Hi, the Exim queue in my VPS is currently being filled with thousands of bounced emails per minute. I found an old formmail script in a client's website and removed it, I am sure this was the cause of the spam, however even after deleting the whole queue (which took forever) there are still all these bounced messages being generated. They all look like this:
The "X-Failed-Recipients" are all different but the "envelope-from" are all the same three or four.
Is it possible that even though I have removed the cause of the outgoing spam, previously undelivered messages are still causing problems, or are these new emails being sent, which means I still have a source of spam in that account? I don't understand enough about the way Exim works to know the answer.
Thanks!
Code:
Headers spool file
1WQh2m-0007mQ-0w-H
mailnull 47 12
<>
1395337576 0
-ident mailnull
-received_protocol local
-body_linecount 143
-max_received_linelength 110
-allow_unqualified_recipient
-allow_unqualified_sender
-frozen 1395337576
-localerror
XX
1
[email protected]
159P Received: from mailnull by server1.domain.co.uk with local (Exim 4.82)
id 1WQh2m-0007mQ-0w
for [email protected]; Thu, 20 Mar 2014 17:46:16 +0000
045 X-Failed-Recipients: [email protected]
029 Auto-Submitted: auto-replied
069F From: Mail Delivery System <[email protected]>
028T To: [email protected]
059 Subject: Mail delivery failed: returning message to sender
058I Message-Id: <[email protected]>
038 Date: Thu, 20 Mar 2014 17:46:16 +0000
Data spool file
1WQh2m-0007mQ-0w-D
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
[email protected]
Domain domain3.co.uk has exceeded the max emails per hour (375/300 (125%)) allowed. Message discarded.
------ This is a copy of the message, including all the headers. ------
Return-path: <[email protected]>
Received: from [91.235.7.37] (port=51282 helo=91.235.7.37)
by server1.domain.co.uk with esmtpa (Exim 4.82)
(envelope-from <[email protected]>)
id 1WQh2l-0007jC-OD
for [email protected]; Thu, 20 Mar 2014 17:46:15 +0000
Message-ID: <[email protected]>
From: =?windows-1251?B?zODw4+Dw6PLg?= <[email protected]>
To: <[email protected]>
Subject: =?windows-1251?B?y/7k7Ojr4CwgxfHr6CDi+yDw5eDr/O3uIObl?=
=?windows-1251?B?6+Dl8uUg6+Xj6u4g5+Dw4OHu8uDy/CAxMs5P?=
=?windows-1251?B?zvAsIA==?=
Date: Thu, 20 Mar 2014 21:46:05 +0400
Is it possible that even though I have removed the cause of the outgoing spam, previously undelivered messages are still causing problems, or are these new emails being sent, which means I still have a source of spam in that account? I don't understand enough about the way Exim works to know the answer.
Thanks!