» »

spamblock

spamblock

korenje3 ::

Mi lahko kdo razloži zakaj je moj email pristal na spam listi? (t-2)
imam email na lastnem strežniku @the-nox.com.

V logih se pa stalno ponavlja tole:

May 14 08:48:58 the-nox sm-mta[14957]: t4E6muvt014957: from=<>, size=6472, class=0, nrcpts=0, proto=ESMTP, daemon=MTA-v4, relay=host81-136-137-12.in-addr.btopenworld.com [81.136.137.12]
May 14 08:49:00 the-nox sm-mta[14955]: t4E6mxfS014955: <Lacasse51@the-nox.com>... User unknown
May 14 08:49:00 the-nox sm-mta[14955]: t4E6mxfS014955: from=<>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA-v4, relay=mail.microcom.dk [77.66.59.181] (may be forged)
May 14 08:49:00 the-nox sm-mta[14958]: STARTTLS=server, relay=mx0a-00114c01.pphosted.com [67.231.145.21], version=TLSv1/SSLv3, verify=NOT, cipher=DHE-RSA-AES256-SHA, bits=256/256
May 14 08:49:01 the-nox sm-mta[14958]: t4E6mx6O014958: <msyrn.intranet10@the-nox.com>... User unknown
May 14 08:49:01 the-nox sm-mta[14958]: t4E6mx6O014958: from=<>, size=19608, class=0, nrcpts=0, proto=ESMTP, daemon=MTA-v4, relay=mx0a-00114c01.pphosted.com [67.231.145.21]
May 14 08:49:02 the-nox sm-mta[14959]: STARTTLS=server, relay=mx0b-00114c01.pphosted.com [67.231.153.10], version=TLSv1/SSLv3, verify=NOT, cipher=DHE-RSA-AES256-SHA, bits=256/256
May 14 08:49:02 the-nox sm-mta[14959]: t4E6n04h014959: <melospa42052@the-nox.com>... User unknown
May 14 08:49:02 the-nox sm-mta[14959]: t4E6n04h014959: from=<>, size=20140, class=0, nrcpts=0, proto=ESMTP, daemon=MTA-v4, relay=mx0b-00114c01.pphosted.com [67.231.153.10]
May 14 08:49:06 the-nox sm-mta[14963]: t4E6n5xY014963: <0d55f0e6058887@the-nox.com>... User unknown
May 14 08:49:06 the-nox sm-mta[14963]: t4E6n5xY014963: from=<>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA-v4, relay=82-69-11-119.dsl.in-addr.zen.co.uk [82.69.11.119]
May 14 08:49:06 the-nox sm-mta[14964]: STARTTLS=server, relay=mx0a-00114c01.pphosted.com [67.231.145.21], version=TLSv1/SSLv3, verify=NOT, cipher=DHE-RSA-AES256-SHA, bits=256/256
May 14 08:49:07 the-nox sm-mta[14964]: t4E6n4RS014964: <togoorderssdfrl265@the-nox.com>... User unknown
May 14 08:49:07 the-nox sm-mta[14960]: t4E6n69a014960: <uiifavyeig1364745@the-nox.com>... User unknown
May 14 08:49:07 the-nox sm-mta[14960]: t4E6n69a014960: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA-v4, relay=darkmail.nplay.pl [89.167.48.131]
May 14 08:49:07 the-nox sm-mta[14964]: t4E6n4RS014964: from=<>, size=20600, class=0, nrcpts=0, proto=ESMTP, daemon=MTA-v4, relay=mx0a-00114c01.pphosted.com [67.231.145.21]
May 14 08:49:07 the-nox sm-mta[14961]: STARTTLS=server, relay=mail.antenne-ag.de [188.111.97.146], version=TLSv1/SSLv3, verify=NOT, cipher=AES256-SHA, bits=256/256
May 14 08:49:08 the-nox sm-mta[14961]: t4E6n6ga014961: <and.orgdas53@the-nox.com>... User unknown
May 14 08:49:08 the-nox sm-mta[14961]: t4E6n6ga014961: from=<>, size=7955, class=0, nrcpts=0, proto=ESMTP, daemon=MTA-v4, relay=mail.antenne-ag.de [188.111.97.146]
May 14 08:49:11 the-nox sm-mta[14969]: t4E6n9ut014969: <belldandy50@the-nox.com>... User unknown
May 14 08:49:11 the-nox sm-mta[14969]: t4E6n9ut014969: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA-v4, relay=[194.224.166.1]
May 14 08:49:12 the-nox sm-mta[14965]: STARTTLS=server, relay=ecohosting01.redelx.com [5.206.231.133], version=TLSv1/SSLv3, verify=NOT, cipher=DHE-RSA-AES256-GCM-SHA384, bits=256/256
May 14 08:49:12 the-nox sm-mta[14965]: t4E6nAbx014965: <cmfigueiredo5281@the-nox.com>... User unknown


od 07:00 pa do 13.00 vsako minuto.
je možno da nekdo uporablja kao odgovore o nedosegljivosti strežnika, ki jih potem moj strežnik pošilja na te emaile?
i9-12900k; 32GB DDR5-6000 CL36; Nvidia RTX 3080 ti;
Gigabyte Aorus z690 master; Be Quiet Dark Power 12 1000W

NoName ::

Znan pojav pri mail serverjih... wiki
Svoj poštni sistem skonfiguriraj tako, da bo sporočila, namenjena na neobstoječe poštne naslove zavračal (5xx) že v SMTP seji... Drugače pa je videti, da je na tvojem omrežju nekaj sila grdega... Za začetek začni logirati vse frišne povezave z lokalnega omrežja navzven (da boš izvedel IP naslov okuženega sistema), nato zablokiraj kakšen TCP/25 z vsega razen s strežnika, ...

multirbl
cbl
IP Address 84.255.238.138 is listed in the CBL. It appears to be infected with a spam sending trojan, proxy or some other form of botnet.
It was last detected at 2015-05-14 14:00 GMT (+/- 30 minutes), approximately 7 hours, 30 minutes ago.
This IP is infected (or NATting for a computer that is infected) with the kelihos spambot. In other words, it's participating in a botnet.
If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again.
I can see dumb people...They're all around us... Look, they're even on this forum!


Vredno ogleda ...

TemaSporočilaOglediZadnje sporočilo
TemaSporočilaOglediZadnje sporočilo
»

linux sendmail java

Oddelek: Programiranje
91203 (970) illion
»

dspam

Oddelek: Pomoč in nasveti
6827 (716) korenje3
»

ubuntu slapd pomoč

Oddelek: Operacijski sistemi
10655 (486) korenje3
»

Hotmail.com označi moj smtp kot spam

Oddelek: Omrežja in internet
122679 (2406) kronik
»

Linux sendmail - Problem !!!??

Oddelek: Omrežja in internet
151887 (1648) n0name

Več podobnih tem