I inherited a server some months ago and found that some of the accounts were seemed to be sending out spam mail. At the time there were records like this in exim_mainlog
2017-06-28 23:02:42 1dQPj7-0005Mm-JP <=
[email protected] H=([127.0.0.1]) [78.90.72.196]:41899
P=esmtpa A=dovecot_plain:[email protected]_of_my_site.com S=15548
[email protected]_of_my_sites.com T="Hand regard:
following the hand with the eyes!" for [email protected]
I deleted the email account in question and all email accounts for that website.
Also at that time I found that the directory for /var/spool/exim was filling up by several GB in the space of hours and the servers disk was becoming full because of it. I cant recall what I did exactly but I think I may have deleted or removed something that I followed in a guide and the disk usage stopped anyway.
Since then though mail doesnt seem to work on the server at all and I need to fix it now. It seems that no messages sent to any of the email addresses for the accounts are received and no mails from cron jobs and other tools are received by the root email and test emails are never received too.
Exim is still running though, here is some sample output from /exim_mainlog
2017-10-13 05:28:34 SMTP connection from [51.254.125.108]:46176 (TCP/IP connection count = 2)
2017-10-13 05:28:36 dovecot_login authenticator failed for 108.ip-51-254-125.eu (ADMIN) [51.254.125.108]:46176: 535 Incorrect authentication data ([email protected]_site.com)
2017-10-13 05:28:36 SMTP connection from [127.0.0.1]:59006 (TCP/IP connection count = 3)
2017-10-13 05:28:36 SMTP connection from 108.ip-51-254-125.eu (ADMIN) [51.254.125.108]:46176 closed by QUIT
2017-10-13 05:28:55 1e2T9p-0002wB-Jh Sender identification U=another_site D=another_site.net [email protected]_site.net
2017-10-13 05:28:55 1e2uKp-0001KM-Kt Sender identification U=another_site D=another_site.net [email protected]_site.net
2017-10-13 05:28:55 1e2pHa-0004vO-Vz Message is frozen
2017-10-13 05:28:56 1e2vqV-0002Ey-GI Message is frozen
2017-10-13 05:28:56 1e2uxV-0003Vm-47 Message is frozen
a few other details:
In the WHM sent summary there is no activity and same for the mail delivery reports.
Mail queue manager seems to have a lot of activity in it, all messages there are either frozen or queued and seem to be from [System] and trying to go to either root, cpanel or [email protected], there are also some mails trying to send from one of our sites to other email addresses I dont recognise (I would guess they are wither users signed up to the site or people that have left a comment).
Im not sure how to tackle this, should I submit a ticket?
I should add that a lot of the messages are not needed and Id be ok with re-instaling everything from scrath for the mail on the server if needed.
thanks
2017-06-28 23:02:42 1dQPj7-0005Mm-JP <=
[email protected] H=([127.0.0.1]) [78.90.72.196]:41899
P=esmtpa A=dovecot_plain:[email protected]_of_my_site.com S=15548
[email protected]_of_my_sites.com T="Hand regard:
following the hand with the eyes!" for [email protected]
I deleted the email account in question and all email accounts for that website.
Also at that time I found that the directory for /var/spool/exim was filling up by several GB in the space of hours and the servers disk was becoming full because of it. I cant recall what I did exactly but I think I may have deleted or removed something that I followed in a guide and the disk usage stopped anyway.
Since then though mail doesnt seem to work on the server at all and I need to fix it now. It seems that no messages sent to any of the email addresses for the accounts are received and no mails from cron jobs and other tools are received by the root email and test emails are never received too.
Exim is still running though, here is some sample output from /exim_mainlog
2017-10-13 05:28:34 SMTP connection from [51.254.125.108]:46176 (TCP/IP connection count = 2)
2017-10-13 05:28:36 dovecot_login authenticator failed for 108.ip-51-254-125.eu (ADMIN) [51.254.125.108]:46176: 535 Incorrect authentication data ([email protected]_site.com)
2017-10-13 05:28:36 SMTP connection from [127.0.0.1]:59006 (TCP/IP connection count = 3)
2017-10-13 05:28:36 SMTP connection from 108.ip-51-254-125.eu (ADMIN) [51.254.125.108]:46176 closed by QUIT
2017-10-13 05:28:55 1e2T9p-0002wB-Jh Sender identification U=another_site D=another_site.net [email protected]_site.net
2017-10-13 05:28:55 1e2uKp-0001KM-Kt Sender identification U=another_site D=another_site.net [email protected]_site.net
2017-10-13 05:28:55 1e2pHa-0004vO-Vz Message is frozen
2017-10-13 05:28:56 1e2vqV-0002Ey-GI Message is frozen
2017-10-13 05:28:56 1e2uxV-0003Vm-47 Message is frozen
a few other details:
In the WHM sent summary there is no activity and same for the mail delivery reports.
Mail queue manager seems to have a lot of activity in it, all messages there are either frozen or queued and seem to be from [System] and trying to go to either root, cpanel or [email protected], there are also some mails trying to send from one of our sites to other email addresses I dont recognise (I would guess they are wither users signed up to the site or people that have left a comment).
Im not sure how to tackle this, should I submit a ticket?
I should add that a lot of the messages are not needed and Id be ok with re-instaling everything from scrath for the mail on the server if needed.
thanks