ScottGoddard
Basic Pleskian
It seems I have a problem with SMTP authorisation and my server is sending out spam from a user that does not seem to exist. The logfile below has been anonimised and show one of the spam emails sent.
As far as I can see there is no user called 'barry' within Plesk although it does form part of other usernames such as 'barry.smith@mydomain.co.uk' or 'barry@myotherdomain.co.uk'
Any ideas how to resolve this? How do I find and delete/change password for this user?
Jun 14 11:36:59 myservername postfix/smtpd[7267]: D6FED6C2BD: client=unknown[106.76.218.41], sasl_method=PLAIN, sasl_username=barry
Jun 14 11:37:01 myservername postfix/cleanup[7198]: D6FED6C2BD: message-id=<403DB68E-E8DB-4E38-822F-2E293FB8370B@mydomain.co.uk>
Jun 14 11:37:01 myservername postfix/qmgr[8066]: D6FED6C2BD: from=<petermharrison@mydomain.co.uk>, size=720, nrcpt=1 (queue active)
Jun 14 11:37:03 myservername postfix/smtp[7173]: D6FED6C2BD: to=<trevor.pathak@targetdomain.co.uk>, relay=targetdomain-co-uk.mail.protection.outlook.com[213.199.180.170]:25, delay=3.9, delays=2/0/0.47/1.4, dsn=2.6.0, status=sent (250 2.6.0 <403DB68E-E8DB-4E38-822F-2E293FB8370B@mydomain.co.uk> [InternalId=131322920045177, Hostname=DBXPR07MB431.eurprd07.prod.outlook.com] 8268 bytes in 0.172, 46.939 KB/sec Queued mail for delivery)
Jun 14 11:37:03 myservername postfix/qmgr[8066]: D6FED6C2BD: removed
As far as I can see there is no user called 'barry' within Plesk although it does form part of other usernames such as 'barry.smith@mydomain.co.uk' or 'barry@myotherdomain.co.uk'
Any ideas how to resolve this? How do I find and delete/change password for this user?
Jun 14 11:36:59 myservername postfix/smtpd[7267]: D6FED6C2BD: client=unknown[106.76.218.41], sasl_method=PLAIN, sasl_username=barry
Jun 14 11:37:01 myservername postfix/cleanup[7198]: D6FED6C2BD: message-id=<403DB68E-E8DB-4E38-822F-2E293FB8370B@mydomain.co.uk>
Jun 14 11:37:01 myservername postfix/qmgr[8066]: D6FED6C2BD: from=<petermharrison@mydomain.co.uk>, size=720, nrcpt=1 (queue active)
Jun 14 11:37:03 myservername postfix/smtp[7173]: D6FED6C2BD: to=<trevor.pathak@targetdomain.co.uk>, relay=targetdomain-co-uk.mail.protection.outlook.com[213.199.180.170]:25, delay=3.9, delays=2/0/0.47/1.4, dsn=2.6.0, status=sent (250 2.6.0 <403DB68E-E8DB-4E38-822F-2E293FB8370B@mydomain.co.uk> [InternalId=131322920045177, Hostname=DBXPR07MB431.eurprd07.prod.outlook.com] 8268 bytes in 0.172, 46.939 KB/sec Queued mail for delivery)
Jun 14 11:37:03 myservername postfix/qmgr[8066]: D6FED6C2BD: removed