1

Topic: Spam sended to ourselfs

==== Required information ====
- iRedMail version (check /etc/iredmail-release): 0.9.2
- Linux/BSD distribution name and version: Ubuntu 14.04.2 LTS
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? Yes
- Related log if you're reporting an issue:
====

Hi, we have received two emails that appears to have been sended by our own email server.

The first one received at Jan-11-2016 at 9:44:32 PM CST

De: <ventas@disime.com.mx>
Fecha: 11 de enero de 2016, 9:44:32 PM CST
Para: ventas@disime.com.mx
Asunto: Parabens ! Aproveite a Oportunidade - [ 716319252271  ]

The second one received at Jan-11-2016 9:57:22 PM CST
De: <vguerrero@disime.com.mx>
Fecha: 11 de enero de 2016, 9:57:22 PM CST
Para: vguerrero@disime.com.mx
Asunto: Parabens ! Aproveite a Oportunidade - [ 459273155778  ]


It seems like it's spam sending from our email server to ourselfs, can you please tell me where can I check this behavior?

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Spam sended to ourselfs

The From:, To: mail headers are easy to fake.

*) please show us the FULL mail headers.
*) Please try to extract related log of these 2 emails in Postfix log file.