Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Oct 2003
    Location
    Romania
    Posts
    25

    Default Reading exim_mainlog

    Hello,

    I have a problem with a hosting account possibly sending spam and upon investigating this was found in exim_mainlog:

    2009-08-28 03:02:13 1Mgpr3-0005ir-Pd <= (user)@(host) U=(user) P=local S=1308
    2009-08-28 03:02:14 1Mgpr3-0005ir-Pd ** (recipient)@yahoo.com R=lookuphost T=remote_smtp: SMTP error from remote mail server after end of data: host c.mx.mail.yahoo.com [216.39.53.3]: 554 delivery error: dd This user doesn't have a yahoo.com account (user)@yahoo.com [-5] - mta454.mail.re4.yahoo.com
    2009-08-28 03:02:15 1Mgpr4-0005jb-FJ <= <> R=1Mgpr3-0005ir-Pd U=mailnull P=local S=2329

    Where did this mail come from? PHP script or direct SMTP connection from an infected PC or what?

    Is there a guide for all the notations from exim_mainlog?

    Thanks!!

  2. #2
    Member
    Join Date
    Nov 2008
    Posts
    167

    Default

    Hi Andy, I can't help, but I too have been looking for a while for a friendly guide to exim_mainlog and what all of the shorthand letters mean. Like many things unix/linux the answers are usually found buried and obfuscated in long texts written by people who just love to write more than is necessary.

    My take on Msg 1Mgpr3-0005ir-Pd is that one of your users tried to email a yahoo.com account that didn't exist.

    <= means message incoming to server (in the case from a local user)
    T=remote_smtp: = Transport method

    I'm still not sure what the P= and S= are!

  3. #3
    Member
    Join Date
    Oct 2003
    Location
    Romania
    Posts
    25

    Default

    Hello,

    Yes...I know that this particular Yahoo recipient doesn't exist but this message was extracted from a much larger bulk of 1000s of mails sent from my shared server and I was trying to understand if the mail comes from an abused script or an abused user account etc...

    Thanks Santrix!

Similar Threads & Tags
Similar threads

  1. EXIM_MAINLOG viewer ?
    By Inetwork in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 03-05-2008, 06:10 AM
  2. exim_mainlog - how often rotate?
    By SupermanInNY in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-07-2006, 02:28 PM
  3. error in exim_mainlog
    By esarakaitis in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-02-2004, 03:30 PM
  4. exim_mainlog
    By dflame in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-25-2003, 02:14 PM
  5. exim_mainlog
    By Ben in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-01-2003, 10:48 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube