[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Logcheck-Sendmail Relay Report



> >> Sep 27 05:17:44 corporate sendmail[22427]: g8RAHiL22427: 
> >> ruleset=check_rcpt, arg1=<stxvilla@xxxxxxxxxxxx>, 
> >> relay=216-166-248-214.clec.peknil.madisonriver.net
> >> [216.166.248.214], reject=550 5.7.1 <stxvilla@xxxxxxxxxxxx>... 
> >> Relaying denied.  Please check your mail first or restart 
> your mail 
> I do have POP B4 SMTP enabled. And is see what your saying, I 
> guess may question or concern is if this is one of our 
> clients trying to send spam through our boxes or if Madison 
> River/Galletin River (large ILEC in this
> region) is running an open relay on their servers, what should I do?
> 
> I ran a dig on the viaccess.net and I don't see any pointing to us.

It's hard to say. Unless you see a ton of action when running tail -f
/var/log/maillog from that user, I doubt they're doing a spam run.
Personally, I don't run POP before SMTP since I haven't seen a need for
it. Everyone I've dealt with has their own ISP to use for SMTP.
-- 
Dan Kriwitsky

Please reply to the list only. Offlist replies are not read.