• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Question When gmail is the mail provider, should our maillog show auth attemps?

jorge ceballos

Regular Pleskian
Server operating system version
Centos 7.9.2009
Plesk version and microupdate number
Plesk Obsidian Versión 18.0.52 Actualización 3
Hi,
Have a couple of clients whose email service is Gmail hosted.
We act as their main DNS and their NS - w/glue - are pointed to us; mail service is completely deactivated on this side for these domains.
Both reported yesterday they were missing mail from certain providers such as hotmail and yahoo.
Monitored maillog and came to my attention that yesterday maillog showed unusual activity trying to auth multiple email accounts belonging to these domains.
Is this behavior ok ? or something changed at Google ?
TIA
 
I am not quite understanding the question but as long as the MX records is pointing to google's service (which could be found here) and has the SPF setup correctly, your server shouldn't be doing anything other then sending the service that's trying to send the email know where to route the emails. If you have anything in the maillog trying to auth email accounts belonging to those domains means either someone is trying to do something bad or someone did set their web site form or whatever setup correctly.
 
Thanks, that's whats I thought, just wanted to be sure.
Seems like a DNS server's caché somewhere is stuck with an old récord.

Regards
 
It is also common that others try to break into mailboxes by brute-force attacks. It can help to have Fail2Ban in place and the Postfix, Dovecot and Recidive rules active.
 
Back
Top