>So that begs the question: What evidence do you have suggesting that spam >is being sent from your server?
logs of my Imail server show attempts to connect to my outgoing mail server to send mail to a bogus address
0040224 000308 127.0.0.1 SMTP (2888) 220 cshore.com - ESMTP - (IPAD 2.5/64 ) - ATTN: UCE trespassers will be pursued.
In this case, you'll need to go back to the SMTP log file entry with "(2888)" in it that has the queue file name, then search the log file for the first entry with the queue file name (search minus the first character and extension, so "1234567" for "C:\IMail\Q1234567.SMD").
That way, you can find the source.
20040224 000308 127.0.0.1 SMTP (2888) >MAIL FROM:<> 20040224 000308 127.0.0.1 SMTP (2888) >RCPT To:<[EMAIL PROTECTED]>
Recipient address rejected: Domain not found
Given that this looks suspiciously like a bounce message ("MAIL FROM:<>") and is being sent to a non-existent domain, I'm guessing that this is spam that is going to a non-existent account on your server, and is being bounced.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
