No email address but still spamming, bug?

rhm.geerts

Well-Known Member
Jul 29, 2008
181
24
68
Maastricht
cPanel Access Level
Root Administrator
We have a user with a domain for example userdomain.nl. Contact email address for this account is [email protected].

The website for userdomain.com is resided at our cpanel server.
However, all e-mail is handled by an external anti-spam server. MX records are set to that external system, remote mail exchanger.

In the user account under e-mail, no single email address is present, except ofcourse for the systemaccount.

Now this is happening:
Code:
2015-04-06 13:20:31 1Yf54w-0002j6-SI <= [email protected] H=(107.182.17.136) [107.182.17.136]:49954 P=esmtpa A=dovecot_login:[email protected] S=4044 id=ed7e6721084e8f572d59ca[email protected] T=" Amazon sellers and affiliates \32\2
etc. Shortly said, this is authenticated login and spam is being send this way.

As far as I'm concerend this is a Cpanel bug. No email address which does not exist on the server, should be able to login to dovecot. But it is happening.

It's now the 3rd time this happens and we're getting tired of it.

Why is it possible that somebody can authenticate for an email address which does not even exist on the server but is only set as contact email addres?

How can this be fixed?
Please advise.

Cpanel version WHM 11.48.2 (build 3)
 
Last edited by a moderator:

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,880
2,267
463
Hello,

Could you open a support ticket using the link in my signature so we can take a closer look? You can post the ticket number here so we can update this thread with the outcome.

Thank you.
 
  • Like
Reactions: rhm.geerts

rhm.geerts

Well-Known Member
Jul 29, 2008
181
24
68
Maastricht
cPanel Access Level
Root Administrator
Hello.

The ticket number is 6363963.

In the ticket I wrote I had to change things to give you access, but I already did.
Please tell me if you're ready, so I can restore the original host and key settings again.
 

rhm.geerts

Well-Known Member
Jul 29, 2008
181
24
68
Maastricht
cPanel Access Level
Root Administrator
Hello Michael.

Jason fixed it for me.
I'll explain for future references or if anybody else might encounter the same issue.

The cause was not the contact email address but the quota.
Since the account was over quota, cpanel was not able to make a lock on the maildir and for that reason none of the email accounts present were displayed in Cpanel itself under the user account.
This gave the impression no email addresses were present, but it made sending mail through the accounts possible, because in fact they did exist.

After temporarily giving the account unlimited quota, the email accounts became visible again. I removed them and set the quota back to the original quota.

Problem fixed.

Thank you and especially Jason for the support and help!
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,880
2,267
463
Hello,

I am happy to see the issue is now resolved. Thank you for updating us with the outcome.