• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Issue Plesk 11.5.30 Qmail mailer deamon bounce "failure notice"

GiulianoP

Basic Pleskian
Hi all,
I use Plesk 11.5.30 with CentOS 6.9 (final version). I have a problem with QMail because I have in the queue there are a lot of mail with subject "failure notice". When I open this mail is impossible to understand who is the sender:

Received: (qmail 23300 invoked for bounce); 19 Jul 2019 18:40:56 +0200
Date: 19 Jul 2019 18:40:56 +0200
From: MAILER-DAEMON@mail.my-company.it
To: user1@clientdomain1.com
Subject: failure notice

I have found the mail in /var/qmail/queue/mess/0 but doesn't show any information about the sender and the authentication process seems ok (/usr/local/psa/admin/bin/mail_auth_view), so I think that a pc of my customer has infected.

Any idea for to fix this situation?

Thanking in advance and sorry for my english.

Giuliano
 
Check /var/log/maillog to see what's going on.

There are several possibilities here, a SMTP account breach, a rogue script (due to a broken in hosting or a vunerable web page) or an actual spammer with a valid account.

The cause needs to be discovered immediately or your server's IP will get blacklisted. This is something you'll need to check when this is over in any case.
 
Yea, probably an account that was broken into, either via a vulnerable client device, a weak or stolen password, ... who knows.

The Outgoing Mail Control feature in Plesk is very good at catching these kind of issues before they cause greater harm. I can only recommend upgrading to a Plesk version that has this feature, if you can.
 
Back
Top