Why is This message being relayed?

I have my relay settings to only accept 127.0.0.0/8 and 192.168.88.0/24, so how did this message get through?
Dec  5 19:55:34 mycompany postfix/smtp[24709]: 6852E91833E: to=<[email protected]>, relay=cluster4.us.messagelabs.com[216.82.250.19]:25, delay=256, delays=0.01/0.01/69/186, dsn=2.0.0, status=sent (250 ok 1323136534 qp 15594 server-5.tower-87.messagelabs.com!1323136279!47765957!1)
This weekend I found that someone was sending thousands of spam messages through my server even though I use authentication.

You need to look further back in your logs for the answer.
Dec  5 19:55:34 mycompany postfix/smtp[24709]: 6852E91833E: to=<[email protected]>, relay=cluster4.us.messagelabs.com[216.82.250.19]:25, delay=256, delays=0.01/0.01/69/186, dsn=2.0.0, status=sent (250 ok 1323136534 qp 15594 server-5.tower-87.messagelabs.com!1323136279!47765957!1)
The 'Accept SNMP relays...' option only relates to blind/untrusted relaying - if a connection comes from these IP addresses then accept the message, but that's not the only method that postfix will allow. If a user authenticates against the server (using one of the authentication methods you've selected) then they can also relay mail, regardless of their IP address.
Therefore, my first guess would be that someone's guessed a valid username/password on your server and is therefore using an authenticated connection. This can happen easily if users don't have strong passwords.
You'll need to track back through your logs to find where this message was injected into the mail queue.  Start off by searching for that message ID (6852E91833E) in the logs, or look back in time (this message has been in the queue for 256 seconds. Eventually that will tell you where it came from, and what user authenticated the connection. Then shut down that account until you can change that user's password and educate them on how to choose effective passwords.

Similar Messages

  • Why does this message keep appearing when i try to instal windows 7 through bootcamp? - "something went wrong and the USB cannot be configured for the installation"

    Why does this message keep appearing when Itry to instal windows 7 through bootcamp? - "Your bootable USB drive could not be created. An error occurred while copying the Windows installation files."

    Found a solution!
    Follow the extended version of these directions here:
    https://discussions.apple.com/docs/DOC-3581
    Worked like a charm!

  • TS2755 Why are SMS messages being undelivered?

    Why are SMS messages being undelivered?

    some detail?  to you - from you?  to another i message user?   the pad is not a phone, and will only message to other i message users.

  • Why was this message

    hi .
    why was this message
    whate to software upate - err - none of the selected updates could be installed ?
    Why was this error message
    or you don't have permission ?

    hi
    hanks I'm going to help you? Thank y'all

  • When  iTunes is not connected  to internet it keeps on displaying a message that "iTunes couldn't connect to the store" whenever i open it. How to stop this message being displayed?

    When  iTunes is not connected  to internet it keeps on displaying a message that "iTunes couldn't connect to the store" whenever i open it. How to stop this message being displayed?

    guyz... do look into this...

  • HT201303 Why show this message in games application? "Please contact itunes support to complete this transaction"

    Why show this message in games application? "Please contact itunes support to complete this transaction"

    Click here and request assistance.
    (70672)

  • Why are my messages being sent through email rather than iMessage?

    Why are my messages being sent as email rather than iMessage?

    Not being sent as email - shown as being sent from an email address because you have selected to start new iMessage conversations from your Apple ID email address on your iPhone.
    When registering an iPhone with iMessage, the phone number along with your Apple ID email address is registered with it.
    Go to Settings > Messages > Send & Receive > Start New Conversations From - select your iPhone's phone number.

  • Why is this message showing up on ALL sites I want to use?

    when I go to bookmarks or click on web address this message always pop up. I can't get this to stop even when I dis able the yahoo from being active. So how do I get this fixed or repaired?
    Server not found Firefox can't find the server at signin.ebay.com. Check the address for typing errors such as ww.example.com instead of www.example.com If you are unable to load any pages, check your computer's network connection. If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the Web.

    .4 gig of other is iOS and normal. Operating system has
    to be stored somewhere. If Other starts to exceed 1 gig,
    then restore to get it back down.

  • Why doese this message appear"Your current security settings don't allow this file to be downloaded"

    no one helped me in this post, why Adobe Company doesn't have an answer to my question?
    please, i need your help
    "Dear Helpers,
    We used to use adobe reader 6 in our foundation to view pdf files on the internet, and since we had upgraded to the new version of adobe (to adobe 7 and X) the browser (IE 8) couldn't open any pdf file, and always returning this message: "Your current security settings do not allow this file to be downloaded".
    we have a group policy that doesn't allow the users to download files from the internet, but when we were using adobe reader 6, this message have not occurred while opening pdf file online, and everything was fine,"
    Please help me in this issue
    Thanks in advance
    Kind regards

    Hi eleanora27327971,
    I don't think there's a problem with the PDF file that you converted--that sounds more like a browser setting. What browser are you using? Are you able to download files from other websites? Or, are you able to log in to https://cloud.acrobat.com using a different web browser, and download from that browser? (See System requirements | Acrobat.com for a list of supported web browsers.)
    Tell me a bit more about your setup (what operating system, browser and version), and I should be able to point you in the right direction.
    Best,
    Sara

  • Why does this message appear: The item you've requested is not currently available in the U.S. store. When I open iTunes?

    For no discernible reason when I opened iTunes and selected the iTunes Store, this message appeared:
    The item you've requested is not currently available in the U.S. store.
    rebooted computer. Flushed iTunes cache. I see lots of references to this in older posts (2012 and earlier) but nothing recent.

    There are several posts about this in the last 15 minutes
    Look around. 
    Be patient, itunes will correct their issue.

  • Why does this message appear? "To display this page, Firefox must send information that will repeat any action (such as a search or order confirmation) that was performed earlier."

    I am in ebay and this message keeps coming up when I try to freshen the page.

    same issue. started happening when I upgraded to the latest FF (3.6.3). very annoying. happens when i use my back button or click refresh.

  • HT5129 Why does this message appear over and over again?

    This message appears everytime I try to do something in iPhoto and freezes everything else.  Can I stop it from appearing?

    Click on the More Info button, go to iPhoto's Accounts preference pane and delete the MobileMe account. Next to go the Sustem/MobileMe preference pane and log out of MMe.  That will stop those messages.
    OT

  • Why are text messages being received as gmail addresses?

    In the last week, I began receiving text messages from my friends that are being sent from their "gmail" address.  Therefore, it seems to replace the other contact that I had in the phone.  Has anyone else experienced this? Thank you

    This has worked for many to solve this problem:
    Open the phone and dial *228. This is a Verizon over-the-air programming number.
    When the system answer press 1 for "Program or activate your phone"
    Wait for the call to disconnect. You should get a prompt stating "Settings updated."
    Double tap the Home button to bring up the recently used apps list at the bottom.  Locate the Phone, Message, and Contacts apps, swiping if necessary, and press and hold until they jiggle then press the red minus sign to stop them.
    Wait a 3-5 minutes.
    Open the Message App to see if they're fixed.

  • What is the story on mac vulnerability? Is it serious or not serious?  If not serious, why is this not being explained?  If serious, why are Mac users not being informed of the risk?

    what is the story on mac vulnerability? Is it serious or not serious?
    If serious, why are we not kept informed
    If not serious, why is some much anxiety being created?

    IMO, it is being greatly over-blown in the media and online.
    Man in the middle attacks require the hacker to be connected to the same intranet network that your device is.  Even if they are, unless you go to a secure site and use personal data (like passcodes) they get nothing from stealing your data stream.
    If you are at your home, on your own secured intranet, then you really have virtually nothing to fear (as long as your own home network is secured and not wide open to anybody within range).  If you routinely use a VPN connection when on public wifi, again, you are fine.  Or if you use FireFox, Chrome or another browser that implements its own SSL security, then you are fine.
    The fact is, that even for those in a particular situation that is vulnerable to such an attack, most are not actually under any such attack - it is not nearly as rampant as the recent hype would have it seem to be.

  • Configure Keyboard Layout - why is this screen being displayed?

    Hello,
    I have a problem. I want the Solaris 10 installation to be hands-off. I modified the sysidcfg file, everything wors fine, but unfortunately after the execution of the finish script (at the end of the installation) this screen is being displayed:
    q Configure Keyboard Layout qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
      Please specify the keyboard layout from the list below.
      > To make a selection, use the arrow keys to highlight the option and
        press Return to mark it [X].
          Keyboard Layout
          qqqqqqqqqqqqqqqqqqqqqqqqq
      ^   [ ] Slovenian
      x   [ ] Slovakian
      x   [ ] Spanish
      x   [ ] Swedish
      x   [ ] Swiss-French
      x   [ ] Swiss-German
      x   [ ] Taiwanese
      x   [ ] TurkishQ
      x   [ ] TurkishF
      x   [ ] UK-English
      -   [X] US-English
    qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
        F2_Continue    F6_HelpWhat is the reason of that?
    Thanks in advance.
    Regards,
    Przemek

    Anybody? My last day to return is tomorrow, but I'd be willing to try once more if I just happened to get two faulty phones.

Maybe you are looking for