• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Strange mail usage!

dragnovich

Basic Pleskian
Hello I had noticed that the server Mail Server is been used very often (I have near 80 domains in the server) and it seems that is Normal... but some times and hours the delivery times grow up, loking the logs and analizing the situation it seems the server is used to send spam mails, surendly I got the mail queue full with "Failure notices" the problem becomes that there's no sender! or worst from SENDERS NOT IN THE SERVER!

I had ALL server locked up, log before smtp, user authentication, full email as mail account, etc.. I try monitoring the SCRIPTS that sends mails (like PHP MAIL routines) and does not seems that the problem comes from there.

Loking the qmail logs I notice HUNDREDS of lines like this:

Jan 20 04:10:21 SERVER qmail-remote-handlers[24406]: from=
Jan 20 04:10:21 SERVER qmail-remote-handlers[24406]: [email protected]
Jan 20 04:10:25 SERVER qmail-remote-handlers[24413]: from=
Jan 20 04:10:25 SERVER qmail-remote-handlers[24413]: [email protected]

As you can see the FROM is empty why? if is supossed to disallow any ANONYMOUS usage!
the TO emails are not in my server.

Any advice??
 
I don't have an answer yet, but I do have the same problem (also on Plesk 8.6).

Are you also getting lots of relaylock messages? I am, like these...

Jan 23 15:13:12 SERVER relaylock: /var/qmail/bin/relaylock: mail from 151.50.17.194:3273 (adsl-ull-194-17.50-151.net24.it)
Jan 23 15:13:34 SERVER relaylock: /var/qmail/bin/relaylock: mail from 65.17.48.208:54450 (host48-208.rancor.birch.net)
Jan 23 15:14:06 SERVER relaylock: /var/qmail/bin/relaylock: mail from 151.50.17.194:1435 (adsl-ull-194-17.50-151.net24.it)
 
Back
Top