Solved

how to read SMTP logs

Posted on 2008-06-12
7
2,840 Views
Last Modified: 2010-04-21
Hi, i've been getting huge logs everyday. Here's part of the logs:
...
19:00:20 189.36.201.18 MAIL - 250
19:00:20 189.36.201.18 RCPT - 550
19:00:20 189.36.201.18 DATA - 503
19:00:20 92.1.36.248 DATA - 250
19:00:20 92.1.36.248 QUIT - 240
19:00:20 189.36.201.18 QUIT - 240
19:00:21 84.143.210.214 EHLO - 250
19:00:21 84.143.210.214 MAIL - 250
19:00:21 84.143.210.214 RCPT - 550
19:00:21 84.143.210.214 DATA - 503
19:00:21 84.143.210.214 QUIT - 240
19:00:24 85.105.72.184 EHLO - 250
19:00:24 201.221.149.111 HELO - 250
19:00:24 201.221.149.111 MAIL - 250
19:00:24 78.166.33.247 EHLO - 250
19:00:24 85.105.72.184 MAIL - 250
19:00:24 85.105.72.184 RCPT - 550
19:00:24 85.105.72.184 DATA - 503
19:00:24 201.221.149.111 RCPT - 550
19:00:24 201.221.149.111 QUIT - 240
19:00:24 85.105.72.184 QUIT - 240
19:00:24 78.166.33.247 MAIL - 250
19:00:24 78.166.33.247 RCPT - 550
19:00:24 78.166.33.247 DATA - 503
19:00:27 78.166.33.247 QUIT - 240
19:00:31 83.24.126.5 EHLO - 250
19:00:32 83.24.126.5 MAIL - 250
19:00:32 83.24.126.5 RCPT - 250
19:00:32 83.24.126.5 RCPT - 250
19:00:34 216.117.214.242 HELO - 250
19:00:34 83.24.126.5 DATA - 250
19:00:34 216.117.214.242 MAIL - 250
19:00:34 216.117.214.242 RCPT - 250
19:00:36 83.24.126.5 QUIT - 240
19:00:36 216.117.214.242 DATA - 250
19:00:36 189.34.69.94 EHLO - 250
19:00:36 189.34.69.94 MAIL - 250
19:00:37 200.121.134.100 HELO - 250
19:00:37 200.121.134.100 MAIL - 250
19:00:37 189.34.69.94 RCPT - 550
19:00:37 200.121.134.100 RCPT - 550
19:00:37 189.34.69.94 QUIT - 240
19:00:37 200.121.134.100 QUIT - 240
19:00:40 86.13.6.177 EHLO - 250
19:00:40 86.13.6.177 MAIL - 250
19:00:40 86.13.6.177 RCPT - 250
19:00:42 86.13.6.177 DATA - 250
19:00:42 86.13.6.177 QUIT - 240
...
does this look normal? also, please help me to understand EHLO, MAIL, RCPT, DATA, QUIT commands. what do those numbers (250, 240, 550..) mean?

Thanks,
0
Comment
Question by:ithawaii
  • 3
  • 3
7 Comments
 
LVL 38

Accepted Solution

by:
Hypercat (Deb) earned 125 total points
ID: 21773025
This looks perfectly normal for an SMTP log.  If you're using Exchange, you can get a bit more information in the log by enabling NSCA (? those are the initials, but I can't remember if it's NSCA or NCSA) log format in the properties of the SMTP virtual server.  

EHLO, MAIL, etc., are simply the commands that are sent between SMTP servers to process the mail.  Here's a quick overview of those commands and some basic info on those return codes that are used commonly:

http://www.greenend.org.uk/rjk/2000/05/21/smtp-replies.html
0
 
LVL 25

Assisted Solution

by:kieran_b
kieran_b earned 125 total points
ID: 21774672
Let me try translating;

Them: EHLO
Hi, I'm mail.otherdomain.com
You: 250
Hey

Them: MAIL
I have MAIL FROM joe@otherdomain.com
You: 250
OK

Them: RCPT
The ReCiPienT I am sending this TO is steve@yourdomain.com
You: 250
No problems, Steve is here

Them: DATA
Here is the DATA of the message for Steve
You: 503
No worries, let me know when you are done

Them: QUIT
All done - bye
You: 240
See ya

You have been watching, SMTP Theatre
0
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 21778815
LOL - that's great Kieran! You should rent yourself out as a technospeak interpreter ;-)
0
Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

 
LVL 1

Author Closing Comment

by:ithawaii
ID: 31466711
excellent!!! thanks hypercat and kieran
0
 
LVL 25

Expert Comment

by:kieran_b
ID: 21782864
I have been toying with the idea of SMTP theatre for a while - particularly when explaining SPF or RBLs, just trying to think of the appropriate media :)
0
 
LVL 38

Expert Comment

by:Hypercat (Deb)
ID: 21782912
How about stop motion with claymation, like wallace and grommit? I see the Black Spamcloud hanging over the house pelting it with nasties and Wallace will invent the SPF rainbow umbrella....OK - we're supposed to stop this now, not appropriate for the serious world of EE...
0
 
LVL 25

Expert Comment

by:kieran_b
ID: 21782926
Damn, you just gave me _another_ idea for media!

thanks for closing ithawaii, hope we helped.

Kieran
0

Featured Post

Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

Join & Write a Comment

We are happy to announce a brand new addition to our line of acclaimed email signature management products – CodeTwo Email Signatures for Office 365.
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now