1400, rcvd=34, sent=20 330, time=12, stls=1
Any advise please