Hello. I have checked all of my configs and run several open relay tests against my server and all say I'm good. Yet every few days, I get a FLOOD of bounces coming from other mail servers saying that a message sent via my system couldn't be delivered. I can't tell if someone is sending messages from somewhere else with spoofed addresses using my domains so the bounces are coming to me, or if they're actually finding a way to relay through me. I've made at least one block list that I know of and am trying to get off of that.
Where do I start to look? I'm at a loss here.
Here's a standard message from my MAILER-DAEMON:
################################################
Hi. This is the qmail-send program at mail.xxxx.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<213.165.64.102 does not like recipient.
Remote host said: 550 5.1.1 < User is unknown {mx045}
Giving up on 213.165.64.102.
--- Below this line is a copy of the message.
Return-Path: <anonymous@mail.xxxx.com>
Received: (qmail 24759 invoked by uid 48); 6 May 2010 17:07:50 -0400
Date: 6 May 2010 17:07:50 -0400
Message-ID: <20100506210750.24758.qmail@mail.xxxx.com>
To: Subject: Ordered growth?
MIME-Version: 1.0
Content-type: text/html; charset="utf-8"
X-Mailer: eComm Php
From: Babbette@xxxxxx.org
Original Store! Great Election! ›››› <a
href=" size=4 color="orange">Try
IT</font></a><style>QvLGXIcxmxxz.oH ragu[10,25] ragu[2,60]</style>
Where do I start to look? I'm at a loss here.
Here's a standard message from my MAILER-DAEMON:
################################################
Hi. This is the qmail-send program at mail.xxxx.com.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<213.165.64.102 does not like recipient.
Remote host said: 550 5.1.1 < User is unknown {mx045}
Giving up on 213.165.64.102.
--- Below this line is a copy of the message.
Return-Path: <anonymous@mail.xxxx.com>
Received: (qmail 24759 invoked by uid 48); 6 May 2010 17:07:50 -0400
Date: 6 May 2010 17:07:50 -0400
Message-ID: <20100506210750.24758.qmail@mail.xxxx.com>
To: Subject: Ordered growth?
MIME-Version: 1.0
Content-type: text/html; charset="utf-8"
X-Mailer: eComm Php
From: Babbette@xxxxxx.org
Original Store! Great Election! ›››› <a
href=" size=4 color="orange">Try
IT</font></a><style>QvLGXIcxmxxz.oH ragu[10,25] ragu[2,60]</style>