Re: Are people trying to relay mail through my system?

2023-09-26 Thread Curt
On 2023-09-25, Greg Wooledge wrote: > > The preferred policy nowadays is to perform all possible checks *during* > the initial SMTP conversation. If a message fails to meet acceptance > criteria for any reason, it should be rejected during that initial > conversation. Generating a bounce

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Rick Macdonald
On 9/25/23 17:11, Greg Wooledge wrote: On Mon, Sep 25, 2023 at 04:49:52PM -0600, Rick Macdonald wrote: Lastly, do I understand correctly that the root of this whole issue is simply misformed headers in the original spam mail that I receive at my Dreamhost account? Oh, and does all this lead

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Greg Wooledge
On Mon, Sep 25, 2023 at 04:49:52PM -0600, Rick Macdonald wrote: > Lastly, do I understand correctly that the root of this whole issue is > simply misformed headers in the original spam mail that I receive at my > Dreamhost account? Oh, and does all this lead to the "Frozen Message" emails > I

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Rick Macdonald
On 9/25/23 14:58, Rick Macdonald wrote: Some of the mail in the queue is up to 4 days old. I'm going to clear it all out to see what new arrives in this state. I've made a bit of progress. First, I deleted the almost 6000 messages in the mail queue: # mailq | grep 1q | cut -c11-26 | xargs

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Rick Macdonald
On 9/25/23 14:25, Andy Smith wrote: Hi Rick, Your system has rejected a spam email, not because it worked out it was spam, but because it was syntactically invalid. That's good, but unfortunately your system decided to helpfully tell the (spam) sender what had happened, by trying to send this

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Rick Macdonald
On 9/25/23 12:42, Michael Kjörling wrote: The following address(es) failed: rickm@localhost    SMTP error: 550 header syntax So something running on your local system almost certainly tried to send mail to either "rickm" or "rickm@localhost", and that triggered queuing the non-delivery

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Andy Smith
On Mon, Sep 25, 2023 at 08:25:48PM +, Andy Smith wrote: > You can remove them from your mail queue with: > > # eim4 -Mrm typo of "exim4" -- https://bitfolk.com/ -- No-nonsense VPS hosting

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Andy Smith
Hi Rick, Your system has rejected a spam email, not because it worked out it was spam, but because it was syntactically invalid. That's good, but unfortunately your system decided to helpfully tell the (spam) sender what had happened, by trying to send this bounce message back: On Mon, Sep 25,

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Michael Kjörling
On 25 Sep 2023 12:24 -0600, from rickm...@shaw.ca (Rick Macdonald): > # exim4 -Mvl 1qkOYj-001Hnf-2V > > 2023-09-24 06:50:01 Received from <> H=(timshel) [::1] P=smtp S=2662 ::1 is IPv6 localhost. So whatever caused that particular message to be sent is almost certainly local to your system.

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Rick Macdonald
On 9/25/23 08:29, Michael Kjörling wrote: On 24 Sep 2023 20:58 -0600, from rickm...@shaw.ca (Rick Macdonald): My /var/log/.exim4/log file is flooded with messages such as shown below. I'm not trying to send mail to any of those .co or .com addresses. I use my ISP (shaw.ca cable provider) as a

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Rick Macdonald
On 9/25/23 10:03, Andy Smith wrote: Hi Rick, On Sun, Sep 24, 2023 at 08:58:04PM -0600, Rick Macdonald wrote: 2023-09-24 20:48:37 1qkRDH-001Zqh-1Z == 6626-879-8427-40-rickm=timshel...@mail.purecuresol.co R=smarthost T=remote_smtp_smarthost defer (-54): retry time not reached for any host for

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Andy Smith
Hi Rick, On Sun, Sep 24, 2023 at 08:58:04PM -0600, Rick Macdonald wrote: > 2023-09-24 20:48:37 1qkRDH-001Zqh-1Z == > 6626-879-8427-40-rickm=timshel...@mail.purecuresol.co R=smarthost > T=remote_smtp_smarthost defer (-54): retry time not reached for any host for > 'mail.purecuresol.co' There

Re: Are people trying to relay mail through my system?

2023-09-25 Thread Michael Kjörling
On 24 Sep 2023 20:58 -0600, from rickm...@shaw.ca (Rick Macdonald): > My /var/log/.exim4/log file is flooded with messages such as shown below. > I'm not trying to send mail to any of those .co or .com addresses. I use my > ISP (shaw.ca cable provider) as a smarthost. > > Are people trying to use