• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Qmail allowing spam to be sent

StewartJ

New Pleskian
So, we sent out a good 100,000 messages last night and can't seem to figure out why we are allowing ourselves to be relayed through. First, the header:

Received: (qmail 22779 invoked from network); 8 Jan 2014 04:43:10 -0500
Received: from 71-13-77-50.static.aldl.mi.charter.com (HELO ?192.168.1.50?) (71.13.77.50)
by 65.x.x.x with ESMTPA; 8 Jan 2014 04:43:08 -0500
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
Subject: From Ocalan Joseph
To: Recipient <ocalan@terra.com>
From: "Mr.Ocalan Joseph" <ocalan@terra.com>
Date: Wed, 08 Jan 2014 04:45:09 -0500
Reply-To: ocalan2@terra.com

FROM Ocalan Joseph
EMAIL: azzizocalan@yahoo.com
=

=

How are you today?
=

Peace be unto you my good friend. I am the only surviving child of Abdullah=
Ocalan,The leader of the Kurdistan Workers Party (PKK).My father actively =
fought for the liberation and unification of our people (The Kurds) under o=
ne sovereign nation which earned him the support of many and being branded =
a rebel by others.He amassed a lot of money garnered from supporters and sy=
mpathizers alike from which he kept quite a lot for his family's use.
=

=

Before his sudden arrest in 1999,he confided in me the where about of this =
money which is ($45M)Fourty five Million united State Dollars and instructe=
d me to find means of investing the funds far away from the reach of the Tu=
rkish government who have frozen most of the accounts and assets of the PKK=
. I need you t o invest this money for the benefit of my Five yea r old son=
H assan.He is all that is left of the Ocal an family.A few months ago I wa=
s diagnosed with cancer and was told by doctors that I have no long time to=
live.
=

My dear father will not be released by the Turkish government any time soon=
.All I ask of you is to assist in the transfer and investment of the funds =
in a neutral country on behalf of my son Hassan until he is of age.l want y=
ou to send to me your contact address,your phone number,your Occupation and=
your Age.Once you get back to me,
=

l will tell you on how you can contact the bank where the money is deposite=
d. Right now i am in the hospital where i am taking treatment with my only =
son.
=

Regards,
Ocalan Joseph.
=

Please make sure your send your reply here: =

azzizocalan@yahoo.com



We don't host any of the domains involved. Our rcpthosts file only contains domains that we do host. Our whitelist has 127.0.0.1/32 and 65.x.x.x/32 so shouldn't 71.13.77.50 be rejected? What else can I check. Our system Overview shows the following for versions:

OS Linux 2.6.18-194.el5
Panel version 10.4.4 Update #57, last updated at Oct 26, 2013 04:06 AM

The system is up-to-date; last checked at Jan 4, 2014 04:03 AM

Thanks so much for any help you can give!
 
Got hit again and we don't host either domain:

Received: (qmail 30775 invoked from network); 8 Jan 2014 15:57:40 -0500
Received: from 66.83.200.154.nw.nuvox.net (HELO SOSCF.sos.local) (66.83.200.154)
by 65.x.x.x with ESMTPA; 8 Jan 2014 15:57:40 -0500
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
Subject: How are you today?
To: INFO@THECAPTAINCOURIER.COM
From: "Mr. Robert Ocalan" <robertocalan01@qq.com>
Date: Wed, 08 Jan 2014 15:57:41 -0500
Reply-To: robertocaln@qq.com

Robert Ocalan.
EMAIL: robertocaln@qq.com
=

How are you today?
=

Peace be unto you my good friend. I am the only surviving child of Abdullah=
Ocalan,The leader of the Kurdistan Workers Party (PKK).My father actively =
fought for the liberation and unification of our people (The Kurds) under o=
ne sovereign nation which earned him the support of many and being branded =
a rebel by others.He amassed a lot of money garnered from supporters and sy=
mpathizers alike from which he kept quite a lot for his family's use.
=


=

Before his sudden arrest in 1999,he confided in me the where about of this =
money which is ($45M)Fourty five Million united State Dollars and instructe=
d me to find means of investing the funds far away from the reach of the Tu=
rkish government who have frozen most of the accounts and assets of the PKK=
.I need you to invest this money for the benefit of my Five year old son Ha=
ssan.He is all that is left of the Ocalan family.A few months ago I was dia=
gnosed with cancer and was told by doctors that I have no long time to live.


My dear father will not be released by the Turkish government any time soon=
.All I ask of you is to assist in the transfer and investment of the funds =
in a neutral country on behalf of my son Hassan until he is of age.l want y=
ou to send to me your contact address,your phone number,your Occupation and=
your Age.Once you get back to me,



l will tell you on how you can contact the bank where the money is deposite=
d. Right now i am in the hospital where i am taking treatment with my only =
son.
=


Regards,
Robert Ocalan.
Please make sure your send your reply here: =

robertocaln@qq.com
 
Thanks. It was an account that a spammer had figured out the password. The reason it was hard to find was that the window to open after authenticating was 20 minutes. With a window that large there were hundreds of accounts connecting in. I dropped it to 1 minute and was able to figure it out. Thanks for the help.
 
Back
Top