1

Topic: Spam from local user

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.2.1
- Deployed with iRedMail Easy or the downloadable installer? installer
- Linux/BSD distribution name and version: centos 8
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): mysql
- Web server (Apache or Nginx): nginx
- Manage mail accounts with iRedAdmin-Pro? yes
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====

Hi,
I have this new install and I am getting many of this like emails from users that are hosted on the server from their office IP address.
I removed the indications of users or domains or IP add to protect the innocent....

Why I am getting this messages and how can I fix it.

Thanks
---------------------------------

Content type: Spam
Internal reference code for the message is 29620-14/HXLFwbEB9PFD

First upstream SMTP client IP address: [7x.xxx.29.74]:57722

Received trace: ESMTPSA://[7x.xxx.xx.74]:57722

Return-Path: <j.....o@ca......d.org>
From: Microsoft Outlook <<j.....o@ca......d.org>
Subject: Microsoft Outlook Test Message
Not quarantined.

The message WILL BE relayed to:
<j.....o@ca......d.org>

Spam scanner report:
Spam detection software, running on the system "ired3.----.net",
has NOT identified this incoming email as spam.  The original
message has been attached to this so you can view it or label
similar future email.  If you have any questions, see
@@CONTACT_ADDRESS@@ for details.

Content preview:  This is an e-mail message sent automatically by Microsoft
  Outlook while testing the settings for your account.

Content analysis details:   (2.3 points, 5.0 required)

pts rule name              description
---- ---------------------- --------------------------------------------------
-1.0 ALL_TRUSTED            Passed through trusted hosts only via SMTP
0.0 HTML_MESSAGE           BODY: HTML included in message
1.1 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts
1.4 MISSING_DATE           Missing Date: header
0.6 HTML_MIME_NO_HTML_TAG  HTML-only message, but there is no HTML
                            tag
0.1 MISSING_MID            Missing Message-Id: header


header.hdr

Return-Path: <j.....o@ca......d.org>
Received: from CADC73J8V1 (unknown [70.118.29.74])
    by ired3.---.net (Postfix) with ESMTPSA id 49RHfy1pzpz55b7
    for <j.....o@ca......d.org>; Tue, 19 May 2020 09:03:54 -0500 (CDT)
From: Microsoft Outlook
To: =?utf-8?B?Sm9lIE9yb3pjbw==?=
Subject: =?utf-8?B?TWljcm9zb2Z0IE91dGxvb2sgVGVzdCBNZXNzYWdl?=
MIME-Version: 1.0
Content-Type: text/html;
    charset="utf-8"
Content-Transfer-Encoding: quoted-printable

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Spam from local user

Cannot help much without full + original Postfix log.

3

Re: Spam from local user

ZhangHuangbin wrote:

Cannot help much without full + original Postfix log.

I can send it to you directly. posting the log here in a public place with full addresses is not a good idea.

4

Re: Spam from local user

sergiocesar wrote:

I can send it to you directly. posting the log here in a public place with full addresses is not a good idea.

Please simply replace sensitive data by fake domain names/IPs like "example.com", "x.x.x.x" and paste here.