[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] Sendmail error messages?



I'm trying to figure out what all of these messages mean that are being
generated on a Raq3 box? Is someone trying to use our box to relay spam
mail? And if so, how can I stop them?

My fear is that stuff is getting through because these error messages are
only stating that "Sender domain must exist". So, I assume that if the
sender domain was a valid one, then sendmail will relay their e-mail?
Correct me if I'm wrong.

By the way, this raq box has been updated w/ all the latest updates. What
I'm wondering is we used to have an old version of pop-before-smtp on this
box and then we installed Cobalts version. Could this be part of the
problem?

May 11 08:58:50 dns1 sendmail[23891]: IAA23891: ruleset=check_mail,
arg1=<estokes170@xxxxxxxxxxxxxxxx>, relay=cdshop.photodisc.de
[193.97.202.146],
reject=501 <estokes170@xxxxxxxxxxxxxxxx>... Sender domain must exist
May 12 06:43:24 dns1 sendmail[15137]: GAA15137: ruleset=check_mail,
arg1=<sentto-109088-14201-989664153-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>,
relay=hp.egroups.com [208.50.99.201], reject=451
<sentto-109088-14201-989664153-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>...
Sender
domain must resolve
May 12 07:42:30 dns1 sendmail[17431]: HAA17431: ruleset=check_mail,
arg1=<sentto-109088-14202-989667700-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>,
relay=n1.groups.yahoo.com [216.115.96.51], reject=451
<sentto-109088-14202-989667700-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>...
Sender
domain must resolve
May 12 07:55:11 dns1 sendmail[17935]: HAA17935: ruleset=check_mail,
arg1=<sentto-109088-14203-989668461-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>,
relay=ch.egroups.com [208.50.99.226], reject=451
<sentto-109088-14203-989668461-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>...
Sender
domain must resolve
May 12 07:57:30 dns1 sendmail[18013]: HAA18013: ruleset=check_mail,
arg1=<sentto-109088-14204-989668629-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>,
relay=mu.egroups.com [64.211.240.238], reject=451
<sentto-109088-14204-989668629-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>...
Sender
domain must resolve
May 12 08:23:07 dns1 sendmail[19012]: IAA19012: ruleset=check_mail,
arg1=<sentto-109088-14205-989670167-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>,
relay=fl.egroups.com [64.211.240.233], reject=451
<sentto-109088-14205-989670167-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>...
Sender
domain must resolve
May 12 08:33:11 dns1 sendmail[19420]: IAA19420: ruleset=check_mail,
arg1=<sentto-109088-14206-989670741-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>,
relay=hl.egroups.com [208.50.99.197], reject=451
<sentto-109088-14206-989670741-wppiphoto=wppi.com@xxxxxxxxxxxxxxxxxxx>...
Sender
domain must resolve

Thanks!

SW