For about a week, I've been getting a TON of bounced SPAM that has the sender forged as a user on my server. They look like this
Interesting in this is serv3.myservername.net was my old server's name associated with the old server's IP address.. When I updated servers a year or so ago, the name change to serv4.myservername.net was not done in the WHM cp.. Although, the old serv3.myservername.net does resolve to the current server IP...
I think I have a double problem here in that the old name is probably being used by some of the users who are getting blocked due to the server IP address being put in blacklists from this barrage of bounces...
Arrgh!
HELP!
Code:
------ This is a copy of the message, including all the headers. ------
Return-path: <[email protected]>
Received: from [not.my.server.ip] (port=4193 helo=.com)
by serv3.myservername.net with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1WFTiU-0003s4-CC; Mon, 17 Feb 2014 11:18:58 -0800
Message-ID: <[email protected]>
Date: Mon, 17 Feb 2014 21:18:54 +0200
Reply-To: "myname" <[email protected]>
From: "myname" <[email protected]>
MIME-Version: 1.0
I think I have a double problem here in that the old name is probably being used by some of the users who are getting blocked due to the server IP address being put in blacklists from this barrage of bounces...
Arrgh!
HELP!