• The APS Catalog has been deprecated and removed from all Plesk Obsidian versions.
    Applications already installed from the APS Catalog will continue working. However, Plesk will no longer provide support for APS applications.
  • Please be aware: with the Plesk Obsidian 18.0.78 release, the support for the ngx_pagespeed.so module will be deprecated and removed from the sw-nginx package.

Question When gmail is the mail provider, should our maillog show auth attemps?

jorge ceballos

Regular Pleskian
Server operating system version
Centos 7.9.2009
Plesk version and microupdate number
Plesk Obsidian Versión 18.0.52 Actualización 3
Hi,
Have a couple of clients whose email service is Gmail hosted.
We act as their main DNS and their NS - w/glue - are pointed to us; mail service is completely deactivated on this side for these domains.
Both reported yesterday they were missing mail from certain providers such as hotmail and yahoo.
Monitored maillog and came to my attention that yesterday maillog showed unusual activity trying to auth multiple email accounts belonging to these domains.
Is this behavior ok ? or something changed at Google ?
TIA
 
I am not quite understanding the question but as long as the MX records is pointing to google's service (which could be found here) and has the SPF setup correctly, your server shouldn't be doing anything other then sending the service that's trying to send the email know where to route the emails. If you have anything in the maillog trying to auth email accounts belonging to those domains means either someone is trying to do something bad or someone did set their web site form or whatever setup correctly.
 
Thanks, that's whats I thought, just wanted to be sure.
Seems like a DNS server's caché somewhere is stuck with an old récord.

Regards
 
It is also common that others try to break into mailboxes by brute-force attacks. It can help to have Fail2Ban in place and the Postfix, Dovecot and Recidive rules active.
 
Back
Top