Topic: Strange Spam Issue (mail.leftidesire.rest) with iRedMail
We're having a strange spam issue where it appears we have been exploited in some way. We have dozens of log entries like this:
2020-04-30 10:58:33 INFO [0.0040s] [155.94.154.152] RCPT, 10218-20-675074-1903-mike=domain.com@mail.leftidesire.rest -> mike@domain.com, DUNNO
2020-04-30 11:03:20 INFO [155.94.154.152] recipient throttle, leon@site.net -> msg_size (6419/15728640, period: 86400 seconds, time left: 13 hours, 1 minutes, 11 seconds)
2020-04-30 11:03:20 INFO [0.0050s] [155.94.154.152] END-OF-MESSAGE, 10218-20-535106-1903-leon=site.net@mail.leftidesire.rest -> leon@site.net, DUNNO
10218-20-675074-1903-mike=domain.com@mail.leftidesire.rest is not an email but mike@domain.com is and same for leon@site.net.
I thought this may be and exploited password issue but I am not so sure because we have these for at least 2 dozens different users on our server that I have found so far.
We do not allow users to send as an alias as far as I know. We are not sure how this has happened. Has anyone else seen something similar? We're at a loss as to how to curb this behavior.
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.