Eric Pretorious
Regular Pleskian
E-mail Accounts: Stopping Outbound Spam
WARNING: Some names have been changed to protect the privacy of the individuals involved
During the installation and configuration of Plesk 11.x, we had created an e-mail account for testing purposes (info@example.com). It seems that someone recently discovered the account and guessed the password and then began relaying an enormous amount of UCE/Spam using the account. When we discovered this, we immediately deleted the account (Domains -> Example.com -> Mail -> Remove) but - more than 60 hours later - the account still appears to be very active:
Looking more closely at message ID E63021E1468:
WARNING: Some names have been changed to protect the privacy of the individuals involved
During the installation and configuration of Plesk 11.x, we had created an e-mail account for testing purposes (info@example.com). It seems that someone recently discovered the account and guessed the password and then began relaying an enormous amount of UCE/Spam using the account. When we discovered this, we immediately deleted the account (Domains -> Example.com -> Mail -> Remove) but - more than 60 hours later - the account still appears to be very active:
Code:
Aug 6 20:27:28 www postfix/qmgr[29665]: EF1331C9498: from=<info@example.com>, size=557, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: E2AA22417E7: from=<info@example.com>, size=552, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: EC2DE1C92B6: from=<info@example.com>, size=778, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: E36E61E0446: from=<info@example.com>, size=556, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: E69E31C928F: from=<info@example.com>, size=558, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: EC9151E18CE: from=<info@example.com>, size=767, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: E5DE01E18B2: from=<info@example.com>, size=754, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: EC7F71E1EC9: from=<info@example.com>, size=554, nrcpt=5 (queue active)
Aug 6 20:27:28 www postfix/qmgr[29665]: E63021E1468: from=<info@example.com>, size=759, nrcpt=5 (queue active)
Looking more closely at message ID E63021E1468:
Code:
...<SNIP>...
Aug 6 19:17:29 www postfix/error[9897]: E63021E1468: to=<consult4u2@comcast.net>, relay=none, delay=409051, delays=409051/0/0/0.02, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to mx2.comcast.net[2001:558:fe2d:70::22]:25: Network is unreachable)
Aug 6 19:18:02 www postfix/smtp[10023]: E63021E1468: to=<trish.danby@diageo.com>, relay=cluster3.eu.messagelabs.com[194.106.220.51]:25, delay=409084, delays=409051/31/1.6/0, dsn=4.0.0, status=deferred (host cluster3.eu.messagelabs.com[194.106.220.51] refused to talk to me: 501 Connection rejected by policy [7.7] 9206, please visit www.messagelabs.com/support for more details about this error message.)
Aug 6 20:27:29 www postfix/error[18017]: E63021E1468: to=<consult4u2@comcast.net>, relay=none, delay=413251, delays=413251/0.01/0/0, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to mx2.comcast.net[2001:558:fe2d:70::22]:25: Network is unreachable)
Aug 6 20:28:04 www postfix/smtp[17857]: E63021E1468: to=<trish.danby@diageo.com>, relay=none, delay=413286, delays=413251/34/1.4/0, dsn=4.4.1, status=deferred (connect to cluster3.eu.messagelabs.com[194.106.220.51]:25: Connection refused)
Aug 6 21:38:01 www postfix/error[24861]: E63021E1468: to=<consult4u2@comcast.net>, relay=none, delay=417483, delays=417483/0.01/0/0.01, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to mx1.comcast.net[2001:558:fe14:70::22]:25: Network is unreachable)
Aug 6 21:38:20 www postfix/smtp[24899]: E63021E1468: to=<trish.danby@diageo.com>, relay=cluster3.eu.messagelabs.com[85.158.139.3]:25, delay=417502, delays=417483/18/1.2/0, dsn=4.0.0, status=deferred (host cluster3.eu.messagelabs.com[85.158.139.3] refused to talk to me: 501 Connection rejected by policy [7.7] 9011, please visit www.messagelabs.com/support for more details about this error message.)
...<SNIP>...
- Why is Postfix still accepting e-mail for this account? How can we permanently disable this account?
- There don't appear to be any entries in /usr/local/psa/var/log/maillog that give us a clue about the source IP address of these messages. How can we determine the source of these messages?
Last edited: