Topic: To much information on log, is some type of attack?
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.3.2
- Deployed with iRedMail Easy or the downloadable installer? Downloadable installer
- Linux/BSD distribution name and version: Ubuntu 18.04
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL (MariaDB)
- Web server (Apache or Nginx): Nginx (+ Apache for PHPList)
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
Hello to this fantastic community.
Last week my server worked very well, received and send emails very quickly. But this week it take a lot time to delivery in some domains and other like "gmail" never arrives. May be I have severals problems.
I made this server to work with PHPList, I suspect these problems started when I send my first campagain for 840 e-mails.
First maybe I need a clean log, but that I found on it. With my search "barracudacentral" and "spamhaus" is a blacklist monitor, but why my server is "under attack"? Like every second I see this.
("xx.xx.xx.xx" is my server ip that I removed for share the log)
-----------------------
"Mar 16 10:39:53 news postfix/postscreen[2333]: CONNECT from [212.70.149.85]:16484 to [xx.xx.xx.xx]:25
Mar 16 10:39:53 news postfix/dnsblog[2335]: addr 212.70.149.85 listed by domain b.barracudacentral.org as 127.0.0.2
Mar 16 10:39:53 news postfix/dnsblog[2335]: addr 212.70.149.85 listed by domain zen.spamhaus.org as 127.0.0.10
Mar 16 10:39:53 news postfix/dnsblog[2335]: addr 212.70.149.85 listed by domain zen.spamhaus.org as 127.0.0.4
Mar 16 10:39:55 news postfix/postscreen[2333]: PREGREET 11 after 1.6 from [212.70.149.85]:16484: EHLO User\r\n
Mar 16 10:39:55 news postfix/postscreen[2333]: DISCONNECT [212.70.149.85]:16484
Mar 16 10:40:10 news postfix/postscreen[2333]: CONNECT from [212.70.149.55]:55268 to [xx.xx.xx.xx]:25
Mar 16 10:40:10 news postfix/dnsblog[2335]: addr 212.70.149.55 listed by domain zen.spamhaus.org as 127.0.0.4
Mar 16 10:40:10 news postfix/dnsblog[2335]: addr 212.70.149.55 listed by domain zen.spamhaus.org as 127.0.0.10
Mar 16 10:40:10 news postfix/dnsblog[2334]: addr 212.70.149.55 listed by domain b.barracudacentral.org as 127.0.0.2"
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.