>I have a question that you guys may be able to help me out with. I am
>looking at my log files for my IMAIL server. I realized that I have no
>idea how to tell if someone used my server to relay through or even if we
>got spammed (incoming). What could I look for in the log files that would
>indicate any suspicious activities? If someone could give me an example
>from there log file of what something like this would look like I would
>appreciate it much.
It is impossible to tell from the log files if you received incoming spam.
The usual giveaway for hijacking -- where someone relays their spam through
your server -- is that the log file will increase tremendously. One way to
quickly search the logs is to type 'FIND "RCPT TO:" SYS####.TXT' from a
command prompt. This will show all of the people that E-mail was going
to. In the case of a hijacking, you will see *lots* of E-mails going to
similar addresses ([EMAIL PROTECTED], [EMAIL PROTECTED],
[EMAIL PROTECTED], etc.).
You could use our free "Domain Lister" tool at http://www.declude.com/tools
, which would likely show very unusual results if a spammer hijacked your
server.
-Scott
Declude: Anti-spam and Anti-virus solutions for IMail. http://www.declude.com
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/