Koozali.org: home of the SME Server

Email outbound or Antivirus problem?

Offline jimgoode

  • *
  • 40
  • +0/-0
Email outbound or Antivirus problem?
« on: March 11, 2016, 12:48:34 AM »
Concern:  Based on email logs it appears that thousands of messages are trying to be sent out from this server.  I say trying because NO messages are actually being sent out (the SMTP outbound settings are intentionally invalid and, therefore, won’t allow outbound messages).  I think I have settings such that NO inbound messages will be rejected or sent back out on the Internet.  I have clamav running daily and clamav logs indicate I'm staying current.  Where can I find documentation that will help me track down the problem I think I have and help me stop it.  If others are having similar issues, let's work to solve it.  I provide the following in case it affects your answer.

Server – 8.2, all patches applied, serveronly, DHCP disabled

E-mail settings
•   POP3 server access: Allow private and public (secure POP3S)
•   IMAP server access: Allow private and public (secure IMAPS)
•   Webmail access: Allow HTTPS (secure)
•   Virus scanning: Enabled
•   Spam filtering: Enabled
•   Spam sensitivity: Medium
•   Custom spam tagging level: 5
•   Custom spam rejection level: 0
•   Sort spam into junkmail folder: Enabled
•   Modify subject of spam messages: Disabled
•   SPAM subject prefix: [SPAM]
•   Content to block: all available are selected
•   E-mail retrieval mode: Standard (SMTP)
•   SMTP authentication: Allow both SMTP and SSMTP
•   No ETRN or multi-drop
•   E-mail to unknown users: Send to jgoode
•   Address of internal mail server: blank
•   SMTP server: contains data but does not work at this time
Antivirus settings
•   Scan filesystems: Daily
•   Quarantine infected files: Enabled
•   ClamAV and db versions: 0.98.7/21459/Thu Mar 10 11:38:01 2016

guest22

Re: Email outbound or Antivirus problem?
« Reply #1 on: March 11, 2016, 04:55:18 AM »
I *believe* I saw the recommendation several times now on the forums to, in these cases, specifically check your clients on any form of infection.

Offline brianr

  • *
  • 989
  • +2/-0
Re: Email outbound or Antivirus problem?
« Reply #2 on: March 11, 2016, 08:56:01 AM »
Yes, this will definately be down to a compromised client PC on your network. Turn each one off  (or unplug it from the network) and see if the network activity is reduced (you could look at the lights on the switch for example to help spot this).

Brian j Read
(retired, for a second time, still got 2 installations though)
The instrument I am playing is my favourite Melodeon.
.........

Offline Stefano

  • *
  • 10,879
  • +3/-0
Re: Email outbound or Antivirus problem?
« Reply #3 on: March 11, 2016, 11:52:39 AM »
Based on email logs it appears that thousands of messages are trying to be sent out from this server.

well, you didn't share any kind of log here.. quite difficult to help you