• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Email Aliases Exposed?

G J Piper

Regular Pleskian
I recently moved from an older FreeBSD 6 server that I had been using since around 2003. I had been using aliases to control/track email spam on my old server. (every time I use a new company or online store, I'd make an alias email address specifically for that company, and delete it if it started getting spam)

About one month after switching to my new Plesk 12.5.30 u#24 CentOS 6.7 server, I started getting spam on some of those older aliases. Some of these aliases were only used once, a decade ago!

My question is this: How are spammers getting these email aliases on their list now? Many of these aliases are extremely obscure, and could not be getting hit by dictionary attackers. As an example, one of these aliases hasn't been used since 2004, and was only used one time for one email back and forth. Now suddenly spammers are hitting it.

Is there some way spammers are getting my list of over 70+ aliases from my new server?

I'm running Dovecot and Postfix.
 

Attachments

  • screen.png
    screen.png
    142.2 KB · Views: 7
Hi G J Piper,

Is there some way spammers are getting my list of over 70+ aliases from my new server?

No, there is NO WAY, that spammers/bots may get a list of your eMail-accounts, configured on your server. But you should inspect your mail - logs and the headers of your eMails, if you would like to investigate spam on your server.
It helps as well, to follow KB - article 114845, to investigate the source of spam on your server:



Consider to add depending log - entries from your logs, if you need help and add as well the eMail - headers and configuration files, so that further investigations can be done.
 
Back
Top