I was watching top today and notice lots of qmail, so I took a look in the mail log and found that lots of mail was being sent. After seeing some of the email addresses I turned off the SMTP relaying (however I do need this on with Auth).
I have a couple of questions, first is this spam ?
------------------------------
3 04:39:19 plesk qmail: 1033634359.968821 new msg 278959
Oct 3 04:39:19 plesk qmail: 1033634359.968838 info msg 278959: bytes 2219 from <> qp 23307 uid 2522
Oct 3 04:39:19 plesk qmail: 1033634359.974715 starting delivery 7264: msg 278959 to remote thepornplaygroundishereforyou@papertime.com
Oct 3 04:39:19 plesk qmail: 1033634359.974844 status: local 0/10 remote 2/20
Oct 3 04:39:19 plesk qmail: 1033634359.979238 delivery 7264: deferral: Sorry,_I_wasn't_able_to_establish_an_SMTP_connection._(#4.4.1)/
------------------------------------
I had the SMTP off altogether at this stage but the email was still trying to send. I am getting lots of these in the log. They never have a 'from' address.
Also there are always IP addresses in the maillog for POP3 but I never see any IP addresses for SMTP, so I can't put the bad guy in my IP blacklist. How do I find the senders IP address ?
Also I added 127.0.0.1/24 to my IP White List ... I beleive this helps somehow ?
I've been trying to look at the qmail-qstat but I just get a bash even when I run it from the correct directory ? How do I find the mail queue ?
That's alot of questions, any answers are appreciated.
Thanks,
Stephen