LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 12-28-2005, 02:00 AM   #1
sulee
LQ Newbie
 
Registered: Jul 2005
Location: Bangkok
Distribution: Slackware
Posts: 20

Rep: Reputation: 0
too much mail - too many useless mails


Goodday all,

I'm using postfix / mysql / courier-imap on a slackware 10.1.

I host about 6 virtual domains. Regarding email traffic, 4 of them are very quiet and 2 are extremly busy.

Shocking is the amount of email coming in.

There are 1 to 2 entries in the maillog per second (in peak times it's 5 - 8 per second).

The maillog grows to 12 - 14 MB per day. I rotate daily.

An average entry looks something like this:
Dec 28 06:49:46 fortuner postfix/smtpd[8037]: NOQUEUE: reject: RCPT from c-67-173-226-141.hsd1.co.comcast.net[67.173.226.141]: 554 Spam sorted out with RBL!; from=<nytmeg@coahuila.com> to=<732.naka777@MYDOMAIN.com> proto=SMTP helo=<Dell.hsd1.co.comcast.net.>

IS THIS NORMAL? Are other maillogs with 5 - 20 domains hosted similar huge?

It would be nice to hear about your experience in this field and ideas to cope with it. Thanks in Advance....
 
Old 12-28-2005, 06:22 AM   #2
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 271Reputation: 271Reputation: 271
Are these valid emails for users? Some users get more mail than others. They sign up for more things on the internet which also then targeted for spam. If these are not valid emails, you should look into spamassassin or the like and turn your logging level down a notch or two if you don't like huge logs due to heavy traffic.
 
Old 12-28-2005, 07:42 AM   #3
sulee
LQ Newbie
 
Registered: Jul 2005
Location: Bangkok
Distribution: Slackware
Posts: 20

Original Poster
Rep: Reputation: 0
Hi trickykid,

tx for replying.

The 2 "heavy" users are my own 2 websites, online for years and used a lot (also email addresses).

I'm working on implementing spamassassin - and I installed the greylisting package GLD just a couple of days back. Formerly I had the 2 sites on 2 different servers, so it wasn't so obvious

However, what's bothering me most are these multi mail sendings, looks like they try to track their mails, because these "732.naka777@MYDOMAIN.com", "732.nida777@MYDOMAIN.com", etc. recipients always come as a pile (10 - 20 in a row), mostly changing sender addresses wihin.

I will definitely install Spamassassin, but am thinking of a maybe more "mechanical" way of rejecting this type of easily trackable spams (which might already make up to 20 - 30% of the total spam).

So, the questions are:

1. How to do that? ... It should be possible to filter them out in an early stage with regexp (prce) to reduce the load of the follow-up filters (the advantage is, that it's my own sites, so I can decide - even though there are more sites hosted on the server).

2. What does your's(ituation) look like? ... I'm just curious about other people's experience, to have a comparison - since watching these piles of junk coming into the server (not my box) is irritating.

and 3. how do I reduce the logging level in Postfix? (haven't found a way)

It's a new field for me. I'm reading a lot - but missing out experience.

Thanks, and enjoy your day!

Last edited by sulee; 12-28-2005 at 12:42 PM.
 
Old 12-29-2005, 11:06 AM   #4
sulee
LQ Newbie
 
Registered: Jul 2005
Location: Bangkok
Distribution: Slackware
Posts: 20

Original Poster
Rep: Reputation: 0
Hi Again,
Here's an answer to Q1:

smtpd_recipient_restrictions =
check_recipient_access
pcre:/etc/postfix/checks/own_domains,

as long as there isn't

permit_mynetworks,
permit_sasl_authenticated,

placed before it ... since that gives a free pass to all *@mydomain.com

/etc/postfix/checks/own_domains ::
/^([0-9]{2,3})([\._,-]?)([0-9A-Z._-]*)[@](mydomain\.com)/ REJECT Go away!

That works!

Question 2 & 3 are still open...
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Setting up a mail server to scan mails nightfall_sg Linux - Software 1 10-20-2005 01:11 AM
sending old e-mails into new mail server inbox mush Linux - Newbie 2 10-02-2005 08:58 PM
e-mail client that prints e-mails instantly dorum2003 Linux - Software 3 07-15-2005 12:06 PM
mail server: just send mails out, but not receive hamish Linux - Software 4 02-27-2005 11:06 AM
Mail Server not accepting mails!! RKris Linux - Networking 5 08-27-2002 06:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 10:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration