Topic: Help needed with stopping relaying spam
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.51
- Deployed with iRedMail Easy or the downloadable installer?
- Linux/BSD distribution name and version: Ubuntu 20.04
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
Not sure what happened yet, mail stopped flowing so I jumped on the server to find a bunch of spam trying to relay out. I changed the suss account password, ran the find_top_sasl_username and find_sasl_login_ip to try to stop the bleeding. Is the a command to delete these messages from the queue? I tried postsuper with the queue-ID with no luck. Not sure how to stop these, the server has been running fine since 1-2022.
Here is the tail of maillog. Its ugly and been going on since 7-2-2022. Any guidance would be greatly appreciated. Thanks!
maillog
Jul 4 12:44:52 mail postfix/bounce[3584]: 4Lc7hK0ZQtzrfn: sender non-delivery notification: 4LcBVX3LP5z4FtV
Jul 4 12:44:52 mail postfix/qmgr[1465]: 4Lc7hK0ZQtzrfn: removed
Jul 4 12:44:52 mail postfix/qmgr[1465]: 4LbZ5G5Xkxz1WHc: from=<>, size=7493, nrcpt=1 (queue active)
Jul 4 12:44:52 mail postfix/smtp[3270]: Trusted TLS connection established to smtp.sendgrid.net[52.204.68.213]:587: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Jul 4 12:44:54 mail postfix/smtp[3293]: 4Lbqnk2hQzz3cx5: to=<hukset2@aol.com>, relay=smtp.sendgrid.net[167.89.123.82]:587, delay=50590, delays=47821/2738/0.16/30, dsn=5.0.0, status=bounced (host smtp.sendgrid.net[167.89.123.82] said: 550 The from address does not match a verified Sender Identity. Mail cannot be sent until this error is resolved. Visit https://sendgrid.com/docs/for-developer … -identity/ to see the Sender Identity requirements (in reply to end of DATA command))
Jul 4 12:44:54 mail postfix/cleanup[3555]: 4LcBVZ6lc9z4FpK: message-id=<4LcBVZ6lc9z4FpK@mail.mydomain.com>
Jul 4 12:44:54 mail postfix/bounce[3584]: 4Lbqnk2hQzz3cx5: sender non-delivery notification: 4LcBVZ6lc9z4FpK
Jul 4 12:44:54 mail postfix/qmgr[1465]: 4Lbqnk2hQzz3cx5: removed
Jul 4 12:44:54 mail postfix/qmgr[1465]: 4LbdcB056sz2Pj9: from=<>, size=7469, nrcpt=1 (queue active)
Jul 4 12:44:54 mail postfix/smtp[3330]: 4LbM1P1Lcrzs5b: to=<jesela85@yahoo.com>, relay=smtp.sendgrid.net[54.146.218.5]:587, delay=117583, delays=114815/2738/0.02/30, dsn=5.0.0, status=bounced (host smtp.sendgrid.net[54.146.218.5] said: 550 The from address does not match a verified Sender Identity. Mail cannot be sent until this error is resolved. Visit https://sendgrid.com/docs/for-developer … -identity/ to see the Sender Identity requirements (in reply to end of DATA command))
Jul 4 12:44:54 mail postfix/cleanup[3555]: 4LcBVZ6q6Mz4FtW: message-id=<4LcBVZ6q6Mz4FtW@mail.mydomain.com>
Jul 4 12:44:54 mail postfix/bounce[3584]: 4LbM1P1Lcrzs5b: sender non-delivery notification: 4LcBVZ6q6Mz4FtW
Jul 4 12:44:54 mail postfix/qmgr[1465]: 4LbM1P1Lcrzs5b: removed
Jul 4 12:44:54 mail postfix/qmgr[1465]: 4LbTSQ6RXQz3Xww: from=<>, size=7502, nrcpt=1 (queue active)
Jul 4 12:44:54 mail postfix/smtp[3243]: Trusted TLS connection established to smtp.sendgrid.net[34.237.250.201]:587: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Jul 4 12:44:54 mail postfix/smtp[3293]: Trusted TLS connection established to smtp.sendgrid.net[52.0.142.242]:587: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Jul 4 12:44:56 mail postfix/smtp[3295]: 4LbyRl45QCz4Mrb: to=<laquetta1119@gmail.com>, relay=smtp.sendgrid.net[167.89.123.97]:587, delay=32597, delays=29827/2739/0.16/30, dsn=5.0.0, status=bounced (host smtp.sendgrid.net[167.89.123.97] said: 550 The from address does not match a verified Sender Identity. Mail cannot be sent until this error is resolved. Visit https://sendgrid.com/docs/for-developer … -identity/ to see the Sender Identity requirements (in reply to end of DATA command))
Jul 4 12:44:56 mail postfix/cleanup[3555]: 4LcBVc0bTpz4FpL: message-id=<4LcBVc0bTpz4FpL@mail.mydomain.com>
Jul 4 12:44:56 mail postfix/bounce[3584]: 4LbyRl45QCz4Mrb: sender non-delivery notification: 4LcBVc0bTpz4FpL
Jul 4 12:44:56 mail postfix/qmgr[1465]: 4LbyRl45QCz4Mrb: removed
Jul 4 12:44:56 mail postfix/qmgr[1465]: 4Lbxny3fKMz4Jg2: from=<info@bone.go.id>, size=5007, nrcpt=1 (queue active)
Jul 4 12:44:56 mail postfix/smtp[3330]: Trusted TLS connection established to smtp.sendgrid.net[34.237.250.201]:587: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.