Topic: Spf and spam from same domain
==== Required information ====
- iRedMail version:
- Store mail accounts in which backend (LDAP/MySQL/PGSQL):
- Linux/BSD distribution name and version:
- Related log if you're reporting an issue:
======== Required information ====
- iRedMail version:
- Store mail accounts in which backend (LDAP/MySQL/PGSQL):
- Linux/BSD distribution name and version:
- Related log if you're reporting an issue:
====
Hello,
i have two problems on iredmail server, the first is the spam and second is SPF check ( i guess they are related ).
The customer receives a lot of spam from his own address, the following log on the server and the header of the message
Oct 21 18:44:35 posta postfix/smtpd[5677]: connect from unknown[181.66.167.61]
Oct 21 18:44:46 posta policyd: rcpt=58436, module=bypass, host=181.66.167.61 (unknown), from=roughestgv3@google.com, to=info@mydomain.it, size=0
Oct 21 18:44:46 posta postfix/smtpd[5677]: EDD635C0E24: client=unknown[181.66.167.61]
Oct 21 18:44:52 posta amavis[5786]: (05786-02) ESMTP< XFORWARD NAME=unknown ADDR=181.66.167.61 PORT=38619\r\n
Oct 21 18:44:52 posta amavis[5786]: (05786-02) lookup_ip_acl: key="181.66.167.61", no match
Oct 21 18:44:52 posta amavis[5786]: (05786-02) Checking: 4XFRxLRCWmzH [181.66.167.61] <roughestgv3@google.com> -> <info@mydomain.it>
Oct 21 18:45:16 posta postfix/smtpd[5677]: disconnect from unknown[181.66.167.61]
Return-Path: <roughestgv3@google.com>
Delivered-To: info@mydomain.it
Received: from localhost (localhost [127.0.0.1])
by posta.serverIred.xx (Postfix) with ESMTP id 31D695C1ACF
for <info@mydomain.it>; Mon, 21 Oct 2013 18:44:53 +0200 (CEST)
X-Virus-Scanned: amavisd-new at posta.serverIred.xx
Received: from posta.serverIred.xx ([127.0.0.1])
by localhost (posta.serverIred.xx [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 4XFRxLRCWmzH for <info@mydomain.it>;
Mon, 21 Oct 2013 18:44:52 +0200 (CEST)
Received: from [190.233.12.44] (unknown [181.66.167.61])
by posta.serverIred.xx (Postfix) with ESMTP id EDD635C0E24
for <info@mydomain.it>; Mon, 21 Oct 2013 18:44:46 +0200 (CEST)
Date: Mon, 21 Oct 2013 11:44:45 -0500
From: <info@mydomain.it>
To: <info@mydomain.it>
The messages of this type are many, such as connections from "unknown". In none of the incoming message appears the classic SPF check.
Is possible check the problem ?
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.