Hmm, strangely enough the load on my server has NOT gone down even though I stopped Postfix!
uptime
11:06:26 up 18:56, 1 user, load average: 249.00, 249.03, 249.05
Maybe I’m looking in the wrong area? I thought the load would go down with Postfix turned off.
There are still a ton of Postfix processes listed under Running Processes - any idea how I can stop/kill all of those?
I ran mailq:
[code]postqueue: warning: Mail system is down – accessing queue directly
-Queue ID- --Size-- ----Arrival Time---- -Sender/Recipient-------
EEC10149A* 834 Fri Dec 7 20:31:34 CDA4A3D1@veneilijat.net
(bounce or trace service failure)
BOUNCE@dedi-fr-57196.op-net.com
B5C1617B1* 1097 Fri Dec 7 22:31:06 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
F299617A1* 868 Fri Dec 7 22:18:29 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
BF8F717A8* 1109 Fri Dec 7 22:20:33 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
3F3DA17AE* 852 Fri Dec 7 22:26:28 688DFBD@johanvangilsfd.nl
BOUNCE@dedi-fr-57196.op-net.com
447E817AA* 1093 Fri Dec 7 22:24:35 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
224A6148B* 866 Fri Dec 7 21:06:12 1629EE3@theknightsofavalon.com
BOUNCE@dedi-fr-57196.op-net.com
29E4B15DB* 1094 Fri Dec 7 21:50:25 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
20342146E* 2946 Fri Dec 7 20:53:21 JaniahLopaz@pacific.net.sg
BOUNCE@dedi-fr-57196.op-net.com
63B8117AD* 1102 Fri Dec 7 22:26:30 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
B6C16152B* 4011 Fri Dec 7 21:35:44 AlaynaThurstonson@dwvideoproductions.com
BOUNCE@dedi-fr-57196.op-net.com
54BAC12AF* 882 Fri Dec 7 20:41:25 04203558A@poncedeleongroup.com
BOUNCE@dedi-fr-57196.op-net.com
82DE71490* 1112 Fri Dec 7 21:07:21 alcaldesalteras@dipusevilla.es
BOUNCE@dedi-fr-57196.op-net.com
EE9281532* 2697 Fri Dec 7 21:37:33 LaneyBarbaro@orange.fr
BOUNCE@dedi-fr-57196.op-net.com
1FF78160C* 1100 Fri Dec 7 22:02:38 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
F296717BE* 1109 Fri Dec 7 22:40:33 double-bounce@dedi-fr-57196.op-net.com
postmaster@dedi-fr-57196.op-net.com
[/code]
There is not a single email address in there I recognize - the BOUNCE and postmaster addresses are standard ones, right? Why are there so many emails going from one to the other? Would that indicate the postmaster address is being used to send SPAM? dedi-fr-57196.op-net.com is my host name.
I looked up one of the bounce-postmaster emails:
[code]*** ENVELOPE RECORDS active/B5C1617B1 ***
message_size: 1097 256 1 0 1097
message_arrival_time: Fri Dec 7 23:31:06 2012
create_time: Fri Dec 7 23:31:06 2012
named_attribute: log_message_origin=local
named_attribute: trace_flags=0
sender: double-bounce@dedi-fr-57196.op-net.com
original_recipient: postmaster
recipient: postmaster@dedi-fr-57196.op-net.com
*** MESSAGE CONTENTS active/B5C1617B1 ***
Received: by dedi-fr-57196.op-net.com (Postfix)
id B5C1617B1; Fri, 7 Dec 2012 23:31:06 +0100 (CET)
Date: Fri, 7 Dec 2012 23:31:06 +0100 (CET)
From: MAILER-DAEMON@dedi-fr-57196.op-net.com (Mail Delivery System)
To: postmaster@dedi-fr-57196.op-net.com (Postmaster)
Subject: Postfix SMTP server: errors from unknown[95.86.0.88]
Message-Id: 20121207223106.B5C1617B1@dedi-fr-57196.op-net.com
Transcript of session follows.
Out: 220 dedi-fr-57196.op-net.com ESMTP Postfix
In: EHLO [95.86.0.88]
Out: 250-dedi-fr-57196.op-net.com
Out: 250-PIPELINING
Out: 250-SIZE 10240000
Out: 250-VRFY
Out: 250-ETRN
Out: 250-STARTTLS
Out: 250-AUTH PLAIN LOGIN
Out: 250-AUTH=PLAIN LOGIN
Out: 250-ENHANCEDSTATUSCODES
Out: 250-8BITMIME
Out: 250 DSN
In: MAIL FROM:D79F81FF@hollandwoningen.nl
Out: 250 2.1.0 Ok
In: RCPT TO:celina@anabeatrizbarrosfan.com
Out: 250 2.1.5 Ok
In: DATA
Out: 354 End data with .
Out: 451 4.3.0 Error: queue file write error
Session aborted, reason: lost connection
For other details, see the local mail logfile
*** HEADER EXTRACTED active/B5C1617B1 ***
*** MESSAGE FILE END active/B5C1617B1 ***[/code]
At this point I decided to reboot my server, to clear the hundreds of postfix processes that weren’t going away, and ran mailq again once it was rebooted:
[code]postqueue: warning: Mail system is down – accessing queue directly
-Queue ID- --Size-- ----Arrival Time---- -Sender/Recipient-------
97C3F16D0* 2865 Tue Dec 4 21:26:42 MAILER-DAEMON
080926FE@sekelaam.endjunk.com
9362B15CE* 4172 Wed Dec 5 14:52:55 MAILER-DAEMON
SusanBoshers@stadia.ch
381AC16D9 2861 Thu Dec 6 11:42:05 MAILER-DAEMON
(Host or domain name not found. Name service error for name=eurolatincz.com type=MX: Host not found, try again)
14640506@eurolatincz.com
3A2261781 3711 Thu Dec 6 23:00:55 MAILER-DAEMON
(connect to ftp3.scmedia.com.hk[203.184.143.49]:25: Connection timed out)
rivierar@ftp3.scmedia.com.hk
303461584 2868 Wed Dec 5 00:54:07 MAILER-DAEMON
(connect to cheapsnowmobile.com[98.129.126.138]:25: Connection timed out)
CAE06F11@cheapsnowmobile.com
3C583176E 3620 Thu Dec 6 15:33:39 MAILER-DAEMON
(Host or domain name not found. Name service error for name=packbell.net type=MX: Host not found, try again)
predicatekvvh2@packbell.net
335CD16D2 2840 Wed Dec 5 15:11:55 MAILER-DAEMON
(Host or domain name not found. Name service error for name=casteando.com type=MX: Host not found, try again)
7F6F640@casteando.com
3AF241608 3654 Tue Dec 4 21:30:04 MAILER-DAEMON
(connect to sneogg2.araneo.pl[195.178.114.15]:25: Connection timed out)
bim@sneogg2.araneo.pl
330D817CA 3842 Thu Dec 6 23:40:51 MAILER-DAEMON
(connect to h-195-178-186-197.na.cust.bahnhof.se[195.178.186.197]:25: Connection refused)
gillettetinytimg1@h-195-178-186-197.na.cust.bahnhof.se
B3864174E 3690 Thu Dec 6 20:59:00 MAILER-DAEMON
(connect to www.reifengundlach.de[213.83.36.114]:25: Connection refused)
jakunx@www.reifengundlach.de
B3F4516CC 3672 Thu Dec 6 19:05:22 MAILER-DAEMON
(host mx4.netstrefa.pl[217.149.243.156] said: 451 Temporary local problem - please try later (in reply to RCPT TO command))
encirclingvoyq6@mx4.netstrefa.pl
B55BC1629 3737 Tue Dec 4 19:31:53 MAILER-DAEMON
(connect to da.e.78ae.static.theplanet.com[174.120.14.218]:25: Connection refused)
fonseca@da.e.78ae.static.theplanet.com
B6748157F 2884 Wed Dec 5 00:53:58 MAILER-DAEMON
(connect to owamail4.westerntc.edu[165.128.0.33]:25: Connection refused)
32EBEFF4@owamail4.westerntc.edu
BA0A21595 6414 Tue Dec 4 16:05:29 MAILER-DAEMON
(Host or domain name not found. Name service error for name=gardenvillage.com type=MX: Host not found, try again)
E8B1ABD@gardenvillage.com
B6FDE168D 3735 Tue Dec 4 23:49:13 MAILER-DAEMON
(connect to da.e.78ae.static.theplanet.com[174.120.14.218]:25: Connection refused)
sure110@da.e.78ae.static.theplanet.com
02CA81614 2835 Thu Dec 6 15:21:36 MAILER-DAEMON
(Host or domain name not found. Name service error for name=llccorp.net type=MX: Host not found, try again)
D4C4B190E@llccorp.net
084DE364 2831 Sat Dec 8 10:37:32 MAILER-DAEMON
(connect to mail.veneilijat.net[81.19.114.200]:25: Connection timed out)
CDA4A3D1@veneilijat.net
7EDC51610 2863 Thu Dec 6 17:01:03 MAILER-DAEMON
(Host or domain name not found. Name service error for name=anjcs.com type=MX: Host not found, try again)
BF22B9E4@anjcs.com
D326F1646 2894 Wed Dec 5 00:50:24 MAILER-DAEMON
(connect to yoolimgemstones.com[141.8.225.13]:25: Connection timed out)
F3C8CF9@yoolimgemstones.com
D7CF1168A 2837 Wed Dec 5 01:01:18 MAILER-DAEMON
(connect to mail.serviper.com[201.144.86.162]:25: Connection timed out)
94789D6EE@serviper.com
DB9EB165E 2826 Wed Dec 5 00:58:45 MAILER-DAEMON
(connect to annashouse.net[208.87.35.103]:25: Connection refused)
8056D75DD@annashouse.net
2268D15B9 3625 Tue Dec 4 22:59:38 MAILER-DAEMON
(connect to mx.silentpro.de[141.8.224.137]:25: Connection timed out)
joness@mx.silentpro.de
2CC981785 3235 Fri Dec 7 06:02:20 MAILER-DAEMON
(host mx5.mail.yahoo.co.jp[183.79.57.236] refused to talk to me: 553 Mail from 37.59.52.173 not allowed - VS98-IP0 deferred - see http://help.yahoo.co.jp/help/jp/mail/anti-spam/anti-spam-24.html)
watarulyoukoq7@yahoo.co.jp
2A89D1743 3663 Thu Dec 6 20:12:51 MAILER-DAEMON
(connect to faye.localdns.com[119.110.108.55]:25: Connection timed out)
eames@faye.localdns.com
2117315BD 2892 Tue Dec 4 23:00:46 MAILER-DAEMON
(connect to la.consulting.com[82.98.86.161]:25: Connection timed out)
D1E8775DC@la.consulting.com
22B7B1613 3724 Tue Dec 4 23:02:32 MAILER-DAEMON
(connect to weblinux3.gtdinternet.com[201.238.246.20]:25: Connection timed out)
bimetallistic@weblinux3.gtdinternet.com
2EE3517B2 2905 Fri Dec 7 10:21:00 MAILER-DAEMON
(connect to snyfkdvmuwpuln.dleh.com[98.124.198.1]:25: Connection refused)
022BF97F0@snyfkdvmuwpuln.dleh.com
432931686 3706 Fri Dec 7 01:25:34 MAILER-DAEMON
(connect to gic-web-bsd-010.genotec.ch[82.195.224.110]:25: Connection timed out)
ajdecatur@gic-web-bsd-010.genotec.ch
4A5421705 3700 Thu Dec 6 10:52:02 MAILER-DAEMON
(connect to vz231.worldserver.net[80.81.243.131]:25: Connection refused)
s1954@vz231.worldserver.net
42AC61672 3732 Tue Dec 4 21:32:23 MAILER-DAEMON
(host eagle135.startdedicated.com[69.64.34.106] said: 451 Temporary local problem - please try later (in reply to RCPT TO command))
ables@eagle135.startdedicated.com
400201470 3866 Fri Dec 7 17:10:40 MAILER-DAEMON
(connect to mail.centraltx.us[63.96.10.3]:25: Connection refused)
SantiagoBoekhout@centraltx.us
4FACD1671 2804 Tue Dec 4 12:45:18 MAILER-DAEMON
(Host or domain name not found. Name service error for name=datwm.com type=MX: Host not found, try again)
7650119@datwm.com
C75D21582 2854 Wed Dec 5 18:38:13 MAILER-DAEMON
(Host or domain name not found. Name service error for name=carbonbasket.com type=MX: Host not found, try again)
003DE47AD@carbonbasket.com
C9CEC1492 2992 Fri Dec 7 19:38:29 MAILER-DAEMON
(connect to mx.kth.se[2001:6b0:1:1300:20e:7fff:fe26:4fe1]:25: No route to host)
albynn@neutron.kth.se
CD8E41607 2847 Wed Dec 5 09:09:23 MAILER-DAEMON
(connect to barleyandhopheads.com[98.129.229.195]:25: Connection timed out)
C1172C51@barleyandhopheads.com
149ED16D5 2824 Fri Dec 7 05:20:49 MAILER-DAEMON
(connect to livraria.pt[82.98.86.173]:25: Connection timed out)
6F547D3@livraria.pt
11650114D 7720 Fri Dec 7 20:22:31 MAILER-DAEMON
(host mx1.emailsrvr.com[98.129.184.131] said: 450 4.7.1 no_reply-PX@durham.com: Relay access unavailable. (in reply to RCPT TO command))
no_reply-PX@durham.com
1B9D5164B 2837 Tue Dec 4 12:45:16 MAILER-DAEMON
(connect to mx1.zonadeforos.com.ar[190.228.30.222]:25: Connection refused)
77F355A@zonadeforos.com.ar
1444B168E 3630 Tue Dec 4 20:16:14 MAILER-DAEMON
(connect to canada.com[199.71.40.135]:25: Connection timed out)
billzheng@canada.com
14D42158F 2873 Wed Dec 5 00:54:16 MAILER-DAEMON
(Host or domain name not found. Name service error for name=kavcolombia.com type=MX: Host not found, try again)
670299A6A@kavcolombia.com
94F1616EF 3774 Wed Dec 5 16:13:18 MAILER-DAEMON
(connect to mx1.securebank.com[10.42.23.11]:25: Connection timed out)
message@securebank.com
94EA61746 2875 Wed Dec 5 18:46:26 MAILER-DAEMON
(connect to cuxycoons.de[141.8.224.70]:25: Connection timed out)
55F3330E4@cuxycoons.de
F31F2158D 3495 Wed Dec 5 12:26:14 MAILER-DAEMON
(host mx1.mail.yahoo.co.jp[183.79.29.234] refused to talk to me: 553 Mail from 37.59.52.173 not allowed - VS98-IP0 deferred - see http://help.yahoo.co.jp/help/jp/mail/anti-spam/anti-spam-24.html)
gHightowerqday4Catherine@yahoo.co.jp
F091E1647 2876 Thu Dec 6 09:14:12 MAILER-DAEMON
(host mail.budgetawards.com[209.25.131.52] said: 451 qq write error or disk full (#4.3.0) (in reply to end of DATA command))
C81E866@budgetawards.com
E80B716CB 3681 Thu Dec 6 15:58:43 MAILER-DAEMON
(connect to cake.whatbox.ca[85.17.132.67]:25: Connection timed out)
jvanderlinden@cake.whatbox.ca
E03371645 2810 Wed Dec 5 02:24:12 MAILER-DAEMON
(host mailx.hoster.ru[195.128.50.36] said: 451 Greylisting is in progress. Please, delay the message for at least 15 minutes before retry. (in reply to DATA command))
7CC57E9@hotsys.ru
ED908168B 2843 Wed Dec 5 02:27:41 MAILER-DAEMON
(Host or domain name not found. Name service error for name=anjcs.com type=MX: Host not found, try again)
F7A584D@anjcs.com
ED3BD1748 3667 Thu Dec 6 18:06:37 MAILER-DAEMON
(connect to mx3.mail.yahoo.co.jp[183.79.57.237]:25: Connection timed out)
0parentage5LenardrDooley@yahoo.co.jp
E31621754 3070 Thu Dec 6 21:55:56 MAILER-DAEMON
(host mail-fwd.mx.g19.rapidsite.net[199.239.254.18] said: 451 Could not load DRD for domain (sailmaker.com) rcpt (alberwickcolon@sailmaker.com) (in reply to RCPT TO command))
alberwickcolon@sailmaker.com
E281A16A2 3614 Tue Dec 4 21:49:05 MAILER-DAEMON
(connect to ns202330.ovh.net[91.121.145.21]:25: Connection refused)
heeepp56@ns202330.ovh.net
ED1FC1787 2928 Thu Dec 6 21:01:48 MAILER-DAEMON
(Host or domain name not found. Name service error for name=gdaccountingservices.com type=MX: Host not found, try again)
2B0B1FF@gdaccountingservices.com
EE2D61707 3783 Wed Dec 5 16:30:15 MAILER-DAEMON
(connect to mx1.securebank.com[10.42.23.11]:25: Connection timed out)
message@securebank.com
EE5221741 2899 Wed Dec 5 16:40:29 MAILER-DAEMON
(connect to inforcentral.com[82.98.86.172]:25: Connection timed out)
3175449B@inforcentral.com
8E751168C 3619 Tue Dec 4 20:10:46 MAILER-DAEMON
(connect to ftp.cmp.cl[200.72.11.132]:25: Connection timed out)
ly.flees@ftp.cmp.cl
8A9AF16DA 7580 Wed Dec 5 06:20:15 MAILER-DAEMON
(connect to mx1.rural.com[10.42.23.11]:25: Connection timed out)
aldohey@rural.com
8323E1644 2898 Tue Dec 4 19:35:38 MAILER-DAEMON
(Host or domain name not found. Name service error for name=hutchisonbuilders.co.nz type=MX: Host not found, try again)
FD9C50B98@hutchisonbuilders.co.nz
8DB69170C 2885 Wed Dec 5 03:13:58 MAILER-DAEMON
(connect to ALT2.ASPMX.L.GOOGLE.COM[2a00:1450:4008:c01::1a]:25: No route to host)
4CD4B21C@aethon.co.uk
87A1A174B 2846 Wed Dec 5 07:19:45 MAILER-DAEMON
(connect to mail.protoncy.gr[195.46.5.82]:25: No route to host)
EA5EC91@protoncy.gr
8291D1AE7 2845 Fri Dec 7 12:24:54 MAILER-DAEMON
(connect to lucanux.com[141.8.224.25]:25: Connection timed out)
D5D0AB3D@lucanux.com
8F26A15A0 2819 Wed Dec 5 00:54:16 MAILER-DAEMON
(host mail.premix.se[80.68.123.244] said: 450 Requested mail action not taken: mailbox unavailable (in reply to end of DATA command))
6C403FB@premix.se
6CADC179C 2855 Fri Dec 7 02:30:58 MAILER-DAEMON
(Host or domain name not found. Name service error for name=gwconsumer.com type=MX: Host not found, try again)
490DC7180@gwconsumer.com
622FB172C 3691 Thu Dec 6 19:51:49 MAILER-DAEMON
(host eagle135.startdedicated.com[69.64.34.106] said: 451 Temporary local problem - please try later (in reply to RCPT TO command))
rd743@eagle135.startdedicated.com
631CB16D1 2916 Tue Dec 4 21:27:22 MAILER-DAEMON
(host mail-fwd.mx.g19.rapidsite.net[199.239.254.18] said: 451 Could not load DRD for domain (lakesideguitars.com) rcpt (5d693aa2@lakesideguitars.com) (in reply to RCPT TO command))
5D693AA2@lakesideguitars.com
64ABD16D7 3618 Wed Dec 5 00:16:09 MAILER-DAEMON
(host condor.narzan.com[212.96.101.66] said: 450 4.1.1 lxoda@condor.narzan.com: Recipient address rejected: User unknown in local recipient table (in reply to RCPT TO command))
lxoda@condor.narzan.com
6F82A127A 3314 Fri Dec 7 15:13:01 MAILER-DAEMON
(connect to mx1.securebank.com[10.42.23.11]:25: Connection timed out)
message@securebank.com
68092158E 3913 Tue Dec 4 21:16:23 MAILER-DAEMON
(host static-ip-188-138-96-241.inaddr.ip-pool.com[188.138.96.241] said: 451 4.7.1 Service unavailable - try again later (in reply to MAIL FROM command))
chang3482@static-ip-188-138-96-241.inaddr.ip-pool.com
680D4174C 2848 Wed Dec 5 19:30:31 MAILER-DAEMON
(Host or domain name not found. Name service error for name=mastermakeover.com type=MX: Host not found, try again)
C8FFFEB@mastermakeover.com
A0704159A 3825 Tue Dec 4 20:31:16 MAILER-DAEMON
(connect to static.16.105.9.5.clients.your-server.de[5.9.105.16]:25: Connection refused)
foodbank@static.16.105.9.5.clients.your-server.de
AE73E162A 2862 Tue Dec 4 19:31:50 MAILER-DAEMON
(connect to kamichijackson.com[208.91.197.27]:25: Connection timed out)
85AA5E7@kamichijackson.com
AC0081702 2880 Thu Dec 6 16:15:31 MAILER-DAEMON
(connect to pyramidpublication.com[208.91.197.101]:25: Connection timed out)
7BFD4D6BB@pyramidpublication.com
A40B717CD 3666 Thu Dec 6 23:30:38 MAILER-DAEMON
(connect to hosting.netrator.pl[195.110.48.2]:25: Connection refused)
ukabctravelm@hosting.netrator.pl
592561640 3818 Tue Dec 4 19:55:52 MAILER-DAEMON
(connect to host-88-215-138-122.stv.ru[88.215.138.122]:25: Connection refused)
billingsdd@host-88-215-138-122.stv.ru
57999179B 3608 Fri Dec 7 04:17:18 MAILER-DAEMON
(connect to reverse-89-106-12-63.turkticaret.net[89.106.14.231]:25: Connection refused)
matthias.horn@reverse-89-106-12-63.turkticaret.net
544F217B3 2842 Fri Dec 7 10:23:52 MAILER-DAEMON
(host mailx.hoster.ru[195.128.50.36] said: 451 Greylisting is in progress. Please, delay the message for at least 15 minutes before retry. (in reply to DATA command))
4D02F55@higea.ru
– 263 Kbytes in 74 Requests.[/code]
Again, there is not a SINGLE address in there I recognize.
Running postcat on a randomly selected message:
[code]*** ENVELOPE RECORDS deferred/A/AE73E162A ***
message_size: 2862 225 1 0 2862
message_arrival_time: Tue Dec 4 20:31:50 2012
create_time: Tue Dec 4 20:31:50 2012
named_attribute: log_message_origin=local
named_attribute: trace_flags=0
sender:
original_recipient: 85AA5E7@kamichijackson.com
recipient: 85AA5E7@kamichijackson.com
*** MESSAGE CONTENTS deferred/A/AE73E162A ***
Received: by dedi-fr-57196.op-net.com (Postfix)
id AE73E162A; Tue, 4 Dec 2012 20:31:50 +0100 (CET)
Date: Tue, 4 Dec 2012 20:31:50 +0100 (CET)
From: MAILER-DAEMON@dedi-fr-57196.op-net.com (Mail Delivery System)
Subject: Undelivered Mail Returned to Sender
To: 85AA5E7@kamichijackson.com
Auto-Submitted: auto-replied
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
boundary=“7182C1584.1354649510/dedi-fr-57196.op-net.com”
Content-Transfer-Encoding: 8bit
Message-Id: 20121204193150.AE73E162A@dedi-fr-57196.op-net.com
This is a MIME-encapsulated message.
–7182C1584.1354649510/dedi-fr-57196.op-net.com
Content-Description: Notification
Content-Type: text/plain; charset=us-ascii
This is the mail system at host dedi-fr-57196.op-net.com.
I’m sorry to have to inform you that your message could not
be delivered to one or more recipients. It’s attached below.
For further assistance, please send mail to postmaster.
If you do so, please include this problem report. You can
delete your own text from the attached returned message.
The mail system
BOUNCE@dedi-fr-57196.op-net.com (expanded from pamltup@nothing-less.net):
unknown user: “bounce”
–7182C1584.1354649510/dedi-fr-57196.op-net.com
Content-Description: Delivery report
Content-Type: message/delivery-status
Reporting-MTA: dns; dedi-fr-57196.op-net.com
X-Postfix-Queue-ID: 7182C1584
X-Postfix-Sender: rfc822; 85AA5E7@kamichijackson.com
Arrival-Date: Tue, 4 Dec 2012 20:31:50 +0100 (CET)
Final-Recipient: rfc822; BOUNCE@dedi-fr-57196.op-net.com
Original-Recipient: rfc822;pamltup@nothing-less.net
Action: failed
Status: 5.1.1
Diagnostic-Code: X-Postfix; unknown user: “bounce”
–7182C1584.1354649510/dedi-fr-57196.op-net.com
Content-Description: Undelivered Message
Content-Type: message/rfc822
Content-Transfer-Encoding: 8bit
Return-Path: 85AA5E7@kamichijackson.com
Received: from [62.94.156.19] (unknown [62.94.156.19])
by dedi-fr-57196.op-net.com (Postfix) with SMTP id 7182C1584
for pamltup@nothing-less.net; Tue, 4 Dec 2012 20:31:50 +0100 (CET)
From: “Order Viagara” 85AA5E7@kamichijackson.com
Subject: Ultra fast delivery
To: pamltup@nothing-less.net
List-Unsubscribe: mailto:158578774DD5A10F@politikcity.de
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; chars=“iso-8859-1”
Date: Tue, 04 Dec 2012 20:31:16 +0200
Message-ID: 20121204203116.1C1B162EC572265661F4E.CA6A1@LEODARI-BBB2A69
Yo, friend pamltup!
Ship worldwide
Keep your body in balance! Buy meds from us!
** Porpecia - 0.21$
** Levitr - 1.63$
++ Cialis - 1.73$
– Viarga - 0.53$
Bad heathcare getting you sick and tired? Our pharmacy will give you decent help for less money!
http://ELZw.doctorrayo.ru/
–7182C1584.1354649510/dedi-fr-57196.op-net.com–
*** HEADER EXTRACTED deferred/A/AE73E162A ***
named_attribute: encoding=8bit
*** MESSAGE FILE END deferred/A/AE73E162A ***[/code]
Now this is interesting! It’s most definitely SPAM, and nothing-less.net is one of the domains on my server. I’ve disabled it for now - does that mean that user was compromised, maybe hacked into or something?