Link to home
Start Free TrialLog in
Avatar of Kani Str
Kani StrFlag for India

asked on

simple qmail question but a bit urgent!

i use qmail... someone using this for spamming... how can i restrict this. actually they target the machine using anonymous@my-domain.uk

plese help me secure my qmail server, my aim is to protect this from spammers. so i like to hear any suggestion for making it secure...
SOLUTION
Avatar of ravenpl
ravenpl
Flag of Poland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Kani Str

ASKER

>>>>
/var/qmail/control/rcpthosts should containg domainnames which are relayed (and only those)
also use smpt-auth instead of opening relay with tcp-control.

Yes i see the domains there, but somehow people using my domain anonymous@domain.com !!!
can you please tell how i can enable anuthentication?

*** I use webmin.

Redimido --- i am looking at the link now...

It looks like there is lot more to study..
my aim: I have 5 domains on my server, and i don't like any one sending out emails ourside this machine. I like to sendout emails only from these 5 domains. I am using webmin, is there a easy way to acheive this using webmin?
str_kani:

do your users from the five domains are inside the LAN?
something like
-------LAN--------(EMAIL SERVER)-------INTERNET

if so, then it's easy. if not, then you need to know the ip addresses where your users are, -or- configure smtp-auth.

please tell us more about what you want
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
wnross is correct

we are not analyzing how you know you are being used as relay.

these emails are from some client that showed them to you?
is your internet connection full?
is the server overloaded?
do your users from the five domains are inside the LAN?

yes, they all inside my server (on the same machine...)

my allowed domains have the list...
*.domain1.com
*.domain2com
etc up 10 domains....

>>>>>>>> 1) how do you know that the spammer is using your mail servers?
the from field contains anonymous@my-domain.com

>>> these emails are from some client that showed them to you?
the from field contains anonymous@my-domain.com
>>> is your internet connection full?
Nope
>>>is the server overloaded?
Nope

i just had a chance to view the queue using webmin...
the from header says....

From      robert <roberts_walters@yahoo.com>      
To            
Sent      13 May 2006 09:04:37 -0000      
Subject      CONSOLATION PRIZE WINNING NOTICE!!!

this is surely an ourside email and spamm...!!! please help me keep these sort of emails away...
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of wnross
wnross

Again I caution not to panic, run the tools I recommended above.

Certainly the header came from a spammer but your message is likely a bounce back from a failed delivery....because you won't relay.

PS: What were the results of the tests?

Cheers,
-Bill