How about one like "207.0.0.0 224.0.0.0", which would allow 210.x.x.x to send mail? Are there any IP ranges that do not include "255." as the first byte in the network mask?Makes sense to us here but we have triple checked our allowed IP's and we do not even have one that starts with 210.x.x.x
On that first line of our log...am I right in thinking that the 'suspect" IP is sending though our server but our server sees it as a "good" address?? the 207 IP is an IP assigned to a domain on our server. We are very suspect to this as our issue.
Actually, this isn't a problem:
>01:16 20:59 SMTPD(009F013C) [207.51.128.113] connect 210.21.108.189 port 51894This log file entry just means that 210.21.108.189 (the spammer) connected to your IMail server at 207.51.128.113.
IMail definitely sees the IP address of the spammer as 210.21.108.189, and is definitely allowing it to send mail without authenticating, which would lead me to believe an odd netmask is the issue (such as 207.0.0.0 224.0.0.0).
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches both viruses and vulnerabilities in E-mail, with no annual licensing fees.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
