taravasya
![](http://forum.ru-board.com/board/avatars/PrinceJohn.gif)
Member | Редактировать | Профиль | Сообщение | ICQ | Цитировать | Сообщить модератору Здравствуйте! Долго выбирал тему в которой отписаться,.. но так как предполагаю, что решение проблемы можно будет найти именно в hMail, то решил спросить здесь. Есть проблема, с как я полагаю спамерством посредством моего почтового сервера. Приблизительно вот такие отчёты, я получаю по 2-5 штук в день в gmail-е: Код: This is an automatically generated Delivery Status Notification THIS IS A WARNING MESSAGE ONLY. YOU DO NOT NEED TO RESEND YOUR MESSAGE. Delivery to the following recipient has been delayed: racquelrobinsonj@yaleherald.com Message will be retried for 1 more day(s) Technical details of temporary failure: The recipient server did not accept our requests to connect. Learn more at https://support.google.com/mail/answer/7720 [localhost.yaleherald.com. 127.0.0.1: socket error] ----- Original message ----- DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=photomir-dn-ua.20150623.gappssmtp.com; s=20150623; h=date:from:reply-to:message-id:to:subject:mime-version; bh=0RSHBmKrley1RJSzXibdbiRpeol7iBliWcieuwnNRJ8=; b=bmDvo8fozDFqwVggYbHxuBChoNvPYuojFw6ZndAB2pHT72/XcjEUgnaVb8iv1g544v HT91mSYyXMarV/mgeQYNr/htmphwmJzUgOTHJj6X+RaqwO7wGEK/nyCET3yEXrvkZAoa JxuI+eUuJR9h6Az2ufkLPRkBbNq+qJ8BwdWx5ET1V9FOm+V+TZ4Xig9k/x2VVML0L3D/ BurBAobIuxPRoBmI1ogrSp1+s2uL22H24LxvePGAsd8WvO+Ketc2NZVqSU34HSudvB78 3O6JBqchVl9E7Evsf3/MGX/2RuJolJf5+kuBs1Z1HBhscub/xPIK+oJfcqciTTriOBJy a8AQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:date:from:reply-to:message-id:to:subject :mime-version; bh=0RSHBmKrley1RJSzXibdbiRpeol7iBliWcieuwnNRJ8=; b=NtGoLoOj4wQiMh2O4PWi2KFgxtfHoP+RRMSD/X9kg5WCAm/8C4FcCTraGV7489lVQk ogaM5wgzUYd9H19St0c1a5K2G448K6LgsC150Usjq1pui67EDC9ePQQHRJ+OyzP/lxP2 ne1DJ4dbDnXmHHdus2FxhgjfNzUHLPyk6y4CPr0pQNecXhDwQ/+IgSnNv0fLqu+KoLlO KsASkwB5L83UA/WU31ZgzsNBxf15y8wAp7Ey+RRPde7lrXiYMT1q9LODVKruKKL0PPHL 7m5PviQCw3ptJodlFymCPGH2rv0oKRdAPMTfVybpJdDREaUUNnqELAGKCK6o0m9AP2qJ im7A== X-Gm-Message-State: ALyK8tKY4qhQpIqMICMhmEFlp7ahXCq4pGSOKK0Heo7jBe1XNZoi0cuQFkhtLVbuqylw+Q== X-Received: by 10.25.86.6 with SMTP id k6mr5745565lfb.135.1468965933900; Tue, 19 Jul 2016 15:05:33 -0700 (PDT) Return-Path: <нашМэйл@photomir.dn.ua> Received: from photomir.dn.ua (as42959-91-193-253-237.mol.net.ua. [xx.xxx.xxx.xxx]) by smtp.gmail.com with ESMTPSA id l10sm3112116lfd.19.2016.07.19.15.05.32 for <racquelrobinsonj@yaleherald.com> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 19 Jul 2016 15:05:33 -0700 (PDT) Date: Tue, 19 Jul 2016 15:05:33 -0700 (PDT) X-Google-Original-Date: Wed, 20 Jul 2016 1:05:39 +0300 From: moreno897 <нашМэйл@photomir.dn.ua> X-Google-Original-From: moreno897 <no-reply@huntersclub.com.ua> Received: from huntersclub.com.ua (validation.sls.microsoft.com [127.0.0.1]) by photomir.dn.ua ; Wed, 20 Jul 2016 01:05:40 +0300 Reply-To: <sugary@qztmail.com> Message-ID: <68106517.76361135.1468965939908@huntersclub.com.ua> To: racquelrobinsonj@yaleherald.com Subject: FW: Salute X-Priority: 3 (Normal) MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_76361134_09969152.1468965939908" ----- End of message ----- | ====================================================== Вот лог этого же события в hMail-е: ====================================================== Код: "SMTPD" 1596 18 "2016-07-20 01:05:40.043" "127.0.0.1" "SENT: 220 photomir.dn.ua ESMTP" "SMTPD" 1792 18 "2016-07-20 01:05:40.121" "127.0.0.1" "RECEIVED: EHLO huntersclub.com.ua" "SMTPD" 1792 18 "2016-07-20 01:05:40.121" "127.0.0.1" "SENT: 250-photomir.dn.ua[nl]250-SIZE 20480000[nl]250 AUTH LOGIN" "SMTPD" 1792 18 "2016-07-20 01:05:40.136" "127.0.0.1" "RECEIVED: MAIL FROM:<no-reply@huntersclub.com.ua>" "SMTPD" 1792 18 "2016-07-20 01:05:40.199" "127.0.0.1" "SENT: 250 OK" "SMTPD" 1704 18 "2016-07-20 01:05:40.214" "127.0.0.1" "RECEIVED: RCPT TO:<racquelrobinsonj@yaleherald.com>" "SMTPD" 1704 18 "2016-07-20 01:05:40.214" "127.0.0.1" "SENT: 250 OK" "SMTPD" 1704 18 "2016-07-20 01:05:40.214" "127.0.0.1" "RECEIVED: DATA" "SMTPD" 1704 18 "2016-07-20 01:05:40.230" "127.0.0.1" "SENT: 354 OK, send." "SMTPD" 404 18 "2016-07-20 01:05:40.417" "127.0.0.1" "SENT: 250 Queued (0.078 seconds)" "SMTPD" 1848 18 "2016-07-20 01:05:40.433" "127.0.0.1" "RECEIVED: QUIT" "SMTPD" 1848 18 "2016-07-20 01:05:40.433" "127.0.0.1" "SENT: 221 goodbye" "SMTPC" 1704 19 "2016-07-20 01:05:40.791" "74.125.205.108" "RECEIVED: 220 smtp.gmail.com ESMTP l10sm3112116lfd.19 - gsmtp" "SMTPC" 1704 19 "2016-07-20 01:05:40.807" "74.125.205.108" "SENT: EHLO photomir.dn.ua" "SMTPC" 1704 19 "2016-07-20 01:05:40.838" "74.125.205.108" "RECEIVED: 250-smtp.gmail.com at your service, [xx.xxx.xxx.xxx]" "SMTPC" 1856 19 "2016-07-20 01:05:40.838" "74.125.205.108" "RECEIVED: 250-SIZE 35882577" "SMTPC" 1704 19 "2016-07-20 01:05:40.838" "74.125.205.108" "RECEIVED: 250-8BITMIME" "SMTPC" 1856 19 "2016-07-20 01:05:40.838" "74.125.205.108" "RECEIVED: 250-AUTH LOGIN PLAIN XOAUTH2 PLAIN-CLIENTTOKEN OAUTHBEARER XOAUTH" "SMTPC" 1704 19 "2016-07-20 01:05:40.838" "74.125.205.108" "RECEIVED: 250-ENHANCEDSTATUSCODES" "SMTPC" 1856 19 "2016-07-20 01:05:40.854" "74.125.205.108" "RECEIVED: 250-PIPELINING" "SMTPC" 1704 19 "2016-07-20 01:05:40.854" "74.125.205.108" "RECEIVED: 250-CHUNKING" "SMTPC" 1856 19 "2016-07-20 01:05:40.854" "74.125.205.108" "RECEIVED: 250 SMTPUTF8" "SMTPC" 1856 19 "2016-07-20 01:05:40.854" "74.125.205.108" "SENT: AUTH LOGIN" "SMTPC" 1856 19 "2016-07-20 01:05:40.885" "74.125.205.108" "RECEIVED: 334 VXNlcm5hbWU6" "SMTPC" 1856 19 "2016-07-20 01:05:40.885" "74.125.205.108" "SENT: bWFpbEBwaG90b21pci5kbi51YQ==" "SMTPC" 1856 19 "2016-07-20 01:05:40.932" "74.125.205.108" "RECEIVED: 334 UGFzc3dvcmQ6" "SMTPC" 1856 19 "2016-07-20 01:05:40.932" "74.125.205.108" "SENT: ***" "SMTPC" 1852 19 "2016-07-20 01:05:41.197" "74.125.205.108" "RECEIVED: 235 2.7.0 Accepted" "SMTPC" 1852 19 "2016-07-20 01:05:41.197" "74.125.205.108" "SENT: MAIL FROM:<no-reply@huntersclub.com.ua>" "SMTPC" 1792 19 "2016-07-20 01:05:41.228" "74.125.205.108" "RECEIVED: 250 2.1.0 OK l10sm3112116lfd.19 - gsmtp" "SMTPC" 1792 19 "2016-07-20 01:05:41.228" "74.125.205.108" "SENT: RCPT TO:<racquelrobinsonj@yaleherald.com>" "SMTPC" 1764 19 "2016-07-20 01:05:41.275" "74.125.205.108" "RECEIVED: 250 2.1.5 OK l10sm3112116lfd.19 - gsmtp" "SMTPC" 1764 19 "2016-07-20 01:05:41.275" "74.125.205.108" "SENT: DATA" "SMTPC" 1596 19 "2016-07-20 01:05:41.649" "74.125.205.108" "RECEIVED: 354 Go ahead l10sm3112116lfd.19 - gsmtp" "SMTPC" 1596 19 "2016-07-20 01:05:41.649" "74.125.205.108" "SENT: [nl]." "SMTPC" 1760 19 "2016-07-20 01:05:42.523" "74.125.205.108" "RECEIVED: 250 2.0.0 OK 1468965933 l10sm3112116lfd.19 - gsmtp" "SMTPC" 1760 19 "2016-07-20 01:05:42.539" "74.125.205.108" "SENT: QUIT" "SMTPC" 1760 19 "2016-07-20 01:05:42.570" "74.125.205.108" "RECEIVED: 221 2.0.0 closing connection l10sm3112116lfd.19 - gsmtp" "SMTPD" 1596 20 "2016-07-20 21:58:12.223" "127.0.0.1" "SENT: 220 photomir.dn.ua ESMTP" "SMTPD" 1768 20 "2016-07-20 21:58:12.379" "127.0.0.1" "RECEIVED: EHLO huntersclub.com.ua" "SMTPD" 1768 20 "2016-07-20 21:58:12.395" "127.0.0.1" "SENT: 250-photomir.dn.ua[nl]250-SIZE 20480000[nl]250 AUTH LOGIN" "SMTPD" 1848 20 "2016-07-20 21:58:12.519" "127.0.0.1" "RECEIVED: MAIL FROM:<info@huntersclub.com.ua>" "SMTPD" 1848 20 "2016-07-20 21:58:12.597" "127.0.0.1" "SENT: 250 OK" "SMTPD" 1600 20 "2016-07-20 21:58:12.738" "127.0.0.1" "RECEIVED: RCPT TO:<delta@stat-run.info>" "SMTPD" 1600 20 "2016-07-20 21:58:12.753" "127.0.0.1" "SENT: 250 OK" "SMTPD" 1760 20 "2016-07-20 21:58:12.878" "127.0.0.1" "RECEIVED: DATA" "SMTPD" 1760 20 "2016-07-20 21:58:12.894" "127.0.0.1" "SENT: 354 OK, send." "SMTPD" 404 20 "2016-07-20 21:58:13.128" "127.0.0.1" "SENT: 250 Queued (0.172 seconds)" "SMTPC" 1852 21 "2016-07-20 21:58:13.565" "173.194.220.108" "RECEIVED: 220 smtp.gmail.com ESMTP k15sm840184lfb.25 - gsmtp" "SMTPC" 1852 21 "2016-07-20 21:58:13.565" "173.194.220.108" "SENT: EHLO photomir.dn.ua" "SMTPC" 1768 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250-smtp.gmail.com at your service, [xx.xxx.xxx.xxx]" "SMTPC" 1852 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250-SIZE 35882577" "SMTPC" 1768 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250-8BITMIME" "SMTPC" 1852 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250-AUTH LOGIN PLAIN XOAUTH2 PLAIN-CLIENTTOKEN OAUTHBEARER XOAUTH" "SMTPC" 1768 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250-ENHANCEDSTATUSCODES" "SMTPC" 1852 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250-PIPELINING" "SMTPC" 1768 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250-CHUNKING" "SMTPC" 1852 21 "2016-07-20 21:58:13.611" "173.194.220.108" "RECEIVED: 250 SMTPUTF8" "SMTPC" 1852 21 "2016-07-20 21:58:13.611" "173.194.220.108" "SENT: AUTH LOGIN" "SMTPC" 1504 21 "2016-07-20 21:58:13.658" "173.194.220.108" "RECEIVED: 334 VXNlcm5hbWU6" "SMTPC" 1504 21 "2016-07-20 21:58:13.674" "173.194.220.108" "SENT: bWFpbEBwaG90b21pci5kbi51YQ==" "SMTPC" 1504 21 "2016-07-20 21:58:13.721" "173.194.220.108" "RECEIVED: 334 UGFzc3dvcmQ6" "SMTPC" 1504 21 "2016-07-20 21:58:13.721" "173.194.220.108" "SENT: ***" "SMTPC" 1772 21 "2016-07-20 21:58:14.033" "173.194.220.108" "RECEIVED: 235 2.7.0 Accepted" "SMTPC" 1772 21 "2016-07-20 21:58:14.033" "173.194.220.108" "SENT: MAIL FROM:<info@huntersclub.com.ua>" "SMTPC" 1792 21 "2016-07-20 21:58:14.079" "173.194.220.108" "RECEIVED: 250 2.1.0 OK k15sm840184lfb.25 - gsmtp" "SMTPC" 1792 21 "2016-07-20 21:58:14.079" "173.194.220.108" "SENT: RCPT TO:<delta@stat-run.info>" "SMTPC" 1792 21 "2016-07-20 21:58:14.126" "173.194.220.108" "RECEIVED: 250 2.1.5 OK k15sm840184lfb.25 - gsmtp" "SMTPC" 1792 21 "2016-07-20 21:58:14.126" "173.194.220.108" "SENT: DATA" "SMTPC" 1704 21 "2016-07-20 21:58:14.750" "173.194.220.108" "RECEIVED: 354 Go ahead k15sm840184lfb.25 - gsmtp" "SMTPC" 1704 21 "2016-07-20 21:58:14.781" "173.194.220.108" "SENT: [nl]." "SMTPC" 1848 21 "2016-07-20 21:58:15.717" "173.194.220.108" "RECEIVED: 250 2.0.0 OK 1469041083 k15sm840184lfb.25 - gsmtp" "SMTPC" 1848 21 "2016-07-20 21:58:15.717" "173.194.220.108" "SENT: QUIT" "SMTPC" 1768 21 "2016-07-20 21:58:15.764" "173.194.220.108" "RECEIVED: 221 2.0.0 closing connection k15sm840184lfb.25 - gsmtp" "SMTPD" 1596 22 "2016-07-20 21:58:56.855" "127.0.0.1" "SENT: 220 photomir.dn.ua ESMTP" "SMTPD" 1836 22 "2016-07-20 21:58:57.089" "127.0.0.1" "RECEIVED: EHLO huntersclub.com.ua" "SMTPD" 1836 22 "2016-07-20 21:58:57.089" "127.0.0.1" "SENT: 250-photomir.dn.ua[nl]250-SIZE 20480000[nl]250 AUTH LOGIN" "SMTPD" 1836 22 "2016-07-20 21:58:57.214" "127.0.0.1" "RECEIVED: MAIL FROM:<info@huntersclub.com.ua>" "SMTPD" 1836 22 "2016-07-20 21:58:57.229" "127.0.0.1" "SENT: 250 OK" "SMTPD" 1792 22 "2016-07-20 21:58:57.370" "127.0.0.1" "RECEIVED: RCPT TO:<fmrcong@aol.com>" "SMTPD" 1792 22 "2016-07-20 21:58:57.370" "127.0.0.1" "SENT: 250 OK" "SMTPD" 1768 22 "2016-07-20 21:58:57.494" "127.0.0.1" "RECEIVED: DATA" "SMTPD" 1768 22 "2016-07-20 21:58:57.494" "127.0.0.1" "SENT: 354 OK, send." "SMTPD" 404 22 "2016-07-20 21:58:57.635" "127.0.0.1" "SENT: 250 Queued (0.124 seconds)" "SMTPC" 1764 23 "2016-07-20 21:58:57.838" "173.194.220.108" "RECEIVED: 220 smtp.gmail.com ESMTP 62sm866796ljj.3 - gsmtp" "SMTPC" 1764 23 "2016-07-20 21:58:57.853" "173.194.220.108" "SENT: EHLO photomir.dn.ua" "SMTPC" 1792 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250-smtp.gmail.com at your service, [xx.xxx.xxx.xxx]" "SMTPC" 1596 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250-SIZE 35882577" "SMTPC" 1792 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250-8BITMIME" "SMTPC" 1596 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250-AUTH LOGIN PLAIN XOAUTH2 PLAIN-CLIENTTOKEN OAUTHBEARER XOAUTH" "SMTPC" 1792 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250-ENHANCEDSTATUSCODES" "SMTPC" 1596 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250-PIPELINING" "SMTPC" 1792 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250-CHUNKING" "SMTPC" 1596 23 "2016-07-20 21:58:57.900" "173.194.220.108" "RECEIVED: 250 SMTPUTF8" "SMTPC" 1596 23 "2016-07-20 21:58:57.900" "173.194.220.108" "SENT: AUTH LOGIN" "SMTPC" 1848 23 "2016-07-20 21:58:57.962" "173.194.220.108" "RECEIVED: 334 VXNlcm5hbWU6" "SMTPC" 1848 23 "2016-07-20 21:58:57.962" "173.194.220.108" "SENT: bWFpbEBwaG90b21pci5kbi51YQ==" "SMTPC" 1768 23 "2016-07-20 21:58:58.025" "173.194.220.108" "RECEIVED: 334 UGFzc3dvcmQ6" "SMTPC" 1768 23 "2016-07-20 21:58:58.025" "173.194.220.108" "SENT: ***" "SMTPC" 1836 23 "2016-07-20 21:58:58.306" "173.194.220.108" "RECEIVED: 235 2.7.0 Accepted" "SMTPC" 1836 23 "2016-07-20 21:58:58.306" "173.194.220.108" "SENT: MAIL FROM:<info@huntersclub.com.ua>" "SMTPC" 1764 23 "2016-07-20 21:58:58.368" "173.194.220.108" "RECEIVED: 250 2.1.0 OK 62sm866796ljj.3 - gsmtp" "SMTPC" 1764 23 "2016-07-20 21:58:58.368" "173.194.220.108" "SENT: RCPT TO:<fmrcong@aol.com>" "SMTPC" 1792 23 "2016-07-20 21:58:58.430" "173.194.220.108" "RECEIVED: 250 2.1.5 OK 62sm866796ljj.3 - gsmtp" "SMTPC" 1792 23 "2016-07-20 21:58:58.430" "173.194.220.108" "SENT: DATA" "SMTPC" 1856 23 "2016-07-20 21:58:58.664" "173.194.220.108" "RECEIVED: 354 Go ahead 62sm866796ljj.3 - gsmtp" "SMTPC" 1856 23 "2016-07-20 21:58:58.664" "173.194.220.108" "SENT: [nl]." "SMTPC" 1760 23 "2016-07-20 21:58:59.429" "173.194.220.108" "RECEIVED: 250 2.0.0 OK 1469041127 62sm866796ljj.3 - gsmtp" "SMTPC" 1760 23 "2016-07-20 21:58:59.429" "173.194.220.108" "SENT: QUIT" "SMTPC" 1792 23 "2016-07-20 21:58:59.476" "173.194.220.108" "RECEIVED: 221 2.0.0 closing connection 62sm866796ljj.3 - gsmtp" | ====================================================== Здесь: ====================================================== mol.net.ua - наш интернет-провайдер [xx.xxx.xxx.xxx] - наш внешний статический IP. photomir.dn.ua - наш домен(сайт на joomla), привязанный к почте gmail(посредством MX-записи). huntersclub.com.ua - наш домен(форум на vbulletin), привязанный к почте gmail(посредством MX-записи). нашМэйл@photomir.dn.ua - наш реальный почтовый ящик. no-reply@huntersclub.com.ua - поддельный почтовый ящик(такого нет в аккаунте домена привязанного к gmail). info@huntersclub.com.ua - поддельный почтовый ящик(такого нет в аккаунте домена привязанного к gmail). ====================================================== Как я понимаю: 1)Кто-то через дырку в форуме, либо: 2)Непосредственно через почтовый протокол потыхэньку спамит. Вывод такой делаю исходя из того, что в логах, простите за тавтологию, присутствуют отсутствующие аккаунты(явно подставленные наугад). Помогите отловить злоумышленника и правильно настроить почтовый сервер hMail. ![](http://forum.ru-board.com/board/s/confused.gif) ![](http://forum.ru-board.com/board/s/confused.gif) ![](http://forum.ru-board.com/board/s/confused.gif) |