• We value your experience with Plesk during 2024
    Plesk strives to perform even better in 2025. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2024.
    Please take this short survey:

    https://pt-research.typeform.com/to/AmZvSXkx
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Issue suspicious mass mail sent, Plesk outgoing mail control does not record

Pan_Duke

Basic Pleskian
Hi all!
today a server got blaclisted in TRUNCATE. After searching i found that the mail log is for two hours full of such logs:
Code:
Sep 30 15:32:51 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:51 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:51 myservername drweb[27341]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27341]: scan: the message(drweb.tmp.2MvoVj) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27342]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27342]: scan: the message(drweb.tmp.V2SLYe) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27343]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27343]: scan: the message(drweb.tmp.MaZddo) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27344]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27344]: scan: the message(drweb.tmp.25pWYu) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27345]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27345]: scan: the message(drweb.tmp.JZA0vz) sent by [email protected] to [email protected] is passed
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: handlers_stderr: PASS
Sep 30 15:32:52 myservername /usr/lib64/plesk-9.0/psa-pc-remote[18756]: PASS during call 'drweb' handler
Sep 30 15:32:52 myservername drweb[27346]: Starting the drweb filter...
Sep 30 15:32:52 myservername qmail-queue[27346]: scan: the message(drweb.tmp.P55quG) sent by [email protected] to [email protected] is passed
In the subscription panel of theaffecteddomain.com, the outgoing mail control has a limit of 40 emails per hour (the mail log has hundreds of emails sent) and the pop up graph in the same page reports that there are 3 nessages sent from this domain.

Also, the "Allow using Sendmail for scripts and users on this subscription" setting is unchecked as well for quite a while now.

Is there a way to find out why all these messages bypassed the plesk outgoing mail control?
How can i prevent such situations in the future?
 
Back
Top