• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Issue Spam sent from webmail

SalvadorS

Regular Pleskian
Hello,

First of all thank you for reading this topic.

I have a spammer in one of our servers, sending spam from webmail. So I can find this in mail.info from the info on spamhaus (spamhaus don't show me the full headers yet...)

Oct 11 08:12:37 xxx postfix/smtpd[11109]: connect from localhost[127.0.0.1]

Oct 11 08:12:37 xxx postfix/smtpd[11109]: NOQUEUE: reject: RCPT from localhost[127.0.0.1]: 554 5.7.1 <info@traxxus.ch>: Relay access denied; from=<info@kontakt-ch.net> to=<info@traxxus.ch> proto=ESMTP helo=<kontakt-ch.net>

Oct 11 08:12:37 xxx postfix/smtpd[11109]: disconnect from localhost[127.0.0.1]

How can I know which email account is using the spammer?

Thank you
 
It seems the spammer send a few spam emails and then disappear, so that method is not good for me at this time. Thank you very much for the reply.
 
Hi SalvadorS,

if you can't elimate the script, pls. consider to switch of sendmail usage at your server, untill you are able to eliminate the script on your server.

Second, pls. post your corresponding postfix - configuration, so that people willing to help you have the chance to investigate possible misconfigurations together with you.
 
Hi!

Thanks again for replying.

I am not sure if there is an script or a spammer sending mail from webmail. I check all the POST from de domains logs with the hour of the spam mails and there aren´t POST in the access_log of the domains on the server. But also I don´t see in the logs which email account log in at that time to send spam. Also mail is limited in the server so the spammer send a few mails.

Spamhaus don´t send me full headers so I am lost...
 
Back
Top