LockedOutgoing SPAM!

Author
Tariq
Starting Member
2007/02/02 16:00:51 (permalink)

Outgoing SPAM!

Hello,

I am having a lot of problems with my server sending outgoing SPAM. I am using MailEnable Standard in a web hosting environment with the following relay settings:
- Allow relay from authenticated users
- Allow relay from privileged IP ranges (all computers are denied relay rights, except 127.0.0.1)
- POP before SMTP authentication (remember IP address for 20 minutes)
In the security tab for the SMTP connector I also enabled these settings:
- Reject mail if sender address is from an invalid domain
- Authenticated users must use valid sender address

By checking the SMTP logs, I see that the SPAM originates from localhost which is quite normal in a web hosting environment with 500+ domains per server but it's also quite impossible for me to check all the scripts to see if anything is compromised or if anyone is sending it on purpose. Also, the email addresses in the FROM field do not exist on my server and neither do the domains.

Is there any way I could implement a spam filtering solution that would scan outgoing mails?

Can I set a Quota for sent emails per a day?

No response from MailEnabe.com. Is there any idea?

Thank you!
#1

3 Replies Related Threads

    Dhosting.co.uk
    Premium Member
    RE: Outgoing SPAM! 2007/02/02 16:12:33 (permalink)
    Are you sure they are going out of mailenable

    Do you have iis SMTP installed, if so thats probably your spam source.

    Any good mail server can tell you which users have sent so many messages, if you have set it to only allow authenticated users you should be able to see this.

    We have a zero spam policy, we have settings enabled to tell us if someones trying to spam etc.

    This isn't really a HC issue more of your mail and server config.

    Let me know if IIS SMTP is installed for a start

    __________________
    Chris Daley
    Dwebs Ltd Director :: Company No. 05603664 :: Phone No. (UK) 0870 803 4423
    www.Dhosting.co.uk - Web Hosting, Domain Registration, Windows 2003 NLB Cluster with HC 6.1!!!
    www.Dwebs.ltd.uk - Web Design & Other Services
    My views are my own and not those of my company.
    #2
    Tariq
    Starting Member
    RE: Outgoing SPAM! 2007/02/02 16:47:13 (permalink)
    You can not run iis SMTP and MailEnabled SMTP at the same time.

    As I am using MailEnabled, iis SMTP is disabled on the server.

    My problem that some of my customers are sending bulk emails (SPAM) from thier domains and the company that hosted my server is bloking all emails that are comming from my server (Based on IP).

    How I can prevent that ???

    #3
    Dhosting.co.uk
    Premium Member
    RE: Outgoing SPAM! 2007/02/02 17:07:44 (permalink)
    Well your wrong with IIS SMTP, with the right script and editing you can run any win mail server plus + iis smtp as long as you use two ip's one for mailenable, then one for shared IIS, anyways thats off topic.

    Well its my first look at mail enable but in general all mail servers do the same.

    If you read the manual under smtp it recomends you to
    "For a server on the Internet, the best relay setting to have is to only have Allow relay for authenticated senders checked, and leave Allow relay for local sender addresses unchecked. This will make everyone who wants to send email out via the server provide a username and password."

    Next in the smtp security section
    "Authenticated senders must use valid sender address
    If this is selected, users with authentication to send email must configure their email client with a valid email address that is assigned to the mailbox they are using to send on. This option is used to force clients to use a legitimate email address, thereby reducing the possibility of spam."

    Next
    "Restrict the number of recipients per email" try setting to 20

    Next
    "Drop a connection when the failed number of commands or recipients reaches" set to 5

    Next
    SMTP Logging - Activity Log make sure this is enabled

    I've never used mail enable before but all that info is in the mail enable 2 manual, if you want drop me an email and i will see if i can help you out finding the source of the spam.

    You might also want to look at the mailenable forum for more detailed help.

    We have used merak for the past 2 years, we have only had one spammer in all that time, we locked down more smtp settings so in the event someone sends spam and it fails to be delivered it bounces back to the sender and also a copy to us. We limit number of connections, messages which can be sent.

    __________________
    Chris Daley
    Dwebs Ltd Director :: Company No. 05603664 :: Phone No. (UK) 0870 803 4423
    www.Dhosting.co.uk - Web Hosting, Domain Registration, Windows 2003 NLB Cluster with HC 6.1!!!
    www.Dwebs.ltd.uk - Web Design & Other Services
    My views are my own and not those of my company.
    #4
    Jump to: