Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section Mail Server
  • Search

spam emails from domains on my server

Questions regarding the Mail Server
Dovecot, Exim, RoundCube
Post Reply
  • Print view
Advanced search
2 posts • Page 1 of 1
djeglin
Posts: 3
Joined: Fri Apr 04, 2014 8:26 am

spam emails from domains on my server
  • Quote

Post by djeglin » Fri May 29, 2015 6:49 pm

So I noticed that my server seemed to get unreliable recently, at which point I noticed that my exim queue was hundreds of thousands of messages long. I had recently tried to set up email on one of my domains but my server IP was blacklisted. Now I understand why!

It seems that even after disabling email for the offending domains in Vesta, the domains are still able to send email with exim?

So, I have several questions -

1. How might they be getting access?
2. How can I stop them?
3. Why is the queue still raising even when exim is disabled in Vesta?
4. How can I tell where the intrusion is initiating from and block it?

Any help much appreciated. Cheers!
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: spam emails from domains on my server
  • Quote

Post by skurudo » Sun May 31, 2015 7:51 pm

Use mailq for see your log queue.

exim -Mvh message-id-from queue -- headers
exim -Mvb message-id-from queue -- body message

Search php script, which send all this spam mail.
It seems from php-shell.
You can use maldet for search this php-shell - https://www.rfxn.com/projects/linux-malware-detect/
Top


Post Reply
  • Print view

2 posts • Page 1 of 1

Return to “Mail Server”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password