Hello i need help,
i can see exim processes like this on my server:
27869 mailnull 25 0 7700 852 532 R 4 0.0 0:17.53 /usr/sbin/exim -bd -q60m
There are load spikes and swap is at 50-100%
Mail Queue is at maximum 4000+ messages and tail -f /var/log/exim_mainlog shows some like spammy esmtp threads.
2011-08-10 00:04:12 1QquPD-00061H-TD <= ***@****.org H=ns35.****.com [254.254.254.254] P=esmtps X=TLSv1:AES256-SHA:256 S=3117 id=E1QquUw-0002Z5-DQ@ns35.****.com
Im not able to discover what is the cause and what i need to ban, how to protect server, so im asking you there. There are more details from cPanel mail stats:
Time spent on the queue: all messagesTime Messages Percentage Cumulative Percentage
Under 1m 58312 44.1% 44.1%
5m 47 0.0% 44.1%
3h 4 0.0% 44.1%
6h 1 0.0% 44.1%
12h 6 0.0% 44.1%
1d 8 0.0% 44.2%
Over 1d 73844 55.8% 100.0%
Top 50 mail rejection reasons by message countMessages Mail rejection reason
8264 Unknown
2327 Rejected RCPT: Sender verify failed
492 Rejected MAIL: Access denied - Invalid HELO name (See RFC2821 4.1.1.1)
Top 50 mail temporary rejection reasons by message countMessages Mail temporary rejection reason
6499 Temporarily rejected RCPT: Could not complete sender verify
Top 50 rejected ips by message countMessages Rejected ip
7493 local
1630 [*.*.*.*]
68 [*.*.*.*]
61 [*.*.*.*]
PLEASE, can anyone help me what exactly to do to discover source of this issue and eliminate it? It must be also helpfull for more members.
Thank you,
P.
i can see exim processes like this on my server:
27869 mailnull 25 0 7700 852 532 R 4 0.0 0:17.53 /usr/sbin/exim -bd -q60m
There are load spikes and swap is at 50-100%
Mail Queue is at maximum 4000+ messages and tail -f /var/log/exim_mainlog shows some like spammy esmtp threads.
2011-08-10 00:04:12 1QquPD-00061H-TD <= ***@****.org H=ns35.****.com [254.254.254.254] P=esmtps X=TLSv1:AES256-SHA:256 S=3117 id=E1QquUw-0002Z5-DQ@ns35.****.com
Im not able to discover what is the cause and what i need to ban, how to protect server, so im asking you there. There are more details from cPanel mail stats:
Time spent on the queue: all messagesTime Messages Percentage Cumulative Percentage
Under 1m 58312 44.1% 44.1%
5m 47 0.0% 44.1%
3h 4 0.0% 44.1%
6h 1 0.0% 44.1%
12h 6 0.0% 44.1%
1d 8 0.0% 44.2%
Over 1d 73844 55.8% 100.0%
Top 50 mail rejection reasons by message countMessages Mail rejection reason
8264 Unknown
2327 Rejected RCPT: Sender verify failed
492 Rejected MAIL: Access denied - Invalid HELO name (See RFC2821 4.1.1.1)
Top 50 mail temporary rejection reasons by message countMessages Mail temporary rejection reason
6499 Temporarily rejected RCPT: Could not complete sender verify
Top 50 rejected ips by message countMessages Rejected ip
7493 local
1630 [*.*.*.*]
68 [*.*.*.*]
61 [*.*.*.*]
PLEASE, can anyone help me what exactly to do to discover source of this issue and eliminate it? It must be also helpfull for more members.
Thank you,
P.