Avatar of Frosty555
Frosty555
Flag for Canada asked on

Exim log questions

I'm trying to figure out some spam issues we are having with our server (emails we send out are getting rejected as spam). I have a few questions regarding what I'm seeing in the logs.

For argument sake, our server's IP is "123.123.123.123".


Example 1

2012-05-22 02:33:21 H=(123.123.123.123) [117.194.210.132] rejected MAIL <somebody@asdfasdf.be>: Access denied - Invalid HELO name (See RFC2821 4.1.3)

Open in new window


Does this mean that my server rejected INCOMING mail from 117.194.210.132 because THEY had an invalid HELO name? Or does it mean that 117.194.210.132 rejected OUTGOING mail from my server because MY server has an invalid HELO name?

Example 2

2012-05-22 08:45:20 H=(smtp.lanxxxxxxuys.com) [50.xxx.127.244] Warning: "Increment Connection Ratelimit - (smtp.laxxxxxxxuys.com) [50.xxx.127.244] because of RBL match"
2012-05-22 08:45:20 H=(smtp.lanxxxxxxxs.com) [50.xxx.127.244] F=<wizstar@laxxxxxxxuys.com> rejected RCPT <xxx@torxxxxxxa.com>: "JunkMail rejected - (smtp.landbxxxxuys.com) [50.xxx.127.244] is in an RBL, see http://www.spamhaus.org/sbl/query/SBLCSS"

Open in new window


Does this mean that my server saw incoming mail from 50.123.127.244 and then ratelimited, and then rejected it due to THEM being on a blacklist?  Or does this mean that my server tried to SEND mail to 50.123.127.244 and WE were ratelimited and then rejected for being on a blacklist?


Additionally...

Is there any straightforward way to search the logs for errors related to outbound emails that are bouncing back due to spam? Is there something I can GREP for?

I'm looking at /var/log/exim_mainlog. Is there somewhere else I should be looking too? Or something in cPanel WHM I can use to help make this process easier?
Email ServersLinuxLinux Security

Avatar of undefined
Last Comment
arnold

8/22/2022 - Mon
arnold

123.123.123.123 is seen as an ip on the remote side that does not match the ip from which the request is comming.

The second part suggests that a mail server IP is blacklisted by spamhaus for spamming.


There are log analyzer/crunchers
http://forums.cpanel.net/f43/exim-log-viewer-analyzer-97425.html
http://www.sawmill.net/formats/exim.html

http://www.exim.org/exim-html-3.20/doc/html/spec_51.html
Frosty555

ASKER
Arnold - can you be more specific? For the two log entries above, is the problem with my server sending outgoing mail, or with an outside mailserver sending incoming mail?
ASKER CERTIFIED SOLUTION
arnold

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Frosty555

ASKER
Okay I think I understand now.

In the above example, I own "123.123.123.123", no other IP addresses or hostnames are under my control (they are all external sources). We don't use a smarthost or gateway, mail is delivered and received directly.

So the first error is an incoming mailserver that specified an invalid HELO (in this case they tried to use my own server's IP as the HELO, clearly spam)

The second error is the incoming mailserver being on a blacklist, and my mailserver rejected it.

So neither of these things are failures on my part.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
arnold

Correct.