Thanks Ken-ji,
Thanks very much for that - certainly I think the amount of spam I've been getting has reduced since adding this as you recommended:
Code:
smtpd_client_restrictions = reject_rbl_client bl.spamcop.net,
reject_rbl_client dnsbl.sorbs.net,
reject_rbl_client cbl.abuseat.org
Do you think this is looking healthier? I'll be honest, I don't know what to look for here...
Code:
Sep 2 19:40:30 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected for inactivity bytes=151/1533
Sep 2 19:40:30 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=612/133267
Sep 2 19:40:31 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected for inactivity bytes=369/932
Sep 2 19:40:31 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected for inactivity bytes=283/1977
Sep 2 19:41:30 skynet postfix/anvil[9261]: statistics: max connection rate 1/60s for (smtp:208.117.50.137) at Sep 2 19:38:07
Sep 2 19:41:30 skynet postfix/anvil[9261]: statistics: max connection count 1 for (smtp:208.117.50.137) at Sep 2 19:38:07
Sep 2 19:41:30 skynet postfix/anvil[9261]: statistics: max cache size 1 at Sep 2 19:38:07
Sep 2 19:41:35 skynet postfix/smtpd[9344]: warning: 58.19.191.89: address not listed for hostname 58.19.arpa.hb.cnc.cn
Sep 2 19:41:35 skynet postfix/smtpd[9344]: connect from unknown[58.19.191.89]
Sep 2 19:41:36 skynet postfix/smtpd[9344]: NOQUEUE: reject: RCPT from unknown[58.19.191.89]: 554 5.7.1 Service unavailable; Client host [58.19.191.89] blocked using cbl.abuseat.org; Blocked - see http://cbl.abuseat.org/lookup.cgi?ip=58.19.191.89; from=<be@ie.net> to=<www-data@skynet.pixelatedphotographer.com> proto=ESMTP helo=<ie.net>
Sep 2 19:41:36 skynet postfix/smtpd[9344]: lost connection after RCPT from unknown[58.19.191.89]
Sep 2 19:41:36 skynet postfix/smtpd[9344]: disconnect from unknown[58.19.191.89]
Sep 2 19:41:37 skynet postfix/smtpd[9344]: warning: 58.19.191.89: address not listed for hostname 58.19.arpa.hb.cnc.cn
Sep 2 19:41:37 skynet postfix/smtpd[9344]: connect from unknown[58.19.191.89]
Sep 2 19:41:37 skynet postfix/smtpd[9344]: NOQUEUE: reject: RCPT from unknown[58.19.191.89]: 554 5.7.1 Service unavailable; Client host [58.19.191.89] blocked using cbl.abuseat.org; Blocked - see http://cbl.abuseat.org/lookup.cgi?ip=58.19.191.89; from=<ezhyp@bj.org> to=<www-data@skynet.pixelatedphotographer.com> proto=ESMTP helo=<bj.org>
Sep 2 19:41:38 skynet postfix/smtpd[9344]: lost connection after RCPT from unknown[58.19.191.89]
Sep 2 19:41:38 skynet postfix/smtpd[9344]: disconnect from unknown[58.19.191.89]
Sep 2 19:44:58 skynet postfix/anvil[9346]: statistics: max connection rate 2/60s for (smtp:58.19.191.89) at Sep 2 19:41:37
Sep 2 19:44:58 skynet postfix/anvil[9346]: statistics: max connection count 1 for (smtp:58.19.191.89) at Sep 2 19:41:35
Sep 2 19:44:58 skynet postfix/anvil[9346]: statistics: max cache size 1 at Sep 2 19:41:35
Sep 2 19:47:52 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 19:55:12 skynet postfix/smtpd[9532]: connect from unknown[41.143.198.88]
Sep 2 19:55:13 skynet postfix/smtpd[9532]: NOQUEUE: reject: RCPT from unknown[41.143.198.88]: 554 5.7.1 Service unavailable; Client host [41.143.198.88] blocked using cbl.abuseat.org; Blocked - see http://cbl.abuseat.org/lookup.cgi?ip=41.143.198.88; from=<chris318@antoinegonin.com> to=<chris@pixelatedphotographer.com> proto=ESMTP helo=<[41.143.198.88]>
Sep 2 19:55:13 skynet postfix/smtpd[9532]: disconnect from unknown[41.143.198.88]
Sep 2 19:58:34 skynet postfix/anvil[9535]: statistics: max connection rate 1/60s for (smtp:41.143.198.88) at Sep 2 19:55:12
Sep 2 19:58:34 skynet postfix/anvil[9535]: statistics: max connection count 1 for (smtp:41.143.198.88) at Sep 2 19:55:12
Sep 2 19:58:34 skynet postfix/anvil[9535]: statistics: max cache size 1 at Sep 2 19:55:12
Sep 2 19:58:46 skynet dovecot: imap-login: Login: user=<m@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 19:58:50 skynet dovecot: imap-login: Login: user=<m@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 19:59:08 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected: Logged out bytes=471/2258
Sep 2 19:59:08 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected: Logged out bytes=285/1630
Sep 2 19:59:37 skynet dovecot: imap-login: Login: user=<junkstuff@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 19:59:40 skynet dovecot: imap-login: Aborted login (auth failed, 1 attempts): user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 19:59:46 skynet dovecot: IMAP(junkstuff@pixelatedphotographer.com): Disconnected: Logged out bytes=277/969
Sep 2 20:00:56 skynet dovecot: imap-login: Login: user=<m@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:04:00 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected: Logged out bytes=984/2953
Sep 2 20:04:25 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected in IDLE bytes=551/2103
Sep 2 20:04:27 skynet dovecot: IMAP(m@pixelatedphotographer.com): Connection closed bytes=6833/10614
Sep 2 20:04:27 skynet dovecot: IMAP(m@pixelatedphotographer.com): Connection closed bytes=107/2020
Sep 2 20:04:27 skynet dovecot: IMAP(m@pixelatedphotographer.com): Connection closed bytes=63/1280
Sep 2 20:04:29 skynet dovecot: imap-login: Login: user=<m@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:04:30 skynet dovecot: imap-login: Login: user=<m@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:04:30 skynet dovecot: IMAP(m@pixelatedphotographer.com): Connection closed bytes=19/332
Sep 2 20:04:31 skynet dovecot: imap-login: Login: user=<m@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:05:52 skynet dovecot: last message repeated 2 times
Sep 2 20:16:02 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Connection closed bytes=984/2533
Sep 2 20:16:08 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:19:30 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=352/1548
Sep 2 20:21:38 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:26:44 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=352/1523
Sep 2 20:33:26 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:34:39 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected for inactivity bytes=810/22027
Sep 2 20:37:28 skynet dovecot: imap-login: Login: user=<junkstuff@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:37:32 skynet dovecot: imap-login: Aborted login (auth failed, 1 attempts): user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:37:39 skynet dovecot: IMAP(junkstuff@pixelatedphotographer.com): Disconnected: Logged out bytes=277/969
Sep 2 20:38:52 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected in IDLE bytes=898/2720
Sep 2 20:41:42 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=352/1523
Sep 2 20:45:28 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected for inactivity bytes=1767/50948
Sep 2 20:50:28 skynet dovecot: IMAP(m@pixelatedphotographer.com): Disconnected for inactivity bytes=9328/15990
Sep 2 20:51:33 skynet postfix/smtpd[10553]: connect from unknown[89.137.130.186]
Sep 2 20:51:34 skynet postfix/smtpd[10553]: NOQUEUE: reject: RCPT from unknown[89.137.130.186]: 554 5.7.1 Service unavailable; Client host [89.137.130.186] blocked using dnsbl.sorbs.net; Exploitable Server See: http://www.sorbs.net/lookup.shtml?89.137.130.186 / Currently Sending Spam See: http://www.sorbs.net/lookup.shtml?89.137.130.186; from=<chris12@ahchamber.org> to=<chris@pixelatedphotographer.com> proto=ESMTP helo=<ADA-PC>
Sep 2 20:51:34 skynet postfix/smtpd[10553]: disconnect from unknown[89.137.130.186]
Sep 2 20:54:54 skynet postfix/anvil[10555]: statistics: max connection rate 1/60s for (smtp:89.137.130.186) at Sep 2 20:51:33
Sep 2 20:54:54 skynet postfix/anvil[10555]: statistics: max connection count 1 for (smtp:89.137.130.186) at Sep 2 20:51:33
Sep 2 20:54:54 skynet postfix/anvil[10555]: statistics: max cache size 1 at Sep 2 20:51:33
Sep 2 20:55:42 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 20:55:52 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=352/1523
Sep 2 21:05:19 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:08:25 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=552/1799
Sep 2 21:10:56 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:10:56 skynet postfix/smtpd[10839]: connect from p5175-ipngn4101marunouchi.tokyo.ocn.ne.jp[153.129.162.175]
Sep 2 21:10:57 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:10:57 skynet postfix/smtpd[10839]: disconnect from p5175-ipngn4101marunouchi.tokyo.ocn.ne.jp[153.129.162.175]
Sep 2 21:10:58 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:11:01 skynet dovecot: last message repeated 2 times
Sep 2 21:11:01 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Connection closed bytes=19/332
Sep 2 21:14:17 skynet postfix/anvil[10843]: statistics: max connection rate 1/60s for (submission:153.129.162.175) at Sep 2 21:10:56
Sep 2 21:14:17 skynet postfix/anvil[10843]: statistics: max connection count 1 for (submission:153.129.162.175) at Sep 2 21:10:56
Sep 2 21:14:17 skynet postfix/anvil[10843]: statistics: max cache size 1 at Sep 2 21:10:56
Sep 2 21:20:07 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:20:19 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=352/1523
Sep 2 21:22:05 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:28:02 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected in IDLE bytes=579/436553
Sep 2 21:30:38 skynet dovecot: imap-login: Login: user=<junkstuff@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:30:41 skynet dovecot: imap-login: Aborted login (auth failed, 1 attempts): user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:30:56 skynet dovecot: IMAP(junkstuff@pixelatedphotographer.com): Disconnected: Logged out bytes=277/969
Sep 2 21:32:45 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Disconnected: Logged out bytes=514/1343
Sep 2 21:39:30 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Connection closed bytes=107/1146
Sep 2 21:39:30 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Connection closed bytes=415/1361
Sep 2 21:39:30 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Connection closed bytes=283/1829
Sep 2 21:39:42 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:39:43 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:39:44 skynet postfix/smtpd[11357]: connect from p5175-ipngn4101marunouchi.tokyo.ocn.ne.jp[153.129.162.175]
Sep 2 21:39:44 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:39:45 skynet postfix/smtpd[11357]: disconnect from p5175-ipngn4101marunouchi.tokyo.ocn.ne.jp[153.129.162.175]
Sep 2 21:39:45 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:39:46 skynet dovecot: imap-login: Login: user=<chris@pixelatedphotographer.com>, method=PLAIN, rip=153.129.162.175, lip=173.230.147.71, TLS
Sep 2 21:39:47 skynet dovecot: IMAP(chris@pixelatedphotographer.com): Connection closed bytes=19/332
Sep 2 21:39:47 skynet postfix/smtpd[11357]: connect from p5175-ipngn4101marunouchi.tokyo.ocn.ne.jp[153.129.162.175]
Sep 2 21:39:48 skynet postfix/smtpd[11357]: disconnect from p5175-ipngn4101marunouchi.tokyo.ocn.ne.jp[153.129.162.175]
Looking at the link you sent over yesterday regarding the conf file - I noticed it has a restriction list example.
Would you recommend these (copy and pasted here)?
Code:
Examples of simple restriction lists are:
/etc/postfix/main.cf:
# Allow connections from trusted networks only.
smtpd_client_restrictions = permit_mynetworks, reject
# Don't talk to mail systems that don't know their own hostname.
# With Postfix < 2.3, specify reject_unknown_hostname.
smtpd_helo_restrictions = reject_unknown_helo_hostname
# Don't accept mail from domains that don't exist.
smtpd_sender_restrictions = reject_unknown_sender_domain
# Relay control (Postfix 2.10 and later): local clients and
# authenticated clients may specify any destination domain.
smtpd_relay_restrictions = permit_mynetworks,
permit_sasl_authenticated,
reject_unauth_destination
# Spam control: exclude local clients and authenticated clients
# from DNSBL lookups.
smtpd_recipient_restrictions = permit_mynetworks,
permit_sasl_authenticated,
# reject_unauth_destination is not needed here if the mail
# relay policy is specified under smtpd_relay_restrictions
# (available with Postfix 2.10 and later).
reject_unauth_destination
reject_rbl_client zen.spamhaus.org,
reject_rhsbl_helo dbl.spamhaus.org,
reject_rhsbl_sender dbl.spamhaus.org
# Block clients that speak too early.
smtpd_data_restrictions = reject_unauth_pipelining
# Enforce mail volume quota via policy service callouts.
smtpd_end_of_data_restrictions = check_policy_service unix:private/policy
Thanks very much for all your help!