• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Spammer Using my server

E

eewd

Guest
Having checked the mail queue on Plesk I found yet another 500 e-mails to thousands of AOL, Yahoo and Hotmail addresses.

I've set the relaying preferences to

Authorization Required for SMTP and given POP a lock of 1min.

I've even disabled Mail on the domain that the spam is originating from...

How can I stop the spammers?

Thanks
 
They're either using a compromised user account, or relaying through a vulnerable web app. You'll need to look through your logs, maillog, and your domains web logs, to try to isolate it.
 
If I delete the domain that the spam is coming from should that sort it??

Also, does plesk have a way of viewing logs or am I going to have to SSH in? (I am a bit of a n00b)

Thanks,
 
You'll have to access SSH to view the logs. Depending on how the server has been compromised, deleting the domain may resolve the issue, but it very well may not as well.
 
We would normally remove the MX record for this domain's DNS so that no mail could be sent to or from the server for this domain, while you research what is happening.
 
Back
Top