open relay
Posted: Wed Oct 04, 2006 11:06 am
I seem to be sending out spam as an open relay. I know my users are not sending these out.
And we don't have any dealings with Taiwan or Russia:
my /var/opt/scalix/sys/smtpd.cfg :
my /etc/mail/sendmail.mc (I did not include the lines starting with 'dnl'):
Any suggestions? Thanks in Advance.
Oct 4 10:27:32 mail sendmail[30486]: k945IL4F020395: to=<akhandjtiwari@gmail.com>, delay=09:09:08, xdelay=00:00:02, mailer=esmtp, pri=933892, relay=alt1.gmail-smtp-in.l.google.com. [66.249.93.114], dsn=4.2.1, stat=Deferred: 450-4.2.1 The Gmail user you are trying to contact is receiving
Oct 4 10:27:33 mail sendmail[30486]: k945IL4F020395: to=<akhandjtiwari@gmail.com>, delay=09:09:09, xdelay=00:00:03, mailer=esmtp, pri=933892, relay=gsmtp163.google.com. [64.233.163.27], dsn=4.2.1, stat=Deferred: 450-4.2.1 The Gmail user you are trying to contact is receiving
Oct 4 10:27:34 mail sendmail[30486]: k945IL4F020395: to=<akhandjtiwari@gmail.com>, delay=09:09:10, xdelay=00:00:04, mailer=esmtp, pri=933892, relay=gsmtp183.google.com. [64.233.183.27], dsn=4.2.1, stat=Deferred: 450-4.2.1 The Gmail user you are trying to contact is receiving
Oct 4 10:29:35 mail sendmail[30486]: k9455Y6b019914: to=<bulletinbeatify@royaloakhomes.com>, delay=09:23:59, xdelay=00:02:00, mailer=esmtp, pri=1041188, relay=royaloakhomes.com. [66.116.109.62], dsn=4.0.0, stat=Deferred: Connection timed out with royaloakhomes.com.
Oct 4 10:29:58 mail sendmail[30486]: k941Tlg1013123: to=<billiard@1-sovetnik.com>, delay=13:00:07, xdelay=00:00:23, mailer=esmtp, pri=1292776, relay=mxs.valuehost.ru. [217.112.42.216], dsn=4.3.0, stat=Deferred: 451 bad reverse DNS
Oct 4 10:30:03 mail sendmail[30486]: k941Tlg1013123: to=<billiard@1-sovetnik.com>, delay=13:00:12, xdelay=00:00:28, mailer=esmtp, pri=1292776, relay=mxs2.valuehost.ru. [217.112.42.216], dsn=4.3.0, stat=Deferred: 451 bad reverse DNS
And we don't have any dealings with Taiwan or Russia:
[root@mail ~]# lsof -i :25
sendmail 31902 root 4u IPv4 5850588 TCP localhost.localdomain:smtp (LISTEN)
sendmail 31903 root 8u IPv6 5850684 TCP my.FQDN.com:50377->mx3.valuehost.ru:smtp (SYN_SENT)
omsmtpd 8615 root 30u IPv4 5826001 TCP my.FQDN.com:smtp->61-62-4-2-adsl-tpe.dynamic.so-net.net.tw:1819 (ESTABLISHED)
my /var/opt/scalix/sys/smtpd.cfg :
Code: Select all
EXTENSIONS=AUTH,DSN,8BITMIME
GREETING=SMTPD
SMTPFILTER=TRUE
RELAY accept 127.0.0.1
RELAY accept my.FQDN.com
RELAY Log_Reject ALL
# extra rules added to prevent open relay usage
RECIPIENT Log_Reject *@*@*
RECIPIENT Log_Reject *%*
RECIPIENT Log_Reject *!*
RECIPIENT Log_Reject *#*@*
my /etc/mail/sendmail.mc (I did not include the lines starting with 'dnl'):
Code: Select all
include(`/usr/share/sendmail-cf/m4/cf.m4')dnl
VERSIONID(`setup for linux')dnl
OSTYPE(`linux')dnl
define(`confDEF_USER_ID',``8:12'')dnl
define(`confTO_CONNECT', `1m')dnl
define(`confTO_COMMAND', `2m')dnl
define(`confTRY_NULL_MX_LIST',true)dnl
define(`confDONT_PROBE_INTERFACES',true)dnl
define(`PROCMAIL_MAILER_PATH',`/usr/bin/procmail')dnl
define(`ALIAS_FILE', `/etc/aliases')dnl
define(`STATUS_FILE', `/var/log/mail/statistics')dnl
define(`UUCP_MAILER_MAX', `2000000')dnl
define(`confUSERDB_SPEC', `/etc/mail/userdb.db')dnl
define(`confPRIVACY_FLAGS', `goaway,noreceipts')dnl
define(`confAUTH_OPTIONS', `A')dnl
define(`confDOUBLE_BOUNCE_ADDRESS', `')dnl
define(`confTO_IDENT', `0')dnl
FEATURE(delay_checks)dnl
FEATURE(`no_default_msa',`dnl')dnl
FEATURE(`smrsh',`/usr/sbin/smrsh')dnl
FEATURE(`mailertable',`hash -o /etc/mail/mailertable.db')dnl
FEATURE(`virtusertable',`hash -o /etc/mail/virtusertable.db')dnl
FEATURE(redirect)dnl
FEATURE(always_add_domain)dnl
FEATURE(use_cw_file)dnl
FEATURE(use_ct_file)dnl
define(`confCONNECTION_RATE_THROTTLE', 5)dnl
FEATURE(local_procmail,`',`procmail -t -Y -a $h -d $u')dnl
FEATURE(`access_db',`hash -T<TMPF> -o /etc/mail/access.db')dnl
FEATURE(`blacklist_recipients')dnl
EXPOSED_USER(`root')dnl
DAEMON_OPTIONS(`Port=smtp,Addr=127.0.0.1, Name=MTA')dnl
FEATURE(`dnsbl', `relays.ordb.org', `"550 Email rejected due to sending server misconfiguration - see http://www.ordb.org/faq/\#why_rejected"')dnl
define('confINPUT_MAIL_FILTERS', 'clmilter')
INPUT_MAIL_FILTER(`clmilter',`S=local:/var/run/clamav-milter/clamav.sock, F=, T=S:4m;R:4m')dnl
define('confINPUT_MAIL_FILTERS', 'spamassassin')
INPUT_MAIL_FILTER(`spamassassin',`S=local:/var/run/spamass-milter/spamass-milter.sock, F=, T=C:10s;S:10s;R:30s;E:2m')dnl
MAILER(smtp)dnl
MAILER(procmail)dnl
Any suggestions? Thanks in Advance.