Mijn vraag
Ik heb een eigen mail server en heb SPF, DKIM, en DMARC een tijdje geleden ingesteld. Nu krijg ik veel DMARC reports en daar staan 1700 mails in die ik niet verstuurd heb, en niet van mijn IP komen, maar van verschillende IP's
Relevante software en hardware die ik gebruik
AXIGEN X
Ubuntu 14.04
Time4VPS.eu VPS
SMTP op :25 en :465(ssl)
IMAP op :143 en 993(ssl)
Wat ik al gevonden of geprobeerd heb
Ik heb fail2ban ingesteld, hier krijg ik soms een ban op maar dat is als iemand een inlogaanval doet op SSH of Axigen. Kan ik de listener op poort 25 gewoon uitzetten? aangezien iedereen op mijn mail SSL gebruiken.
Log :
DMARC log:
AOL : https://dmarcian.com/dmarc-xml/details/mhjgbGYN2csPirnH/
Yahoo (906KB groot!?) : https://dmarcian.com/dmarc-xml/details/ed1HpiNks6QX5G2m
Ik hoop dat jullie mij kunnen helpen!
Ik heb een eigen mail server en heb SPF, DKIM, en DMARC een tijdje geleden ingesteld. Nu krijg ik veel DMARC reports en daar staan 1700 mails in die ik niet verstuurd heb, en niet van mijn IP komen, maar van verschillende IP's
Relevante software en hardware die ik gebruik
AXIGEN X
Ubuntu 14.04
Time4VPS.eu VPS
SMTP op :25 en :465(ssl)
IMAP op :143 en 993(ssl)
Wat ik al gevonden of geprobeerd heb
Ik heb fail2ban ingesteld, hier krijg ik soms een ban op maar dat is als iemand een inlogaanval doet op SSH of Axigen. Kan ik de listener op poort 25 gewoon uitzetten? aangezien iedereen op mijn mail SSL gebruiken.
Log :
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
| 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: [MIJN IP:25] connection accepted from [95.46.225.240:42278] 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Set remote delivery to auth 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Greylist disabled 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Set max data size to 25600 KB 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Set max received headers to 30 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Maximum recipient count set to 1000 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Wait for processing response at least 10 seconds 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: STARTTLS extension allowed 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: 8BIT MIME accepted 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: BINARY DATA extension allowed 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: PIPELINING extension allowed 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Set local delivery to all 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: Set mail state to REMOVED 2016-09-29 11:26:57 +0200 08 mail SMTP-IN:00000A9B: closing session from [95.46.225.240:42278] 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: [MIJN IP:25] connection accepted from [179.209.28.44:50430] 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: Set remote delivery to auth 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: Greylist disabled 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: Set max data size to 25600 KB 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: Set max received headers to 30 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: Maximum recipient count set to 1000 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: Wait for processing response at least 10 seconds 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: STARTTLS extension allowed 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: 8BIT MIME accepted 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: BINARY DATA extension allowed 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: PIPELINING extension allowed 2016-09-29 11:27:06 +0200 08 mail SMTP-IN:00000A9C: Set local delivery to all 2016-09-29 11:27:07 +0200 08 mail SMTP-IN:00000A9C: Set mail state to REMOVED 2016-09-29 11:27:07 +0200 08 mail SMTP-IN:00000A9C: closing session from [179.209.28.44:50430] 2016-09-29 11:27:18 +0200 08 mail SMTP-IN:00000A9D: [MIJN IP:25] connection accepted from [109.241.251.48:44159] 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Set remote delivery to auth 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Greylist disabled 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Set max data size to 25600 KB 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Set max received headers to 30 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Maximum recipient count set to 1000 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Wait for processing response at least 10 seconds 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: STARTTLS extension allowed 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: 8BIT MIME accepted 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: BINARY DATA extension allowed 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: PIPELINING extension allowed 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Set local delivery to all 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: Set mail state to REMOVED 2016-09-29 11:27:19 +0200 08 mail SMTP-IN:00000A9D: closing session from [109.241.251.48:44159] 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: [MIJN IP:25] connection accepted from [178.57.246.144:54841] 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Set remote delivery to auth 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Greylist disabled 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Set max data size to 25600 KB 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Set max received headers to 30 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Maximum recipient count set to 1000 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Wait for processing response at least 10 seconds 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: STARTTLS extension allowed 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: 8BIT MIME accepted 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: BINARY DATA extension allowed 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: PIPELINING extension allowed 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Set local delivery to all 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: Set mail state to REMOVED 2016-09-29 11:27:30 +0200 08 mail SMTP-IN:00000A9E: closing session from [178.57.246.144:54841] |
DMARC log:
AOL : https://dmarcian.com/dmarc-xml/details/mhjgbGYN2csPirnH/
Yahoo (906KB groot!?) : https://dmarcian.com/dmarc-xml/details/ed1HpiNks6QX5G2m
Ik hoop dat jullie mij kunnen helpen!