Topic: iredapd is killed by "spam"? I have to restart every few hours
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.4.2 MYSQL edition
- Deployed with iRedMail Easy or the downloadable installer? - Downloadable installer
- Linux/BSD distribution name and version: Ubuntu 20.04.3 LTS
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): Mysql
- Web server (Apache or Nginx): Apache
- Manage mail accounts with iRedAdmin-Pro? Yes
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
Dear forum members,
It seems, that one of my iredmail server keeps getting malicious email which would go to mx01.mytld.com whereas the server serves only for mytld.com
iredapd just keeps 'hanging', that means, it is inaccessible on port 7777, and i can see in the dovecot logs numerous log lines like this:
Feb 11 23:28:20 mail python3[2749301]: iredapd [SPF][__12.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] No valid IP addresses/networks.
Feb 11 23:28:20 mail python3[2749301]: iredapd [SPF][include __9.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] empty
Feb 11 23:28:20 mail python3[2749301]: iredapd [SPF][include __7.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] empty
Feb 11 23:28:21 mail python3[2749301]: iredapd [SPF][include __5.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] empty
Feb 11 23:28:21 mail python3[2749301]: iredapd [SPF][include __2.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] empty
Feb 11 23:28:21 mail python3[2749301]: iredapd [SPF][include __11.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] v=spf1 include:__1.__11.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org. inc>
Feb 11 23:28:21 mail python3[2749301]: iredapd [SPF][__11.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] 'spf:' tag: __7.__11.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org., __3.__11.__12>
Feb 11 23:28:21 mail python3[2749301]: iredapd [SPF][include __7.__11.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] empty
Feb 11 23:28:22 mail python3[2749301]: iredapd [SPF][include __3.__11.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] empty
Feb 11 23:28:22 mail python3[2749301]: iredapd [SPF][include __4.__11.__12.__12.__10.__11.__10.__1.__12.__10.__1.kovbal.net-measurement.org.] empty
I'm trying to escalate this as an attack, I've already blacklisted the target email@mx01.mytld.com, also this .net-measurement.org stuff, but this just keeps happening.
Can you tell me a way to efficiently filter out this type of attacks, and protect iredapd from falling apart?
Thanks,
Balazs Kovacs
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.