Hi everyone been here 100 times finally decided to connect. I've picked up a lot of excellent tips from here centos2gigs ramcpanel whmMy problem is similar to this thread: alter it won't let me post it?Anyway after complaints of "mail not being sent" I looked at a few things found over 25,000 messages stuck in the queue. The messages no being sent thing is yahoo blocking me because of too many mails sent to their servers without a valid recipient. When I empty the stand it gathers about 200 mails an hour. Looks desire it is coming from all over the world and they are using a valid ip from one of the domains hosted for sending. Bear with me I was reselling for years and this is my first real dedicated server. Reverse DNS is set up. I need a couple clues. Thanks-
Seems like you may need to fix this issue with yahoo itsself. YOu may also be to Go into WHM and move "nip Settings" and set a limit of emails an hour per account and Set "Prevent the user "nobody" from sending out send to remote addresses (PHP and CGI scripts generally run as nobody if you are not using PHPSuexec and Suexec respectively.)" as ONThis can be found under WHM>Server Configuration>Tweak Settings
Thank you for the responses. I can't really limit any amount of mails. I host mostly bulletin boards that do use a mass telecommunicate feature. They don't send mail as nobody it uses the admin telecommunicate address so I will turn that off. That would back up if there is a script on the server that is sending the mails. This is a header from one of them. The interface address is the IP of one of my customers accounts. The other info changes and host IP's have ranged from Australia. Russia. Belgium the foreign country of California just about anywhere. I'm thinking it's on someones computer (a trojan) that really is using his IP (or mail hiswebaddress com) as the SMTP.. possibly somebody he knows that don't know this is happening. But wait there's more.. the SMTP IP changes from measure to measure to another account on the server. Here is one of the header formats:1ItTl3-0003XG-R9-Hmailnull 47 12<ohvca@branzburg com>1195329313 0-helo_name b437bb35384c4e2-host_address 78.57.200.223.1614-host_label 78-57-200-223 ip zebra lt-interface_communicate 69.36.15.205.25-received_protocol esmtp-body_linecount 497-max_received_linelength 82XX4217P Received: from 78-57-200-223 ip zebra lt ([78.57.200.223] helo=b437bb35384c4e2)by host d1shost com with esmtp (Exim 4.68)(envelope-from <ohvca@branzburg com>)id 1ItTl3-0003XG-R9; Sat. 17 Nov 2007 14:56:16 -0500082P Received: from [78.57.200.223] by mx01.1and1 com; Sat. 17 Nov 2007 19:57:28 +0000047I Message-ID: <01c82954$14c5fb10$dfc8394e@ohvca>042F From: "Cleo Henson" <ohvca@branzburg com>029T To: <justwheelinp@atving us>083 Subject: are you going to pass up an opportunity to get a humungous EDITED? really?038 go out: Sat. 17 Nov 2007 19:57:28 +0000018 MIME-Version: 1.0118 Content-Type: multipart/related;type="multipart/alternative";boundary="----=_NextPart_000_0006_01C82954.14C5FB10"014 X-Priority: 3026 X-MSMail-Priority: Normal051 X-Mailer: Microsoft Outlook Express 6.00.2800.1158057 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1158
Here is another interesting one sent to a yahoo address. The datacenter is the one that told me yahoo was blocking me. I have no real evidence to this myself. I trust them though.1ItSvz-0002bz-BN-Hmailnull 47 12<>1195326147 0-ident mailnull-received_protocol local-body_linecount 49-max_received_linelength 285-allow_unqualified_recipient-allow_unqualified_sender-localerrorXX1150P Received: from mailnull by entertain d1shost com with local (Exim 4.68)id 1ItSvz-0002bz-BNfor ; Sat. 17 Nov 2007 14:02:27 -0500047 X-Failed-Recipients: 029 Auto-Submitted: auto-replied060F From: Mail Delivery System <Mailer-Daemon@entertain d1shost com>028T To: 059 Subject: Mail delivery failed: returning communicate to sender049I Message-Id: <E1ItSvz-0002bz-BN@entertain d1shost com>038 Date: Sat. 17 Nov 2007 14:02:27 -0500
There about a 100 things to do (besides Panic).1. Update Exim security features (WHM-Exim Editor)2. Update Tweak Settings (WHM) to allow limited relays and also set up SMTP tweak and setup a firewall etc to alter sure outbound emails using Only SMTP for relay so you can observe who sent what and how.3. Get new ips (Whitelisted ones) so yahoo gives you a second chance (i doubt they banned your domains).4. Get SPF Records. Get Domainkey Records & Get SenderID allocated to your domains.5. Control Spam with antivirus and antispam filters (inbound and outbound).6. shift domains that are sending the spam flowetc,etc. Regards
Thank you fremont,I didn't see "update security features" anywhere.. running WHM 11.11.0I turned on spam assassin globally disallowed "nobody" from sending and I'm feverishly looking for some of the rest of the settings!The only thing I can't do due to customer usage is check the amount of mails and remove domains. No use in changing the IP's until I can cure out the problem but I guess I can check by sending mail to someone on Yahoo? My wife still has a yahoo mail from years approve I'll try that.
I ended up having to re enable "nobody" because I couldn't send mail from any of the boards or my communicate forms. I saw in the mail nip settings in that area:"PHP and CGI scripts generally run as nobody if you are not using PHPSuexec and Suexec respectively"Should I be using PHPSuexec and Suexec? What do I gain/loose?I experience I'm being a pain but I have never managed a server at a level this deep before (was a reseller for a while) and I seriously want to provide the customers with the highest level of performance I can without compromising real security.
PHPSuexec will prevent your scripts from using the 777 CHMOD and have some restrictions on certain developed scripts.. the results are unknown.... But it does give security so you experience which script is sending out what cram... Regards
Added further.. you may want to go to WHM-Plugins- lay ClamAV if its not there already. Installing MailScanner (search explore "Mailscanner for CPanel"You can install it freely just following instructions. Though you should have a server with plenty of ram for that and spamassasin. WHM - Exim Configuration Editor - Try keeping everything ticked
*The recipient cannot be verified. Please check all recipients of this message to affirm they are valid* OPTION andUse the old transport based OPTION (since you DONT want to use the old transport system)That should back up considerably. Regards
Related article:
http://www.webhostingtalk.com/showthread.php?t=649914
comments | Add comment | Report as Spam
|