1

Topic: fresh install of iRedMail and it looks like my host is sending spams

==== Required information ====
- iRedMail version (check /etc/iredmail-release): 0.9.3
- Linux/BSD distribution name and version: CentOS Linux release 7.2.1511 (Core)
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Apache
- Manage mail accounts with iRedAdmin-Pro? no
- Related log if you're reporting an issue:

I have a fresh install of iRedMail and it looks like its being used to send spams.

looking at my mail logs i see alot of mail being routed

Jan 18 15:16:54 host1 postfix/qmgr[2911]: 7CC8922154F2: removed
Jan 18 15:16:54 host1 postfix/smtpd[9867]: connect from host1.example.com[127.0.0.1]
Jan 18 15:16:54 host1 postfix/smtpd[9867]: 886D5220FF6C: client=host1.example.com[127.0.0.1]
Jan 18 15:16:54 host1 postfix/cleanup[10181]: 886D5220FF6C: message-id=<d453e7586fe9e8b43a5b460c90157425@example.com>
Jan 18 15:16:54 host1 postfix/smtpd[9867]: disconnect from host1.example.com[127.0.0.1]
Jan 18 15:16:54 host1 postfix/qmgr[2911]: 886D5220FF6C: from=<clara_dennis@example.com>, size=2015, nrcpt=1 (queue active)
Jan 18 15:16:54 host1 postfix/error[10343]: 886D5220FF6C: to=<eninuraeni@yahoo.com>, relay=none, delay=0.02, delays=0.01/0/0/0, dsn=4.4.2, status=deferred (delivery temporarily suspended: lost connection with mta5.am0.yahoodns.net[63.250.192.45] while sending RCPT TO)
Jan 18 15:16:54 host1 amavis[10624]: (10624-01) Passed CLEAN {RelayedInbound}, [127.0.0.1] <clara_dennis@example.com> -> <eninuraeni@yahoo.com>, Message-ID: <d453e7586fe9e8b43a5b460c90157425@example.com>, mail_id: 9xcboJW6xABZ, Hits: 2, size: 1328, queued_as: 886D5220FF6C, 665 ms
Jan 18 15:16:54 host1 postfix/smtp[10518]: EF6ED2267D78: to=<eninuraeni@yahoo.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=9.7, delays=0.15/8.8/0.18/0.67, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 886D5220FF6C)
Jan 18 15:16:54 host1 postfix/qmgr[2911]: EF6ED2267D78: removed

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: fresh install of iRedMail and it looks like my host is sending spams

Maybe someone's password is too weak and was cracked, and used by spammer to send spam.

Please run script "find_top_sasl_username.sh" under iRedMail-0.9.3/tools/ to find the possible account. If top 1 account sent too many emails, it might be the one.

3

Re: fresh install of iRedMail and it looks like my host is sending spams

thank you! i should have looked in tools first.  I did find the problem and it was not iRedMail related.

Thanks again

4

Re: fresh install of iRedMail and it looks like my host is sending spams

So, what's the root cause in this case? and how did you solve it?