How to interpret IMAP logs

André Olivato

Registered
Jul 20, 2016
1
0
1
Florianopolis
cPanel Access Level
Root Administrator
Hello there,

I have some problems for interpret IMAP logs, an acoount was violeted and the client ask if some messas was deleted via IMAP, someone here knows how can I see thet in IMAP log log from maillog?

Jul 16 09:52:02 host dovecot: imap-login: Login: user=<user@domain>, method=PLAIN, rip=xxx.xxx.xxx.xx, lip=xxx.xxxx.xxx.xx, mpid=xxxx, TLS, session=<mpGXM8A3WrO5BYnC>

Jul 16 10:08:01 host dovecot: imap(user@domain): Disconnected: Disconnected in IDLE in=xxx, out=xxxx, bytes=xxxx/xxxxxx


Thanks in advanced.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,880
2,268
463
Hello,

You can look for instances where that user authenticated in /var/log/maillog however by default no entries for email deletion are logged. You may want to look for POP3 authentications for that email account, as downloading the emails to an email client via POP3 can also remove the messages from the server.

Thank you.