Henrik B A
2016-11-25 09:02:22 UTC
It seems that mail from unknown recipients/senders are being sent through my postfix server. I see a lot of entries like this, with different shady addresses:
Nov 24 15:32:35 XXXXX postfix/smtpd[12363]: 34108BA48C6: client=localhost[127.0.0.1]
Nov 24 15:32:35 XXXXX postsrsd[13736]: srs_forward: <***@fortalezatours.com> rewritten as <SRS0+FZUn=XJ=fortalezatours.com=***@YYYYY.ZZ>
Nov 24 15:32:35 XXXXX postfix/cleanup[13735]: 34108BA48C6: message-id=<***@fortalezatours.com>
Nov 24 15:32:35 XXXXX postfix/qmgr[12188]: 34108BA48C6: from=<SRS0+FZUn=XJ=fortalezatours.com=***@YYYYY.ZZ>, size=1196, nrcpt=1 (queue active)
Nov 24 15:32:35 XXXXX amavis[13918]: (13918-01) Passed CLEAN {RelayedOpenRelay}, [222.92.30.22]:49947 [222.92.30.22] <***@fortalezatours.com> -> <***@ukr.net>, Queue-ID: 8F805BA48C7, Message-ID: <***@fortalezatours.com>, mail_id: qF8LOG1vGb3f, Hits: 2.58, size: 768, queued_as: 34108BA48C6, 2235 ms
Nov 24 15:32:35 XXXXX postfix/smtp[13887]: 8F805BA48C7: to=<***@ukr.net>, relay=127.0.0.1[127.0.0.1]:10024, delay=5.3, delays=2.4/0/0.84/2.1, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 34108BA48C6)
Nov 24 15:32:35 XXXXX postfix/smtp[13676]: 34108BA48C6: to=<***@ukr.net>, relay=mxs.ukr.net[212.42.77.251]:25, delay=0.25, delays=0.17/0/0.04/0.04, dsn=2.0.0, status=sent (250 OK id=1c9v4l-000JFT-EP)
Nov 24 15:32:35 XXXXX postfix/qmgr[12188]: 34108BA48C6: removed
(My server name and domain is replaced with XXXXX and YYYYY.ZZ)
I don't have an open relay (relayhost= is set in main.cf), and I have a proper SPF record ("v=spf1 a mx ?all"). What more do I need to do?
Cheers,
Henrik
Nov 24 15:32:35 XXXXX postfix/smtpd[12363]: 34108BA48C6: client=localhost[127.0.0.1]
Nov 24 15:32:35 XXXXX postsrsd[13736]: srs_forward: <***@fortalezatours.com> rewritten as <SRS0+FZUn=XJ=fortalezatours.com=***@YYYYY.ZZ>
Nov 24 15:32:35 XXXXX postfix/cleanup[13735]: 34108BA48C6: message-id=<***@fortalezatours.com>
Nov 24 15:32:35 XXXXX postfix/qmgr[12188]: 34108BA48C6: from=<SRS0+FZUn=XJ=fortalezatours.com=***@YYYYY.ZZ>, size=1196, nrcpt=1 (queue active)
Nov 24 15:32:35 XXXXX amavis[13918]: (13918-01) Passed CLEAN {RelayedOpenRelay}, [222.92.30.22]:49947 [222.92.30.22] <***@fortalezatours.com> -> <***@ukr.net>, Queue-ID: 8F805BA48C7, Message-ID: <***@fortalezatours.com>, mail_id: qF8LOG1vGb3f, Hits: 2.58, size: 768, queued_as: 34108BA48C6, 2235 ms
Nov 24 15:32:35 XXXXX postfix/smtp[13887]: 8F805BA48C7: to=<***@ukr.net>, relay=127.0.0.1[127.0.0.1]:10024, delay=5.3, delays=2.4/0/0.84/2.1, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 34108BA48C6)
Nov 24 15:32:35 XXXXX postfix/smtp[13676]: 34108BA48C6: to=<***@ukr.net>, relay=mxs.ukr.net[212.42.77.251]:25, delay=0.25, delays=0.17/0/0.04/0.04, dsn=2.0.0, status=sent (250 OK id=1c9v4l-000JFT-EP)
Nov 24 15:32:35 XXXXX postfix/qmgr[12188]: 34108BA48C6: removed
(My server name and domain is replaced with XXXXX and YYYYY.ZZ)
I don't have an open relay (relayhost= is set in main.cf), and I have a proper SPF record ("v=spf1 a mx ?all"). What more do I need to do?
Cheers,
Henrik