Results 1 to 7 of 7

Thread: Why remote user is sending 300.000 emails in 2 days?

  1. #1
    Member
    Join Date
    Oct 2010
    Posts
    9

    Default Why remote user is sending 300.000 emails in 2 days?

    I discovered at WHM >> Main >> Email >> View Sent Summary that remote user is sending over 400 Successful emails and over 300.000 Failures emails in last 2 days. I'm wonder how this could possible or how can I find the cause of this issue? Thanks !

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    10,122
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Why remote user is sending 300.000 emails in 2 days?

    In the cPanel of the domain, Default Email address, what is this set to? Not sure if this is helpful at all but worth checking.

  3. #3
    Member
    Join Date
    Oct 2010
    Posts
    9

    Default Re: Why remote user is sending 300.000 emails in 2 days?

    Quote Originally Posted by Infopro View Post
    In the cPanel of the domain, Default Email address, what is this set to? Not sure if this is helpful at all but worth checking.
    Send all unrouted email for:Current Setting: :fail: No Such User Here . This is for one of our domains hosted on this WHM...

  4. #4
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    10,122
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Why remote user is sending 300.000 emails in 2 days?

    The settings are correct there.

    Where you see -remote- on the WHM >> Main >> Email >> View Sent Summary screen, click it. The result should be helpful in giving you some idea whats going on I think.

  5. #5
    Member
    Join Date
    Oct 2010
    Posts
    9

    Default Re: Why remote user is sending 300.000 emails in 2 days?

    Quote Originally Posted by Infopro View Post
    The settings are correct there.

    Where you see -remote- on the WHM >> Main >> Email >> View Sent Summary screen, click it. The result should be helpful in giving you some idea whats going on I think.
    Yes, I see many Spam messages there... Here is an example:
    Code:
    Event: success
    User: -remote-
    Domain:
    Sender: laceymaya@urscorp.com
    Sent Time: May 17, 2012 5:16:17 PM
    Sender Host: pmfocsroiqxcd.com
    Sender IP: 58.187.216.84
    Authentication: localdelivery
    Spam Score:
    Recipient: remus.chitoi@rein.ro
    Delivered To: remus.chitoi@rein.ro
    Delivery User: reinro
    Delivery Domain: rein.ro
    Router: virtual_user
    Transport: virtual_userdelivery
    Out Time: May 17, 2012 5:16:17 PM
    ID: 1SV1VC-000vgs-3g
    Delivery Host: localhost
    Delivery IP: 127.0.0.1
    Size: 819 bytes
    Result: Message accepted
    
    or
    Delivery Event DetailsEvent: success
    User: root
    Domain:
    Sender: root@server.siteulmeu.com
    Sent Time: May 17, 2012 5:31:17 PM
    Sender Host: localhost
    Sender IP: 127.0.0.1
    Authentication: localuser
    Spam Score:
    Recipient: ghl.bestboyyy@yahoo.com
    Delivered To: ghl.bestboyyy@yahoo.com
    Delivery User: -remote-
    Delivery Domain:
    Router: lookuphost
    Transport: remote_smtp
    Out Time: May 17, 2012 5:31:17 PM
    ID: 1SV1jS-000zNu-HE
    Delivery Host: mta5.am0.yahoodns.net
    Delivery IP: 209.191.88.254
    Size: 2.62 KB
    Result: Message accepted
    How are the messages being sent exactly? There is a path where I can find a script that send those emails? or the spammer use valid SMTP credentials to send this? How to stop spam email's being sent ?

  6. #6
    Member
    Join Date
    Feb 2009
    Posts
    6

    Default Re: Why remote user is sending 300.000 emails in 2 days?

    Did anyone fine a cure or fix or know anything about this?

  7. #7
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Why remote user is sending 300.000 emails in 2 days?

    Hello,

    The first posted log shows the user was a delivery to the machine from what it appears. The second indicates it was "Authentication: localuser" so a local user authenticating.

    If you are having the same issue, please submit a ticket to us and provide some of the logs in question for us to go over the logs.

    Tickets can be submitted in WHM > Support Center > Contact cPanel or using the link in my signature. Please post the ticket number here afterward so we can track the issue for future reference purposes.

    Thanks!
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

Similar Threads

  1. over 300.000 mail messages
    By upsforum in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 08-08-2007, 05:46 AM
  2. Replies: 12
    Last Post: 07-18-2007, 08:05 PM
  3. 300,000 mailboxes
    By Estrac in forum cPanel & WHM Discussions
    Replies: 2
    Last Post: 03-03-2006, 12:19 PM
  4. Prevent the user 'nobody' from sending out mail to remote addresses
    By DWHS.net in forum cPanel & WHM Discussions
    Replies: 4
    Last Post: 08-29-2003, 11:21 AM