LinuxQuestions.org
Support LQ: Use code LQ3 and save $3 on Domain Registration
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices



Reply
 
Search this Thread
Old 02-10-2007, 11:37 AM   #1
mrtwice
Member
 
Registered: Feb 2002
Distribution: xubuntu 8.10
Posts: 225

Rep: Reputation: 31
[resolved] Question about Postfix Log Entry


I have a web server running Postfix for my mail server. I am the only user setup with mail accounts on the box, but I do have a bunch of aliases, a few of which go to other people. I use Thunderbird as a mail client and I have it setup to send my email through Gmail's SMTP servers (I have a gmail account) instead of connecting to my own box.

I also have Logwatch setup to email me a report every day. I am currently seeing records like this:

Code:
3134C641B9: host SMTP1.lerelaisinternet.com[194.206.126.201] said: 
450 <vnlawi@horspistes.fr>: Recipient address rejected: Greylisted 
for 5 minutes (in reply to RCPT TO command)
Now, this doesn't make sense to me. Why would my machine be trying to send email to vnlawi@horspistes.fr? I am not sending anything to that address.

I guess I don't understand the log entries. I am trying to make sure that my machine is not compromised.

Thanks.

Last edited by mrtwice; 02-11-2007 at 03:02 PM.
 
Old 02-11-2007, 04:45 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,415

Rep: Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968Reputation: 1968
looks like you're being used, or trying to be used, as an open relay. check what http://www.abuse.net/relay.html says about your relaying status. I'm not too familiar with the errors there but it looks like postfix has correctly blocked the relaying anyway.
 
Old 02-11-2007, 08:34 AM   #3
mrtwice
Member
 
Registered: Feb 2002
Distribution: xubuntu 8.10
Posts: 225

Original Poster
Rep: Reputation: 31
Chris,

Thanks for the response. I have used the tools at dnsstuff.com to check for being an open relay and that check has came out clean. You said that "it looks like postfix has correctly blocked the relaying anwyay." I guess that is what I don't really understand. I have seen relaying denied log entries, they look like this:

Code:
Relaying denied:
   From 61-216-81-33.dynamic.hinet.net[61.216.81.33] to candy59839@yahoo.com.tw : 3 Time(s)
The log entry in question seems to indicate that Postfix is actually trying to deliver the email. It has looked up the MX record for horspistes.fr and is trying to deliver the message. Their mail server, SMTP1.lerelaisinternet.com, then responded to my postfix server with the 450 message. Why would my postfix server be trying to deliver the message? Shouldn't it see that vnlawi@horspistes.fr is not a valid email address on my local machine, is not in the relaying allowed domains, and issue a relaying denied message?

Thanks.
 
Old 02-11-2007, 12:41 PM   #4
Berhanie
Senior Member
 
Registered: Dec 2003
Location: phnom penh
Distribution: Fedora
Posts: 1,625

Rep: Reputation: 165Reputation: 165
Look in the logs to see what submitted the message. It might be a cron job (from a previous admin), an alias, etc.
 
Old 02-11-2007, 01:09 PM   #5
mrtwice
Member
 
Registered: Feb 2002
Distribution: xubuntu 8.10
Posts: 225

Original Poster
Rep: Reputation: 31
Ok, I greped the logs for that email address and here is what I found:

Code:
[root@myhost log]# grep "horspistes.fr" *
maillog.1:Feb  9 07:30:05 myhost postfix/smtp[24865]: 3134C641B9: host SMTP1.lerelaisinternet.com[194.206.126.201] said: 450 <vnlawi@horspistes.fr>: Recipient address rejected: Greylisted for 5 minutes (in reply to RCPT TO command)
maillog.1:Feb  9 07:30:07 myhost postfix/smtp[24865]: 3134C641B9: to=<vnlawi@horspistes.fr>, relay=SMTP2.lerelaisinternet.com[194.206.126.203], delay=3, status=deferred (host SMTP2.lerelaisinternet.com[194.206.126.203] said: 450 <vnlawi@horspistes.fr>: Recipient address rejected: Greylisted for 5 minutes (in reply to RCPT TO command))
maillog.1:Feb  9 07:54:45 myhost postfix/smtp[24962]: 3134C641B9: to=<vnlawi@horspistes.fr>, relay=SMTP1.lerelaisinternet.com[194.206.126.201], delay=1481, status=sent (250 Ok: queued as 5AE0134004)
It looks to me like that email actually got delivered? I really don't understand these log entries. Thank you for your help.
 
Old 02-11-2007, 02:18 PM   #6
Berhanie
Senior Member
 
Registered: Dec 2003
Location: phnom penh
Distribution: Fedora
Posts: 1,625

Rep: Reputation: 165Reputation: 165
Yes, that email was eventually delivered. Now, you have to check the logs to see how that email was submitted in the first place.
grep for the queue id (3134C641B9).

Last edited by Berhanie; 02-11-2007 at 02:19 PM.
 
Old 02-11-2007, 03:01 PM   #7
mrtwice
Member
 
Registered: Feb 2002
Distribution: xubuntu 8.10
Posts: 225

Original Poster
Rep: Reputation: 31
Thank you Berhanie for the suggestion to use the queue id. That was the missing peace of the puzzle for me.

I traced this to a form on one of my websites that allows people to sign up to be on a mailing list and then sends them a confirmation email. Apparently, there are bots out there submitting the form with junk information and that is why I am seeing these records. I will have to implement some kind of form submission protection.

Many thanks!
 
Old 02-11-2007, 03:59 PM   #8
Berhanie
Senior Member
 
Registered: Dec 2003
Location: phnom penh
Distribution: Fedora
Posts: 1,625

Rep: Reputation: 165Reputation: 165
You're welcome.
 
  


Reply

Tags
logs, postfix, spam


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Postfix Error in log file shawnbishop Linux - Software 1 02-28-2007 10:00 AM
postfix log gabsik Linux - Networking 2 05-06-2006 07:19 AM
Postfix log file paddyjoy Linux - Newbie 2 12-29-2005 08:34 AM
Problem with log filles postfix dawidson Linux - Newbie 3 11-03-2005 07:12 PM
Significance of Occasional Blue Question Mark on Tux J.W. LQ Suggestions & Feedback 2 10-23-2003 08:26 PM


All times are GMT -5. The time now is 11:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration