>I have a question that you guys may be able to help me out with.  I am 
>looking at my log files for my IMAIL server.  I realized that I have no 
>idea how to tell if someone used my server to relay through or even if we 
>got spammed (incoming).  What could I look for in the log files that would 
>indicate any suspicious activities?  If someone could give me an example 
>from there log file of what something like this would look like I would 
>appreciate it much.

It is impossible to tell from the log files if you received incoming spam.

The usual giveaway for hijacking -- where someone relays their spam through 
your server -- is that the log file will increase tremendously.  One way to 
quickly search the logs is to type 'FIND "RCPT TO:" SYS####.TXT' from a 
command prompt.  This will show all of the people that E-mail was going 
to.  In the case of a hijacking, you will see *lots* of E-mails going to 
similar addresses ([EMAIL PROTECTED], [EMAIL PROTECTED], 
[EMAIL PROTECTED], etc.).

You could use our free "Domain Lister" tool at http://www.declude.com/tools 
, which would likely show very unusual results if a spammer hijacked your 
server.

                                                         -Scott

Declude: Anti-spam and Anti-virus solutions for IMail.  http://www.declude.com



Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to