Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

how to read SMTP logs

Posted on 2008-06-12
7
Medium Priority
?
3,140 Views
Last Modified: 2010-04-21
Hi, i've been getting huge logs everyday. Here's part of the logs:
...
19:00:20 189.36.201.18 MAIL - 250
19:00:20 189.36.201.18 RCPT - 550
19:00:20 189.36.201.18 DATA - 503
19:00:20 92.1.36.248 DATA - 250
19:00:20 92.1.36.248 QUIT - 240
19:00:20 189.36.201.18 QUIT - 240
19:00:21 84.143.210.214 EHLO - 250
19:00:21 84.143.210.214 MAIL - 250
19:00:21 84.143.210.214 RCPT - 550
19:00:21 84.143.210.214 DATA - 503
19:00:21 84.143.210.214 QUIT - 240
19:00:24 85.105.72.184 EHLO - 250
19:00:24 201.221.149.111 HELO - 250
19:00:24 201.221.149.111 MAIL - 250
19:00:24 78.166.33.247 EHLO - 250
19:00:24 85.105.72.184 MAIL - 250
19:00:24 85.105.72.184 RCPT - 550
19:00:24 85.105.72.184 DATA - 503
19:00:24 201.221.149.111 RCPT - 550
19:00:24 201.221.149.111 QUIT - 240
19:00:24 85.105.72.184 QUIT - 240
19:00:24 78.166.33.247 MAIL - 250
19:00:24 78.166.33.247 RCPT - 550
19:00:24 78.166.33.247 DATA - 503
19:00:27 78.166.33.247 QUIT - 240
19:00:31 83.24.126.5 EHLO - 250
19:00:32 83.24.126.5 MAIL - 250
19:00:32 83.24.126.5 RCPT - 250
19:00:32 83.24.126.5 RCPT - 250
19:00:34 216.117.214.242 HELO - 250
19:00:34 83.24.126.5 DATA - 250
19:00:34 216.117.214.242 MAIL - 250
19:00:34 216.117.214.242 RCPT - 250
19:00:36 83.24.126.5 QUIT - 240
19:00:36 216.117.214.242 DATA - 250
19:00:36 189.34.69.94 EHLO - 250
19:00:36 189.34.69.94 MAIL - 250
19:00:37 200.121.134.100 HELO - 250
19:00:37 200.121.134.100 MAIL - 250
19:00:37 189.34.69.94 RCPT - 550
19:00:37 200.121.134.100 RCPT - 550
19:00:37 189.34.69.94 QUIT - 240
19:00:37 200.121.134.100 QUIT - 240
19:00:40 86.13.6.177 EHLO - 250
19:00:40 86.13.6.177 MAIL - 250
19:00:40 86.13.6.177 RCPT - 250
19:00:42 86.13.6.177 DATA - 250
19:00:42 86.13.6.177 QUIT - 240
...
does this look normal? also, please help me to understand EHLO, MAIL, RCPT, DATA, QUIT commands. what do those numbers (250, 240, 550..) mean?

Thanks,
0
Comment
Question by:ithawaii
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 500 total points
ID: 21773025
This looks perfectly normal for an SMTP log.  If you're using Exchange, you can get a bit more information in the log by enabling NSCA (? those are the initials, but I can't remember if it's NSCA or NCSA) log format in the properties of the SMTP virtual server.  

EHLO, MAIL, etc., are simply the commands that are sent between SMTP servers to process the mail.  Here's a quick overview of those commands and some basic info on those return codes that are used commonly:

http://www.greenend.org.uk/rjk/2000/05/21/smtp-replies.html
0
 
LVL 25

Assisted Solution

by:kieran_b
kieran_b earned 500 total points
ID: 21774672
Let me try translating;

Them: EHLO
Hi, I'm mail.otherdomain.com
You: 250
Hey

Them: MAIL
I have MAIL FROM joe@otherdomain.com
You: 250
OK

Them: RCPT
The ReCiPienT I am sending this TO is steve@yourdomain.com
You: 250
No problems, Steve is here

Them: DATA
Here is the DATA of the message for Steve
You: 503
No worries, let me know when you are done

Them: QUIT
All done - bye
You: 240
See ya

You have been watching, SMTP Theatre
0
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 21778815
LOL - that's great Kieran! You should rent yourself out as a technospeak interpreter ;-)
0
Nothing ever in the clear!

This technical paper will help you implement VMware’s VM encryption as well as implement Veeam encryption which together will achieve the nothing ever in the clear goal. If a bad guy steals VMs, backups or traffic they get nothing.

 
LVL 1

Author Closing Comment

by:ithawaii
ID: 31466711
excellent!!! thanks hypercat and kieran
0
 
LVL 25

Expert Comment

by:kieran_b
ID: 21782864
I have been toying with the idea of SMTP theatre for a while - particularly when explaining SPF or RBLs, just trying to think of the appropriate media :)
0
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 21782912
How about stop motion with claymation, like wallace and grommit? I see the Black Spamcloud hanging over the house pelting it with nasties and Wallace will invent the SPF rainbow umbrella....OK - we're supposed to stop this now, not appropriate for the serious world of EE...
0
 
LVL 25

Expert Comment

by:kieran_b
ID: 21782926
Damn, you just gave me _another_ idea for media!

thanks for closing ithawaii, hope we helped.

Kieran
0

Featured Post

Learn Veeam advantages over legacy backup

Every day, more and more legacy backup customers switch to Veeam. Technologies designed for the client-server era cannot restore any IT service running in the hybrid cloud within seconds. Learn top Veeam advantages over legacy backup and get Veeam for the price of your renewal

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
If something goes wrong with Exchange, your IT resources are in trouble.All Exchange server migration processes are not designed to be identical and though migrating email from on-premises Exchange mailbox to Cloud’s Office 365 is relatively simple…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question