[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] ActiveMonitor, DNS Errors & Email Bounces?



CobaltUsers-

First time I've posted to this list, although I've been a member for, oh... around a year now. I have *greatly* appreciated all the info! Thank you all!

We are suddenly experiencing the following log errors on a Raq3i [pls. see below -- all public DNs & IPs expunged to protect the innocent... sorry!].

We are currently able to receive email, but nothing goes out.

This is obviously a DNS error of some kind, but it appeared overnight with no config changes to the Raq3i. The ISP's primary & secondary DNS's have been verified, and are operating normally.

I can find nothing on the Cobalt KnowledgeBase which specifically relates to this issue. And I don't know if the imap daemon lines are actually related to this SMTP/DNS issue or not. Doubt it.

TIA for any advice! We'd appreciate it... Any questions, pls. don't hesitate to email me directly, as I only subscribe to the Digest version of this list.

-Liz Townsend
mailto:liz@xxxxxxxxxx
Tech Consultant, Los Angeles
Torque Systems, Inc.


Log snips follow:
***********************

Mar 1 21:45:04 raq imapd[10587]: Login failure user=Active_Monitor_69 host=localhost [127.0.0.1] Mar 1 21:45:07 raq imapd[10587]: command stream end of file, while reading line user=Active_Monitor_69 host=localhost [127.0.0.1] Mar 1 21:45:09 raq sendmail[10589]: NOQUEUE: Null connection from localhost [127.0.0.1]
Mar  1 22:00:04 raq imapd[10827]: imap service init from 127.0.0.1

<snip> ...those lines were repeated many times.
I ran some test emails [BTW, *ALL* domains used in these tests are entered in Email Paramaters on the Raq3i as allowable relay domains, and "sender domains" DO exist! Relaying on these domains has never been denied in the past.]:

Mar 1 22:19:12 raq sendmail[11166]: WAA11166: ruleset=check_mail, arg1=<name@domain#1.com>, relay=[111.111.111.111], reject=501 <name@domain#1.com>... Sender domain must exist Mar 1 22:19:12 raq sendmail[11166]: WAA11166: from=<name@domain#1.com>, size=0, class=0, pri=0, nrcpts=0, proto=ESMTP, relay=[111.111.111.111] Mar 1 22:23:25 raq sendmail[11242]: WAA11242: ruleset=check_rcpt, arg1=<name@domain#1.com>, relay=[222.222.222.222], reject=550 <name@domain#1.com>... Relaying denied Mar 1 22:23:25 raq sendmail[11242]: WAA11242: from=<name@domain#2.com>, size=1024, class=0, pri=0, nrcpts=0, proto=ESMTP, relay=[222.222.222.222]
Mar  1 22:25:19 raq sendmail[421]: restarting /usr/sbin/sendmail on signal
Mar 1 22:25:19 raq sendmail[11290]: starting daemon (8.9.3): SMTP+queueing@01:00:00 Mar 1 22:25:58 raq sendmail[11299]: WAA11299: from=<name@domain#2.com>, size=300, class=0, pri=30300, nrcpts=1, msgid=<p05010405b6c4ebf6cb93@[192.168.1.20]>, proto=ESMTP, relay=[222.222.222.222] Mar 1 22:25:58 raq sendmail[11301]: WAA11299: to=<name@domain#1.com>, ctladdr=<name@domain#2.com> (117/100), delay=00:00:00, xdelay=00:00:00, mailer=esmtp, relay=domain#1.com, stat=Host unknown (Name server: domain#1.com: no data known)

[Huh??? No data known??? It used to be known...]

Mar 1 22:25:59 raq sendmail[11301]: WAA11299: WAA11301: DSN: Host unknown (Name server: domain#1.com: no data known) Mar 1 22:25:59 raq sendmail[11301]: WAA11301: to=name@domain#1.com, delay=00:00:00, xdelay=00:00:00, mailer=esmtp, relay=domain#1.com, stat=Host unknown (Name server: domain#1.com: no data known) Mar 1 22:25:59 raq sendmail[11301]: WAA11301: WAB11301: return to sender: Host unknown (Name server: domain#1.com: no data known) Mar 1 22:25:59 raq sendmail[11301]: WAB11301: to=admin, delay=00:00:00, xdelay=00:00:00, mailer=local, stat=Sent

<snip> ...and the bounce indicated in the above session was received back by the sender. Then, repeated again, several times:

Mar  1 22:30:06 raq imapd[11398]: imap service init from 127.0.0.1
Mar 1 22:30:06 raq imapd[11398]: Login failure user=Active_Monitor_69 host=localhost [127.0.0.1] Mar 1 22:30:09 raq imapd[11398]: command stream end of file, while reading line user=Active_Monitor_69 host=localhost [127.0.0.1] Mar 1 22:30:11 raq sendmail[11400]: NOQUEUE: Null connection from localhost [127.0.0.1]

<snip> ...then, a different set of lines, but it's probably just a cronjob (haven't checked yet):

Mar 1 23:00:13 raq sendmail[11998]: alias database /etc/aliases autorebuilt by root Mar 1 23:00:13 raq sendmail[11998]: /etc/aliases: 16 aliases, longest 10 bytes, 174 bytes total Mar 1 23:00:14 raq sendmail[11998]: NOQUEUE: Null connection from localhost [127.0.0.1] Mar 1 23:06:56 raq sendmail[427]: starting daemon (8.9.3): SMTP+queueing@01:00:00 Mar 1 23:06:57 raq sendmail[428]: alias database /etc/aliases autorebuilt by root Mar 1 23:06:57 raq sendmail[428]: /etc/aliases: 17 aliases, longest 22 bytes, 202 bytes total

...after that, it's just more repetition, through several more email tests.


Add'l info: bounced emails also contain the following:

   ----- Transcript of session follows -----
... while talking to "the Raq3i in question".:
 MAIL From:<name@domain#1.com> SIZE=308
<<< 501 <name@domain#1.com>... Sender domain must exist
501 <name@domain#2.com>... Data format error


Anything look familiar to you guys? Thx again!