Hello,
I host about 500 accounts in my server (WHM 11.23.2 cPanel 11.23.3-S25959). This server's IP is being constantly marked as "spammer" in lots of spam lists.
I enabled the option "Prevent the user "nobody" from sending out mail to remote addresses", I have clamAV and SMTP Tweak active, and I even changed the exim outgoing IP to a different one from the server's main IP.
Even so, the server's main IP is being quoted as spammer, primarily from hotmail.
I receive reports from spamlists with some copies of emails/spam sent from my server.
I can not track any of the Exim IDs in the exim_mainlog, and many emails are being sent with this kind of ID:
01C95FEB.7E304865@"myserverhostname.com"
Most of the emails are being sent to hotmail, from requesters that do not exist on my server.
What can I do to track down these spammers? I believe they are exploring php scripts and almost all spam emails are not being sent from Exim. How can I find those scripts?
Any way to block this through firewall, IP tables or something else?
Any help would be very much appreciated.
Best regards,
I host about 500 accounts in my server (WHM 11.23.2 cPanel 11.23.3-S25959). This server's IP is being constantly marked as "spammer" in lots of spam lists.
I enabled the option "Prevent the user "nobody" from sending out mail to remote addresses", I have clamAV and SMTP Tweak active, and I even changed the exim outgoing IP to a different one from the server's main IP.
Even so, the server's main IP is being quoted as spammer, primarily from hotmail.
I receive reports from spamlists with some copies of emails/spam sent from my server.
I can not track any of the Exim IDs in the exim_mainlog, and many emails are being sent with this kind of ID:
01C95FEB.7E304865@"myserverhostname.com"
Most of the emails are being sent to hotmail, from requesters that do not exist on my server.
What can I do to track down these spammers? I believe they are exploring php scripts and almost all spam emails are not being sent from Exim. How can I find those scripts?
Any way to block this through firewall, IP tables or something else?
Any help would be very much appreciated.
Best regards,
Last edited: