LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 04-08-2009, 07:29 AM   #1
areamike
LQ Newbie
 
Registered: Nov 2004
Location: CornFields of Indiana
Distribution: RedHat/CentOS
Posts: 24

Rep: Reputation: 15
Postfix Logfile concerns


CentOS 5.3
I am running Postfix/Dovecot and am using my Linux server to send and receive email from my domain name. I don't use it for spam, only personal emails to friends and family and website notifications where I have used certain emails to sign up for newsletters etc.

Each night I receive a logwatch email from my server. Everything looks OK, or what I would consider normal except for the Postfix log part.

For instance.
--------------------- postfix Begin ------------------------
1641675 bytes transferred
71 messages sent
71 messages removed from queue

71 messages sent????
There is no way I sent 71 email messages in one day from my server. Is it possible my server is being used by spammers as a relay? If so, how do I determine and prevent this?

In my postfix main.cf I have
realy_host=smtp.comcast.net

Here is my postconf -n
Code:
alias_database = hash:/etc/aliases
alias_maps = hash:/etc/aliases
broken_sasl_auth_clients = yes
command_directory = /usr/sbin
config_directory = /etc/postfix
daemon_directory = /usr/libexec/postfix
debug_peer_level = 2
home_mailbox = Maildir/
html_directory = no
inet_interfaces = all
local_recipient_maps =
mail_owner = postfix
mailq_path = /usr/bin/mailq.postfix
manpage_directory = /usr/share/man
maps_rbl_domains = rbl.maps.vix.com, dul.maps.vix.com
mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
mydomain = areamike.com
myhostname = www.areamike.com
mynetworks = 127.0.0.0/8
myorigin = $mydomain
newaliases_path = /usr/bin/newaliases.postfix
queue_directory = /var/spool/postfix
relayhost = smtp.g.comcast.net
sample_directory = /usr/share/doc/postfix-2.3.3/samples readme_directory = /usr/share/doc/postfix-2.3.3/README_FILES
sendmail_path = /usr/sbin/sendmail.postfix
setgid_group = postdrop
smtpd_helo_required = yes
smtpd_helo_restrictions = permit_mynetworks, reject_invalid_hostname, permit
smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination, permit
smtpd_sasl_auth_enable = yes
smtpd_sasl_path = private/auth
smtpd_sasl_type = dovecot
unknown_local_recipient_reject_code = 550

Thanks for any insight.

mike
 
Old 04-08-2009, 11:03 AM   #2
archangel_617b
Member
 
Registered: Sep 2003
Location: GMT -08:00
Distribution: Ubuntu, RHEL/CentOS, Fedora
Posts: 234

Rep: Reputation: 42
Check your maillog (or mail.log), it will show you what messages were sent. This probably includes emails with output from crontjobs and other system utilities like that.

If you're concerned you've got an open relay, then use any of the online open relay tests.

- Arch
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Postfix: postfix: fatal: chdir(/usr/libexec/postfix) Micro420 Ubuntu 2 07-13-2008 12:21 PM
Shell scripting: Print output to logfile, error to logfile & screen stefanlasiewski Programming 18 05-22-2008 12:47 PM
Get IP from logfile Manana Linux - Software 1 03-20-2007 06:56 AM
logfile analyse saavik Linux - Networking 4 03-30-2005 05:14 AM
concerns davidpurple Linux - Newbie 9 10-12-2001 09:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration