I'm try to figure out if the email account has been compromised or not.
I found several lines like the following, from several IPs (from suspicious locations), and all have "Sender verify failed" at the end, but wait... I don't think this related to received email because a courier_login: command is also in each line:
2013-08-11 05:26:18 H=(cyericlh) [59.99.227.57]:1413 F=<[email protected]> A=courier_login
[email protected] rejected RCPT <[email protected]>: Sender verify failed
All the email addresses near the end of the log entry are different. So did they break into the email account, try to send a bunch of spam though, got all "Sender verify" failures and then give up, or???
I found several lines like the following, from several IPs (from suspicious locations), and all have "Sender verify failed" at the end, but wait... I don't think this related to received email because a courier_login: command is also in each line:
2013-08-11 05:26:18 H=(cyericlh) [59.99.227.57]:1413 F=<[email protected]> A=courier_login
All the email addresses near the end of the log entry are different. So did they break into the email account, try to send a bunch of spam though, got all "Sender verify" failures and then give up, or???