LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Networking (https://www.linuxquestions.org/questions/linux-networking-3/)
-   -   How can I tell if my sendmail is an open relay.. (https://www.linuxquestions.org/questions/linux-networking-3/how-can-i-tell-if-my-sendmail-is-an-open-relay-186831/)

Bjorkli 05-28-2004 03:11 AM

How can I tell if my sendmail is an open relay..
 
I thought my sendmail server where secure for open relay until I read about spoofing (hijacking of my domain name). Now I am paranoid again.

What log do I have to see and what do I have to look for to make sure that my sendmail server is not an open relay (did so many different things in webmin to make it work, so I am afraid that I have turned on something I shouldn't have or something.)

I check sendmail.log in /var/log and saw entries like this:

Quote:

May 26 17:53:38 linux sendmail[29491]: i4QFraD3029491: ruleset=check_rcpt, arg1=
<infobank7655@hanmail.net>, relay=[221.159.85.226], reject=550 5.7.1 <infobank76
55@hanmail.net>... Relaying denied. IP name lookup failed [221.159.85.226]

May 28 05:33:41 linux sendmail[6734]: i4S3XeD3006734: ruleset=check_rcpt, arg1=<
nmyone19@hanmail.net>, relay=[220.116.205.141], reject=550 5.7.1 <nmyone19@hanma
il.net>... Relaying denied. IP name lookup failed [220.116.205.141]

May 28 05:33:41 linux sendmail[6734]: i4S3XeD3006734: from=<mail@yourdomain.com>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=Daemon0, relay=[220.116.205.141]
Guess the two top ones has been denied, but the bottom one looked like it went to 220.116.205.141

My webmin settings are as follows:

Local domains: Mydomain
Relay domains: Mydomain and subdomains

The rest would be standard I think...


And how quick are the relay guys anyway. From the log I see that they tried to relay allready before I knew my mail server where working. And it only took 30 minutes before my first junkmail arrived...

ppuru 05-28-2004 03:35 AM

http://www.abuse.net/relay.html
http://www.ordb.org/submit/
http://www.mob.net/~ted/tools/relaytester.php3


All times are GMT -5. The time now is 08:52 PM.