LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 02-03-2014, 03:44 PM   #1
justinwyllie
LQ Newbie
 
Registered: Feb 2014
Posts: 11

Rep: Reputation: Disabled
Where are incoming mails logged?


I am really a beginner with Linux.

I have located /var/log/maillog

As I understand it this shows mail being sent through this server? For example if I authenticate as a valid user on the system and send an email I will see a log entry here?

If I send an email from say my hotmail account to a domain which is handled by this server it gets put into the mailbox for that account (according to my settings in /etc/mail/virtusertable) will it be logged in /var/log/maillog? I suppose I don't know if sendmail (this system is I think running sendmail) handles receiving emails as well.

Many thanks
 
Old 02-03-2014, 03:53 PM   #2
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Any mail message passing through the mail service on the system will be logged.

There is no difference between a local user sending mail (if it is using the local service for delivery) or a remote connection making a connection for delivery. All messages get logged.

The only time a message ISN'T logged will be when the user client makes a connection to a remote mail service for delivery, or for retrieving mail. Since the local service isn't being contacted, there can be no messages logged.
 
1 members found this post helpful.
Old 02-03-2014, 03:59 PM   #3
justinwyllie
LQ Newbie
 
Registered: Feb 2014
Posts: 11

Original Poster
Rep: Reputation: Disabled
Ok. Thanks. I can see them coming in.

The problem is that my client's server is sending out hundreds of emails an hour. It is set up for SMTP auth. I think the most likely candidate is a virus on his office Windows machine which is using his Outlook accounts to send the mails.

Another candidate is that someone has got hold of his password and is sending them from elsewhere. Looking at the maillog I think I can see what looks like the IP address of where the user came from : if this is his machine that will answer that one.

However; having changed the passwords for these users I am still seeing dozens of emails going through sendmail. Since they say to=<someaddress rather than from=< I assume they are outward bound? EDIT: yes. Clearing /var/spool/mqueue seems to have dealt with this.


Thanks

-- Justin Wyllie

Last edited by justinwyllie; 02-03-2014 at 04:31 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Incoming mails + remote backup minim Linux - General 3 04-06-2010 04:16 AM
incoming mails only from particular server senthilvael Linux - Server 0 11-21-2007 01:40 PM
How to get incoming e-mails to go to IMAP inbox? capitalista Linux - Networking 1 12-11-2005 09:50 PM
Incoming mails not working bobcatch Linux - Networking 0 02-24-2005 10:03 AM
No incoming mails gubak Linux - Networking 1 12-06-2004 02:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 02:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration