Postfix Spam Problem

Discussion in 'Server Operation' started by rusty, Feb 26, 2008.

  1. rusty

    rusty Member

    I'm using greylisting and spam assassin with razor2 pyzor dcc and am very happy with the results.

    here's my complaint: I see in my report that one domain in particular with only one user is getting 4000 or more per day "Reject Recipient Address"

    This is tying up bandwidth and needlessly using up server resources. The IP addresses seem pretty varied. Probably infected machines spewing this garbage out.

    Has anyone dealt with this successfully? I'm ready to get this user off my server even though they are just a victim too.

    Thanks
     
  2. falko

    falko Super Moderator Howtoforge Staff

    I guess that some spammer is abusing that user's email address as the sender address for his spam. That's not the user's fault, but explains why he's getting all those "Reject Recipient Address" messages.
     
  3. rusty

    rusty Member

    Sorry, I didn't explain it well. I'm seeing those messages in a report derived from the logs. The spammer is trying every conceivable mailbox name for this domain trying to find one that is real. I have 20 different sender IPs sending to [email protected], then another 20 sender IPs trying [email protected], hundreds of different names everyday from multiple senders. Again totaling 4000 a day. It's been going on for some time and doesn't seem like it will stop. Seems like the sender machines are zombies.
     
  4. falko

    falko Super Moderator Howtoforge Staff

    i'm not sure, but maybe greylisting helps against these bots...
     

Share This Page