I have recently came into an issue with one of my servers that is running virtualmin. I had an issue about a month back where I was getting many failed logins from different ip addresses for my root user. Now recently I have been getting emails stating that I have been reported for high spam count emails from multiple sources. After some looking into the issue I have found that postfix has sent more than 800,000 emails over the past 3 days and none of my sites emails are currently able to send outgoing mail.
After inspecting the /var/log/mail.log I am seeing this:
Dec 2 12:03:48 kodyhusky postfix/error[9899]: EBA351C039BA: to=customers@network.com, relay=none, delay=23069, delays=23069/0.31/0/0.14, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to network.com[160.34.1.130]:25: Connection timed out)
Dec 2 12:03:48 kodyhusky postfix/error[9873]: 4AAED1C03B1D: to=cust@team.com, relay=none, delay=23054, delays=23053/0.3/0/0.16, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to mx3.expertcity.com[216.219.126.8]:25: Connection timed out)
Dec 2 12:03:48 kodyhusky postfix/error[9871]: 4D0B61C03BB2: to=review@network.com, relay=none, delay=14673, delays=14672/0.3/0/0.16, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to network.com[160.34.1.130]:25: Connection timed out)
Dec 2 12:03:48 kodyhusky postfix/error[9866]: 8CA8F1C03BBE: to=intl2@network.com, relay=none, delay=14646, delays=14645/0.31/0/0.14, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to network.com[160.34.1.130]:25: Connection timed out)
Dec 2 12:03:48 kodyhusky postfix/error[9919]: 211411C03B1C: to=guard@team.com, relay=none, delay=23049, delays=23049/0.3/0/0.15, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to mx3.expertcity.com[216.219.126.8]:25: Connection timed out)
Dec 2 12:03:48 kodyhusky postfix/error[9888]: 8BE421C03B9C: to=clients@network.com, relay=none, delay=14679, delays=14678/0.31/0/0.14, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to network.com[160.34.1.130]:25: Connection timed out)
Dec 2 12:03:48 kodyhusky postfix/error[9927]: 82D0B1C03AC8: to=guard@team.com, relay=none, delay=6270, delays=6269/0.31/0/0.17, dsn=4.4.1, status=deferred (delivery temporarily suspended: connect to mx3.expertcity.com[216.219.126.8]:25: Connection timed out)
I have had to shut down all of my personal websites as this issue appears to be a high security risk and I am trying to find a way to fix this issue. Would anyone be willing to give any advice on how to solve this issue?
The machine I have is currently running Ubuntu 14.04.3 LTS and the latest version of virtualmin with all updates installed.