I'm trying to figure out some spam issues we are having with our server (emails we send out are getting rejected as spam). I have a few questions regarding what I'm seeing in the logs.
For argument sake, our server's IP is "22.214.171.124".
2012-05-22 02:33:21 H=(126.96.36.199) [188.8.131.52] rejected MAIL <email@example.com>: Access denied - Invalid HELO name (See RFC2821 4.1.3)
Does this mean that my server rejected INCOMING mail from 184.108.40.206 because THEY had an invalid HELO name? Or does it mean that 220.127.116.11 rejected OUTGOING mail from my server because MY server has an invalid HELO name?
2012-05-22 08:45:20 H=(smtp.lanxxxxxxuys.com) [50.xxx.127.244] Warning: "Increment Connection Ratelimit - (smtp.laxxxxxxxuys.com) [50.xxx.127.244] because of RBL match"
2012-05-22 08:45:20 H=(smtp.lanxxxxxxxs.com) [50.xxx.127.244] F=<firstname.lastname@example.org> rejected RCPT <email@example.com>: "JunkMail rejected - (smtp.landbxxxxuys.com) [50.xxx.127.244] is in an RBL, see http://www.spamhaus.org/sbl/query/SBLCSS"
Does this mean that my server saw incoming mail from 18.104.22.168 and then ratelimited, and then rejected it due to THEM being on a blacklist? Or does this mean that my server tried to SEND mail to 22.214.171.124 and WE were ratelimited and then rejected for being on a blacklist?
Is there any straightforward way to search the logs for errors related to outbound emails that are bouncing back due to spam? Is there something I can GREP for?
I'm looking at /var/log/exim_mainlog. Is there somewhere else I should be looking too? Or something in cPanel WHM I can use to help make this process easier?