Topic: Spoofed Email?
Greetings,
I started receiving complaints on Monday from some customers who were receiving spam mail spoofed from their own email address.
This was extremely odd to me because I know that iRedMail has safeguards against spoofed email (even email that we spoof on purpose sending through a third party mail server.
I'm curious if someone has a better idea in the diagnosis. This is on a stock install of iRedMail - no changes made to the default postfix setup during install.
Here is the full headers of an example of the mail. "domainx.com" is our domain and I've swapped it for a generic name:
From: <anthony@domainx.com>
Date: April 25, 2011 12:10:11 AM PDT
To: <anthony@domainx.com>
Subject: Newsletter Mon, 25 Apr 2011 09:10:11 +0200
return-path: <e6100246d@ms29.hinet.net>
delivered-to: anthony@domainx.com
received: from localhost (mail.domainx.com [127.0.0.1]) by mail.domainx.com (iRedMail) with ESMTP id B847612800A for <anthony@domainx.com>; Mon, 25 Apr 2011 00:10:13 -0700 (PDT)
received: from mail.domainx.com ([127.0.0.1]) by localhost (mail.domainx.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f+JNM-E2KmZF for <anthony@domainx.com>; Mon, 25 Apr 2011 00:10:13 -0700 (PDT)
received: from [178.122.3.12] (unknown [178.122.3.12]) by mail.domainx.com (iRedMail) with ESMTP id 9196C128004 for <anthony@domainx.com>; Mon, 25 Apr 2011 00:10:12 -0700 (PDT)
received: from 178.122.3.12(helo=domainx.com) by domainx.com with esmtpa (Exim 4.69) (envelope-from ) id 1MM9W7-2829qd-4Q for <anthony@domainx.com>; Mon, 25 Apr 2011 09:10:11 +0200
dkim-signature: v=1; a=rsa-sha256; c=relaxed/simple; d=domainx.com; h=message-id:x-mailer:content-transfer-encoding:content-type :content-type:mime-version:date:date:subject:subject:to:from :from; s=dkim; t=1303715413; x=1306307413; bh=LAaksjVhPc8fJrurVF NRM9I5lwqO4lX8aoOkeKEPlkU=; b=H5I7Y+iEz0nHrNml1oNLo9+EGbJ0McqL7Q Clc8XPwiFFtyzPYUNZaI5ioXYacbFl0tmh+5KGLYgwcMvyDVSQdr1wrXnakptkzv Qk0Qn0cP56QWdYfnareKDNeRy2oLc+2qOuUsYCV4uQudrGIo0q2t211ZyM0GBkPI gFQX0rN58=
x-virus-scanned: amavisd-new at mail.domainx.com
x-spam-flag: NO
x-spam-score: 5.191
x-spam-level: *****
x-spam-status: No, score=5.191 tagged_above=-10 required=6.2 tests=[BAYES_99=3.5, RCVD_IN_PBL=0.905, RDNS_NONE=0.1, SPF_NEUTRAL=0.686] autolearn=no
x-original-helo: [178.122.3.12] (iRedMail: http://www.iredmail.org/)
mime-version: 1.0
content-type: text/plain; charset="us-ascii"
content-transfer-encoding: 7bit
x-mailer: rfrg-81
message-id: <0060319118.NQRPTS3G459147@gfdgn.ooamic.info>
And here are the logs in the mail log:
Apr 25 07:10:12 xray policyd: rcpt=13890, module=bypass, host=178.122.3.12 (unknown), from=e6100246d@ms29.hinet.net, to=anthony@domainx.com, size=1016
Apr 25 00:10:12 xray postfix/smtpd[15810]: 9196C128004: client=unknown[178.122.3.12]
Apr 25 07:10:12 xray policyd: connection from: 127.0.0.1 port: 58812 slots: 0 of 2044 used
Apr 25 07:10:13 xray policyd: rcpt=27841, throttle=new(a), host=178.122.3.12, from=e6100246d@ms29.hinet.net, to=anthony@domainx.com, size=1733/15728640, quota=1733/250000000, count=1/60(1), rcpt=1/3600(1), threshold=0%|0%|0%
Apr 25 00:10:13 xray postfix/cleanup[15813]: 9196C128004: message-id=<0060319118.NQRPTS3G459147@gfdgn.ooamic.info>
Apr 25 00:10:13 xray postfix/qmgr[1929]: 9196C128004: from=<e6100246d@ms29.hinet.net>, size=1998, nrcpt=1 (queue active)
Apr 25 00:10:13 xray postfix/smtpd[15810]: disconnect from unknown[178.122.3.12]
Apr 25 00:10:13 xray postfix/smtpd[15819]: connect from mail.domainx.com[127.0.0.1]
Apr 25 00:10:13 xray postfix/smtpd[15819]: B847612800A: client=mail.domainx.com[127.0.0.1]
Apr 25 07:10:13 xray policyd: connection from: 127.0.0.1 port: 58816 slots: 1 of 2044 used
Apr 25 07:10:13 xray policyd: rcpt=27842, whitelist=update, host=127.0.0.1 (mail.domainx.com), from=e6100246d@ms29.hinet.net, to=anthony@domainx.com, size=2982
Apr 25 00:10:13 xray postfix/cleanup[15813]: B847612800A: message-id=<0060319118.NQRPTS3G459147@gfdgn.ooamic.info>
Apr 25 00:10:14 xray postfix/smtpd[15819]: disconnect from mail.domainx.com[127.0.0.1]
Apr 25 00:10:14 xray postfix/qmgr[1929]: B847612800A: from=<e6100246d@ms29.hinet.net>, size=3185, nrcpt=1 (queue active)
Apr 25 00:10:14 xray amavis[14137]: (14137-19) Passed CLEAN, LOCAL [178.122.3.12] [178.122.3.12] <e6100246d@ms29.hinet.net> -> <anthony@domainx.com>, Message-ID: <0060319118.NQRPTS3G459147@gfdgn.ooamic.info>, mail_id: f+JNM-E2KmZF, Hits: 5.191, size: 1997, queued_as: B847612800A, 1254 ms
Apr 25 00:10:14 xray postfix/pipe[15820]: B847612800A: to=<anthony@domainx.com>, relay=dovecot, delay=0.65, delays=0.51/0.01/0/0.13, dsn=2.0.0, status=sent (delivered via dovecot service)
Apr 25 00:10:14 xray postfix/qmgr[1929]: B847612800A: removed
It looks like the first message was held due to greylisting, as normal process... However the second message made it through and wasn't blocked from spoofing.
Does anyone have any thoughts?
Thank You
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.