Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Mar 2004
    Location
    Montreal
    Posts
    23

    Default Exim ACL help needed

    Hey Everyone,

    Not sure if this is isolated or not but we have been receiving a deluge of forged emails bouncing off other servers. Is there some new virus out there causing this as it seems really sudden?

    Here is the scenario: The emails are bouncing back to our server and being rejected because there is no such user. This is seriously hampering our servers capacity to process email in a timely manner. Spent a better part of the day cleaning up the queue. Thank the lord for Chirpy's Configserver Mail Queues, makes the task so amazingly easy (Thanks Chirpy!). The forged emails are concentrated on a few specific domains, I'd say about 80%. I'd like to add a function in Exim that would drop emails for non-existent users in these domains. I know this goes againts SMTP protocols but if I apply it to just the implicated domains I think I will be striking a relative balance between keeping my server functional and 'mostly' compliant.

    So this is what I am thinking. I create a list of affected domains and drop anything that is not destined to an actual user. This would prevent my server from sending a return message to another non-existent user and clogging up my outgoing queue.

    So I would need something to do the following:
    a) read a list of affected domains
    b) from this list of domain drop anything that does not have a verifiable user.

    Can anyone help??

    G

  2. #2
    Member
    Join Date
    Feb 2005
    Location
    North Carolina
    Posts
    237

    Default

    Quote Originally Posted by EcoHosting View Post
    The emails are bouncing back to our server and being rejected because there is no such user. This is seriously hampering our servers capacity to process email in a timely manner. Spent a better part of the day cleaning up the queue.
    Can you verify you are using :fail: for the default email account and not some catchall account? If the user does not exist, the messages should be rejected at the SMTP stage and never hit the mail queue.

  3. #3
    Registered User
    Join Date
    May 2006
    Posts
    2

    Default

    Yes we do have :fail: setup on all accounts. There is still an SMTP message sent back but since there is no actual recipient it ends up staying in our queue. This isn't normally a problem because it is at the SMTP level but when you get about 25,000 of them in about 8 hours then it has a serious impact on the server's performance. Our server's load during peak hours is between 4 and 8 but with this recent SPAM it jumps to about 20 and stays there all day.

Similar Threads & Tags
Similar threads

  1. ACL RULE LIST (more needed!!)
    By bsasninja in forum cPanel and WHM Discussions
    Replies: 45
    Last Post: 03-25-2009, 12:41 PM
  2. Problem using this Exim ACL
    By bsasninja in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-23-2006, 07:08 AM
  3. Please check my Exim ACL 's (r they ok?)
    By SubZero in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 11-15-2005, 11:43 AM
  4. Exim ACL Queries
    By anup123 in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 10-13-2004, 04:20 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube