Hi,
this is postfix 3.8-20220325 (FreeBSD port postfix-current) on FreeBSD
13.1-STABLE.
I do find comparable entries in my logfiles that I do not understand, honestly,
like:
Apr 20 06:36:23 <mail.info> mail.lan postfix/postscreen[74803]: CONNECT from
[1.2.3.4]:45534 to [10.1.1.1]:25
Apr 20 06:36:23 <mail.info> mail.lan postfix/dnsblog[74805]: addr 1.2.3.4
listed by domain zen.spamhaus.org as 127.0.0.4
Apr 20 06:36:23 <mail.info> mail.lan postfix/dnsblog[74807]: addr 1.2.3.4
listed by domain bl.mailspike.net as 127.0.0.2
Apr 20 06:36:24 <mail.info> mail.lan postfix/postscreen[74803]: PREGREET 24
after 1.2 from [1.2.3.4]:45534: EHLO cU6aOdPNYyde1.net\r\n
Apr 20 06:36:24 <mail.info> mail.lan postfix/postscreen[74803]: DNSBL rank 2
for [1.2.3.4]:45534
Apr 20 06:36:25 <mail.info> mail.lan postfix/tlsproxy[74809]: CONNECT from
[1.2.3.4]:45534
Apr 20 06:36:26 <mail.info> mail.lan postfix/tlsproxy[74809]: Anonymous TLS
connection established from [1.2.3.4]:45534: TLSv1.2 with cipher
ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Apr 20 06:36:27 <mail.info> mail.lan postfix/postscreen[74803]: CONNECT from
[1.2.3.4]:49074 to [10.1.1.1]:25
Apr 20 06:36:27 <mail.info> mail.lan postfix/dnsblog[74804]: addr 1.2.3.4
listed by domain bl.mailspike.net as 127.0.0.2
Apr 20 06:36:27 <mail.info> mail.lan postfix/dnsblog[74805]: addr 1.2.3.4
listed by domain zen.spamhaus.org as 127.0.0.4
Apr 20 06:36:27 <mail.info> mail.lan postfix/postscreen[74803]: PREGREET 429
after 0 from [1.2.3.4]:49074:
\026\003\003\001\250\001\000\001\244\003\003\327j\316\343\332\272\233\200\236\017\243`\342e\217\204\
Apr 20 06:36:27 <mail.info> mail.lan postfix/postscreen[74803]: DNSBL rank 2
for [1.2.3.4]:49074
Apr 20 06:36:27 <mail.info> mail.lan postfix/postscreen[74803]: BARE NEWLINE
from [1.2.3.4]:49074 after
\026\003\003\001\250\001\000\001\244\003\003\327j\316\343\332\272\233\200\236\017\243`\342e\217\204\3615\300\324\236\331\262
\000,w3\246u\263k\375
\247A\323Db\025\326r\224N\260$\233\t\3560\223\035\331\v\266\355d\270bR\323\215@\026\342\253\000\212\000\026\0003\000g\300\236\300\242\000\236\0009\000k\300\237\300\243\000\237
Apr 20 06:36:27 <kern.info> kaan-bock kernel: pid 74803 (postscreen), jid 4,
uid 125: exited on signal 11
Apr 20 06:36:27 <mail.warn> mail.lan postfix/master[7359]: warning: process
/usr/local/libexec/postfix/postscreen pid 74803 killed by signal 11
Connecting IPs differ. But all those entries follow the scheme above, first …
BARE NEWLINE followed by \123\…
and then a …
signal 11
Here are my questions:
What do those \entries after that BARE NEWLINE mean?
Is this something to worry about?
Thanks in advance and regards,
Michael