• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.

Question When gmail is the mail provider, should our maillog show auth attemps?

jorge ceballos

Regular Pleskian
Server operating system version
Centos 7.9.2009
Plesk version and microupdate number
Plesk Obsidian Versión 18.0.52 Actualización 3
Hi,
Have a couple of clients whose email service is Gmail hosted.
We act as their main DNS and their NS - w/glue - are pointed to us; mail service is completely deactivated on this side for these domains.
Both reported yesterday they were missing mail from certain providers such as hotmail and yahoo.
Monitored maillog and came to my attention that yesterday maillog showed unusual activity trying to auth multiple email accounts belonging to these domains.
Is this behavior ok ? or something changed at Google ?
TIA
 
I am not quite understanding the question but as long as the MX records is pointing to google's service (which could be found here) and has the SPF setup correctly, your server shouldn't be doing anything other then sending the service that's trying to send the email know where to route the emails. If you have anything in the maillog trying to auth email accounts belonging to those domains means either someone is trying to do something bad or someone did set their web site form or whatever setup correctly.
 
Thanks, that's whats I thought, just wanted to be sure.
Seems like a DNS server's caché somewhere is stuck with an old récord.

Regards
 
It is also common that others try to break into mailboxes by brute-force attacks. It can help to have Fail2Ban in place and the Postfix, Dovecot and Recidive rules active.
 
Back
Top