Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Help with relay issue

Status
Not open for further replies.

InMaine

IS-IT--Management
Aug 1, 2012
1
0
0
US
I have been having some issues lately with large numbers of external smtp sessions being listed in my qmailstats morning report.

Our Mailserver said:
==> Server Report

External SMTP sessions: 32192
Internal SMTP sessions: 0
SMTP msgs dropped: 458
Scan Errors: 0
Non-MIME or text/plain (msgs): 657
MIME (msgs): 31077
Average scan time/msg (secs): 6.55283
QMS WC bad char (msgs): 0
QMS WC header breakage (msgs): 8
QMS WC bad MIME hdr (msgs): 0
QMS WC bad MIME content (msgs): 16
QMS WC bad MIME filename (msgs): 0
QMS WC bad MIME boundary (msgs): 0
QMS WC bad MIME assoc (msgs): 0
QMS WC bad MIME windows file (msgs): 0
QMS WC bad zip file (msgs): 0
PERLSCAN bad MIME hdr (msgs): 0
PERLSCAN bad hdr found in db (msgs): 0
PERLSCAN bad attach length (msgs): 0
PERLSCAN bad attachment type (msgs): 0
UNZIP password protected (msgs): 0
CLAMAV virus found (msgs): 53
SPAM deleted (msgs): 1887
SPAM detected (msgs): 4
SPAM quarantined (msgs): 14968
SPAM rejected (msgs): 0

None of these sessions seem to be from anyone on our system.

As far as I thought, we were not allowing any relaying of messages, but i found this in an open relay test:

Mailradar.com said:
[Method 8]
<<< 220 mail.XYZ.com ESMTP
>>> HELO mailradar.com
<<< 250 mail.XYZ.com
>>> MAIL FROM: <antispam@[216.220.XXX.XXX]>
<<< 250 ok
>>> RCPT TO: <"relaytest%mailradar.com">
<<< 250 ok
>>> QUIT
<<< 221 mail.XYZ.com
[TEST NOT PASSED]


[Method 14]
<<< 220 mail.XYZ.com ESMTP
>>> HELO mailradar.com
<<< 250 mail.XYZ.com
>>> MAIL FROM: <antispam@[216.220.XXX.XXX]>
<<< 250 ok
>>> RCPT TO: <mailradar.com!relaytest>
<<< 250 ok
>>> QUIT
<<< 221 mail.XYZ.com
[TEST NOT PASSED]

Could this be the source of my issues?
How can I close these relays?

We are running qmail set up as per qmailrocks.org

Thank you
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top