Mailqueue full of backscatter

Discussion in 'Server Operation' started by ispconfig_question, Apr 2, 2016.

  1. ispconfig_question

    ispconfig_question New Member

    I have installed ISPconfig 3 on CentOS 7 with Postfix, Amavis, ClamAV, etc. according to the perfect server guide. Everything seems to work quite fine, but the mailqueue fills with backscatter from spam messages. The mailqueue contains waiting mails with content like this (excerpts):
    recipient: FAKE SPAM ADDRESS
    Subject: Undeliverable mail, invalid header section
    *** MESSAGE CONTENTS deferred/B/B76A130ECB62 ***
    The message WAS NOT relayed to:
    <REAL ADDRESS ON MY SERVER>:
    554 5.6.0 bounce, id=3D14327-03 - bad header
    This nondelivery report was generated by the program amavisd-new at host ...

    So it seems there is an incoming spam with bad header sent to a real address on my server from a fake address anywhere else, it is correctly identified by Amavis as having a bad header, Amavis stopped the delivery and created bounce message (to the fake address) informing the spammer that his message couldn't be delivered. Postfix then frankly tries to deliver all those bounces to a nonexisting addresses for four days and the mailqueue quickly fills up.

    I think it didn't work this way on my previous setup (ISPconfig 3 on CentOS 6) and in fact I don't know what to change - configuration of Amavis to don't create the bounces at all and discard the spam? Or postfix configuration so that it doesn't try to deliver the bounces more than once or something like this?
    I don't know in which configuration file I should try to search, what to search nor to what values to change it, so any help would be appreciated.

    Thanks in advance for a reply.
     

Share This Page