SME server 7.6 updates installed.
getting failure of email notices with myriads of addresses that the q-mail is trying to send to but being rejected. Ive stopped the qmail service which has stopped the error messages.
here is a sample of the message with myriads of addresses that is being rejected.
Hi. This is the qmail-send program at ber.local.
I tried to deliver a bounce message to this address, but the bounce bounced!
<fahad.alsaeed198@gmail.com>:
173.194.79.26 failed after I sent the message.
Remote host said: 550-5.7.1 [119.224.106.1 12] Our system has detected that this message is
550-5.7.1 likely unsolicited mail. To reduce the amount of spam sent to Gmail,
550-5.7.1 this message has been blocked. Please visit
550-5.7.1 http://support.google.com/mail/bin/answer.py?hl=en&answer=188131 for
550 5.7.1 more information. so1si4664466pab.90 - gsmtp
--- Below this line is the original bounce.
Return-Path: <>
Received: (qmail 7451 invoked for bounce); 16 Jul 2013 21:38:00 -0000
Date: 16 Jul 2013 21:38:00 -0000
From: MAILER-DAEMON@ber.local
To: fahad.alsaeed198@gmail.com
Subject: failure notice
Hi. This is the qmail-send program at ber.local.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.I've shutdown all the internal PC's and scanned to spam- all clean. Shut down all PC's- restarted qmail and the errors began to pour in again.
I suspect the server has been hacked??
here is the qmail log
2013-07-17 23:56:38.415934500 starting delivery 10405: msg 5424493 to remote menno2000@ayna.com
2013-07-17 23:56:38.415935500 status: local 0/10 remote 20/20
2013-07-17 23:56:38.417339500 delivery 10404: deferral: Sorry,_I_wasn't_able_to_establish_an_SMTP_connection._(#4.4.1)/
2013-07-17 23:56:38.417341500 status: local 0/10 remote 19/20
2013-07-17 23:56:38.417342500 starting delivery 10406: msg 5424493 to remote meno2000@ayna.com
2013-07-17 23:56:38.417344500 status: local 0/10 remote 20/20
2013-07-17 23:56:38.452580500 delivery 10405: deferral: Sorry,_I_wasn't_able_to_establish_an_SMTP_connection._(#4.4.1)/
2013-07-17 23:56:38.452582500 status: local 0/10 remote 19/20
2013-07-17 23:56:38.452583500 starting delivery 10407: msg 5424493 to remote meno_ya_layaly@hotmail.com
2013-07-17 23:56:38.452584500 status: local 0/10 remote 20/20
2013-07-17 23:56:38.454607500 delivery 10406: deferral: Sorry,_I_wasn't_able_to_establish_an_SMTP_connection._(#4.4.1)/
2013-07-17 23:56:38.454609500 status: local 0/10 remote 19/20
2013-07-17 23:56:38.454610500 starting delivery 10408: msg 5424493 to remote menome@yahoo.com
2013-07-17 23:56:38.454611500 status: local 0/10 remote 20/20
2013-07-17 23:56:38.976165500 delivery 10401: success: 65.54.188.94_accepted_message./Remote_host_said:_250__<20130712024632.19992vn7dgsb3ha8@119.224.106.1>_Queued_mail_for_delivery/
2013-07-17 23:56:38.976167500 status: local 0/10 remote 19/20
2013-07-17 23:56:38.976168500 starting delivery 10409: msg 5424493 to remote mensaf@37.com
2013-07-17 23:56:38.976169500 status: local 0/10 remote 20/20
2013-07-17 23:56:39.261931500 delivery 10403: failure: 65.55.92.136_does_not_like_recipient./Remote_host_said:_550_Requested_action_not_taken:_mailbox_unavailable/Giving_up_on_65.55.92.136./
2013-07-17 23:56:39.261933500 status: local 0/10 remote 19/20
2013-07-17 23:56:39.261934500 starting delivery 10410: msg 5424493 to remote Mensur.Tahirovic@tr.ey.com
2013-07-17 23:56:39.261935500 status: local 0/10 remote 20/20
2013-07-17 23:56:39.471366500 delivery 10402: success: 65.54.188.94_accepted_message./Remote_host_said:_250__<20130712024632.19992vn7dgsb3ha8@119.224.106.1>_Queued_mail_for_delivery/
2013-07-17 23:56:39.471368500 status: local 0/10 remote 19/20
2013-07-17 23:56:39.471369500 starting delivery 10411: msg 5424493 to remote ment@ayna.com
2013-07-17 23:56:39.471371500 status: local 0/10 remote 20/20/var/log/qpsmtpd/current
2013-07-17 20:09:44.309564500 23766 Plugin tls, hook mail returned DECLINED,
2013-07-17 20:09:44.309604500 23766 running plugin (mail): require_resolvable_fromhost
2013-07-17 20:09:44.309678500 23766 trying to get config for invalid_resolvable_fromhost
2013-07-17 20:09:44.324664500 23766 trying to get config for require_resolvable_fromhost
2013-07-17 20:09:44.326035500 23766 Plugin require_resolvable_fromhost, hook mail returned DECLINED,
2013-07-17 20:09:44.326080500 23766 running plugin (mail): check_badmailfrom
2013-07-17 20:09:44.326152500 23766 trying to get config for badmailfrom
2013-07-17 20:09:44.338554500 23766 Plugin check_badmailfrom, hook mail returned DECLINED,
2013-07-17 20:09:44.338668500 23766 getting mail from <clubwarebackup@asfc.co.nz>
2013-07-17 20:09:44.338739500 23766 250 <clubwarebackup@asfc.co.nz>, sender OK - how exciting to get mail from you!
2013-07-17 20:09:44.375412500 23766 dispatching RCPT TO:<john@ber.net.nz>
2013-07-17 20:09:44.375414500 23766 to email address : [<john@ber.net.nz>]
2013-07-17 20:09:44.375415500 23766 running plugin (rcpt): tls
2013-07-17 20:09:44.375417500 23766 Plugin tls, hook rcpt returned DECLINED,
2013-07-17 20:09:44.375418500 23766 running plugin (rcpt): check_badmailfrom
2013-07-17 20:09:44.375419500 23766 Plugin check_badmailfrom, hook rcpt returned DECLINED,
2013-07-17 20:09:44.375420500 23766 running plugin (rcpt): check_badrcptto_patterns
2013-07-17 20:09:44.375431500 23766 trying to get config for badrcptto_patterns
2013-07-17 20:09:44.376745500 23766 Plugin check_badrcptto_patterns, hook rcpt returned DECLINED,
2013-07-17 20:09:44.376787500 23766 running plugin (rcpt): check_badrcptto
2013-07-17 20:09:44.376851500 23766 trying to get config for badrcptto
2013-07-17 20:09:44.391750500 23766 Plugin check_badrcptto, hook rcpt returned DECLINED,
2013-07-17 20:09:44.391794500 23766 running plugin (rcpt): check_goodrcptto
2013-07-17 20:09:44.391879500 23766 check_goodrcptto plugin (rcpt): stripping '-' extensions
2013-07-17 20:09:44.391922500 23766 trying to get config for goodrcptto
2013-07-17 20:09:44.558480500 23766 check_goodrcptto plugin (rcpt): address includes extn '-', checking users: john
2013-07-17 20:09:44.572745500 23766 Plugin check_goodrcptto, hook rcpt returned DECLINED,
2013-07-17 20:09:44.572806500 23766 running plugin (rcpt): rcpt_ok
2013-07-17 20:09:44.572890500 23766 trying to get config for rcpthosts
2013-07-17 20:09:44.591180500 23766 Plugin rcpt_ok, hook rcpt returned OK,
2013-07-17 20:09:44.591321500 23766 250 <john@ber.net.nz>, recipient ok
2013-07-17 20:09:44.627796500 23766 dispatching DATA
2013-07-17 20:09:44.627908500 23766 running plugin (data): tls
2013-07-17 20:09:44.627998500 23766 Plugin tls, hook data returned DECLINED,
2013-07-17 20:09:44.628037500 23766 running plugin (data): check_earlytalker
2013-07-17 20:09:44.628155500 23766 Plugin check_earlytalker, hook data returned DECLINED,
2013-07-17 20:09:44.628305500 23766 354 go ahead
2013-07-17 20:09:44.628381500 23766 trying to get config for databytes
2013-07-17 20:09:44.646044500 23766 max_size: 50000000 / size: 0
2013-07-17 20:09:44.646205500 23766 trying to get config for timeout
2013-07-17 20:09:44.675130500 23766 spooling message to disk
2013-07-17 20:09:44.757011500 23766 max_size: 50000000 / size: 1270
2013-07-17 20:09:44.757013500 23766 running plugin (data_post): check_basicheaders
2013-07-17 20:09:44.757014500 23766 Plugin check_basicheaders, hook data_post returned DECLINED,
2013-07-17 20:09:44.757016500 23766 running plugin (data_post): virus::pattern_filter
2013-07-17 20:09:44.757017500 23766 trying to get config for pattern_filter
2013-07-17 20:09:44.757018500 23766 trying to get config for signatures_patterns
2013-07-17 20:09:44.757019500 23766 Plugin virus::pattern_filter, hook data_post returned DECLINED,
2013-07-17 20:09:44.757031500 23766 running plugin (data_post): tnef2mime
2013-07-17 20:09:44.780146500 23766 Plugin tnef2mime, hook data_post returned DECLINED,
2013-07-17 20:09:44.780196500 23766 running plugin (data_post): spamassassin
2013-07-17 20:09:44.780280500 23766 spamassassin plugin (data_post): check_spam
2013-07-17 20:09:44.780749500 23766 spamassassin plugin (data_post): check_spam: connected to spamd
2013-07-17 20:09:44.781588500 23766 spamassassin plugin (data_post): check_spam: finished sending to spamd
2013-07-17 20:09:48.467078500 23766 spamassassin plugin (data_post): check_spam: spamd: SPAMD/1.1 0 EX_OK
2013-07-17 20:09:48.467080500 23766 spamassassin plugin (data_post): check_spam: spamd: Content-length: 42
2013-07-17 20:09:48.467082500 23766 spamassassin plugin (data_post): check_spam: spamd: Spam: False ; 3.1 / 5.0
2013-07-17 20:09:48.467083500 23766 spamassassin plugin (data_post): check_spam: spamd:
2013-07-17 20:09:48.467084500 23766 spamassassin plugin (data_post): check_spam: finished reading from spamd
2013-07-17 20:09:48.467085500 23766 spamassassin plugin (data_post): check_spam: No, hits=3.1, required=5.0, tests=MISSING_MID,RCVD_IN_BRBL_LASTEXT,RDNS_NONE
2013-07-17 20:09:48.467110500 23766 Plugin spamassassin, hook data_post returned DECLINED,
2013-07-17 20:09:48.467111500 23766 running plugin (data_post): spamassassin
2013-07-17 20:09:48.474081500 23766 Plugin spamassassin, hook data_post returned DECLINED,
2013-07-17 20:09:48.474083500 23766 running plugin (data_post): virus::clamav
2013-07-17 20:09:48.474084500 23766 virus::clamav plugin (data_post): Changing permissions on file to permit scanner access
2013-07-17 20:09:48.474086500 23766 virus::clamav plugin (data_post): Running: /usr/bin/clamdscan --stdout --config-file=/etc/clamd.conf --no-summary /var/spool/qpsmtpd/1374048584:23766:0 2>&1
2013-07-17 20:09:48.541338500 23766 virus::clamav plugin (data_post): clamscan results: /var/spool/qpsmtpd/1374048584:23766:0: OK
2013-07-17 20:09:48.541340500 23766 Plugin virus::clamav, hook data_post returned DECLINED,
2013-07-17 20:09:48.541341500 23766 running plugin (queue): logging::logterse
2013-07-17 20:09:48.541343500 23766 logging::logterse plugin (queue): ` 219.88.131.228 Unknown asfc.local <clubwarebackup@asfc.co.nz> <john@ber.net.nz> queued <> No, hits=3.1 required=5.0_
2013-07-17 20:09:48.541344500 23766 Plugin logging::logterse, hook queue returned DECLINED,
2013-07-17 20:09:48.541361500 23766 running plugin (queue): queue::qmail_2dqueue
2013-07-17 20:09:48.541362500 23776 queue::qmail_2dqueue plugin (queue): (for 23766 ) Queuing qp 23776 to
/var/qmail/bin/qmail-queue
2013-07-17 20:09:48.899772500 23766 Plugin queue::qmail_2dqueue, hook queue returned OK, Queued! 1374048588 qp 23776 <>
2013-07-17 20:09:48.899774500 23766 250 Queued! 1374048588 qp 23776 <>
2013-07-17 20:09:48.949051500 23766 dispatching QUITI am at a loss how to fix this...What is the best way to resolve it?