hi guys !
i think my server is sending spam, a couple of day ago was receiving lots of bounced emails, so i checked the queue an it was very big. Cleared the queue and its now empty almost all the time.
Now i´m checking the mail logs and still are lots of rare lines like this :
Oct 16 08:52:58 panel postfix/smtpd[2588]: connect from unknown[191.96.249.24]
Oct 16 08:53:00 panel postfix/smtpd[2038]: warning: unknown[23.226.136.33]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:02 panel postfix/smtpd[2588]: warning: unknown[191.96.249.24]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:03 panel postfix/smtpd[2588]: disconnect from unknown[191.96.249.24]
Oct 16 08:53:06 panel postfix/smtpd[2038]: lost connection after AUTH from unknown[23.226.136.33]
Oct 16 08:53:06 panel postfix/smtpd[2038]: disconnect from unknown[23.226.136.33]
Oct 16 08:53:09 panel postfix/smtpd[2627]: connect from unknown[23.226.136.33]
Oct 16 08:53:10 panel postfix/smtpd[2627]: Anonymous TLS connection established from unknown[23.226.136.33]: TLSv1 with cipher AES128-SHA (128/128 bits)
Oct 16 08:53:12 panel postfix/smtpd[2590]: connect from unknown[191.96.249.61]
Oct 16 08:53:14 panel postfix/smtpd[2627]: lost connection after AUTH from unknown[23.226.136.33]
Oct 16 08:53:14 panel postfix/smtpd[2627]: disconnect from unknown[23.226.136.33]
Oct 16 08:53:18 panel postfix/smtpd[2588]: warning: hostname radheengineering.info does not resolve to address 191.96.249.26
Oct 16 08:53:18 panel postfix/smtpd[2588]: connect from unknown[191.96.249.26]
Oct 16 08:53:19 panel postfix/smtpd[2590]: warning: unknown[191.96.249.61]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:20 panel postfix/smtpd[2590]: disconnect from unknown[191.96.249.61]
Oct 16 08:53:22 panel postfix/smtpd[2588]: warning: unknown[191.96.249.26]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:22 panel postfix/smtpd[2588]: disconnect from unknown[191.96.249.26]
Oct 16 08:53:22 panel postfix/smtpd[2038]: connect from unknown[23.226.136.33]
Oct 16 08:53:24 panel postfix/smtpd[2038]: Anonymous TLS connection established from unknown[23.226.136.33]: TLSv1 with cipher AES128-SHA (128/128 bits)
Oct 16 08:53:27 panel postfix/smtpd[2038]: warning: unknown[23.226.136.33]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:27 panel postfix/smtpd[2038]: lost connection after AUTH from unknown[23.226.136.33]
Oct 16 08:53:27 panel postfix/smtpd[2038]: disconnect from unknown[23.226.136.33]
Oct 16 08:53:29 panel postfix/smtpd[2511]: connect from unknown[191.96.249.24]
Oct 16 08:53:33 panel postfix/smtpd[2511]: warning: unknown[191.96.249.24]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:34 panel postfix/smtpd[2511]: disconnect from unknown[191.96.249.24]
Oct 16 08:53:43 panel postfix/smtpd[2590]: connect from unknown[191.96.249.61]
Oct 16 08:53:49 panel postfix/smtpd[2590]: warning: unknown[191.96.249.61]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:49 panel postfix/smtpd[2590]: disconnect from unknown[191.96.249.61]
Oct 16 08:53:50 panel postfix/smtpd[2588]: warning: hostname radheengineering.info does not resolve to address 191.96.249.26
i have no idea how to proceed to solve this. I´m looking for someone in the staff who can do the job, not for free obviously.
i think my server is sending spam, a couple of day ago was receiving lots of bounced emails, so i checked the queue an it was very big. Cleared the queue and its now empty almost all the time.
Now i´m checking the mail logs and still are lots of rare lines like this :
Oct 16 08:52:58 panel postfix/smtpd[2588]: connect from unknown[191.96.249.24]
Oct 16 08:53:00 panel postfix/smtpd[2038]: warning: unknown[23.226.136.33]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:02 panel postfix/smtpd[2588]: warning: unknown[191.96.249.24]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:03 panel postfix/smtpd[2588]: disconnect from unknown[191.96.249.24]
Oct 16 08:53:06 panel postfix/smtpd[2038]: lost connection after AUTH from unknown[23.226.136.33]
Oct 16 08:53:06 panel postfix/smtpd[2038]: disconnect from unknown[23.226.136.33]
Oct 16 08:53:09 panel postfix/smtpd[2627]: connect from unknown[23.226.136.33]
Oct 16 08:53:10 panel postfix/smtpd[2627]: Anonymous TLS connection established from unknown[23.226.136.33]: TLSv1 with cipher AES128-SHA (128/128 bits)
Oct 16 08:53:12 panel postfix/smtpd[2590]: connect from unknown[191.96.249.61]
Oct 16 08:53:14 panel postfix/smtpd[2627]: lost connection after AUTH from unknown[23.226.136.33]
Oct 16 08:53:14 panel postfix/smtpd[2627]: disconnect from unknown[23.226.136.33]
Oct 16 08:53:18 panel postfix/smtpd[2588]: warning: hostname radheengineering.info does not resolve to address 191.96.249.26
Oct 16 08:53:18 panel postfix/smtpd[2588]: connect from unknown[191.96.249.26]
Oct 16 08:53:19 panel postfix/smtpd[2590]: warning: unknown[191.96.249.61]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:20 panel postfix/smtpd[2590]: disconnect from unknown[191.96.249.61]
Oct 16 08:53:22 panel postfix/smtpd[2588]: warning: unknown[191.96.249.26]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:22 panel postfix/smtpd[2588]: disconnect from unknown[191.96.249.26]
Oct 16 08:53:22 panel postfix/smtpd[2038]: connect from unknown[23.226.136.33]
Oct 16 08:53:24 panel postfix/smtpd[2038]: Anonymous TLS connection established from unknown[23.226.136.33]: TLSv1 with cipher AES128-SHA (128/128 bits)
Oct 16 08:53:27 panel postfix/smtpd[2038]: warning: unknown[23.226.136.33]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:27 panel postfix/smtpd[2038]: lost connection after AUTH from unknown[23.226.136.33]
Oct 16 08:53:27 panel postfix/smtpd[2038]: disconnect from unknown[23.226.136.33]
Oct 16 08:53:29 panel postfix/smtpd[2511]: connect from unknown[191.96.249.24]
Oct 16 08:53:33 panel postfix/smtpd[2511]: warning: unknown[191.96.249.24]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:34 panel postfix/smtpd[2511]: disconnect from unknown[191.96.249.24]
Oct 16 08:53:43 panel postfix/smtpd[2590]: connect from unknown[191.96.249.61]
Oct 16 08:53:49 panel postfix/smtpd[2590]: warning: unknown[191.96.249.61]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 16 08:53:49 panel postfix/smtpd[2590]: disconnect from unknown[191.96.249.61]
Oct 16 08:53:50 panel postfix/smtpd[2588]: warning: hostname radheengineering.info does not resolve to address 191.96.249.26
i have no idea how to proceed to solve this. I´m looking for someone in the staff who can do the job, not for free obviously.