I am extremely perplexed by these error notifications I am receiving from my Mailgateway.
This email address (supplier@mail.domain.tld), which does not exist, is involved somehow and I am confused where it is coming from, and why I keep finding it in all domains outgoing and incoming email addresses.
The error emails I am receiving everyday are as follows:
When I look at my tracking log and filter by "supplier@mail.domain.tld" I see a ton of incoming and outgoing messages that look like this:
Here is what I pulled from my Syslog around the same time as above:
What the hell am I looking at?
I've seen reference to a similar issue here:
https://forum.proxmox.com/threads/451-4-3-0-error-queue-file-write-error.76423/
But I am not using any plugins, is this an issue with DNSBLs or Bayes?
The only thing I've adjusted as of late is upping my heuristic score from 3 to 5 and swapping out some DNSBLs.
This still leaves me perplex by this "supplier@mail.domain.tld".
First off, again I don't have a mailbox or account setup with that name.
Secondly, even if I did, my mailboxes are setup as "name@domain.tld" not "name@mail.domain.tld"
My logs are FULL of these instances, constantly. I have no idea what is going on. Has anyone else encountered this?
Thanks in advance.
This email address (supplier@mail.domain.tld), which does not exist, is involved somehow and I am confused where it is coming from, and why I keep finding it in all domains outgoing and incoming email addresses.
The error emails I am receiving everyday are as follows:
Code:
Mail Delivery System posted 21/03/22 3:06 AM Proxmox SMTP server: errors from mail.domain.tld[192.168.1.1]
Transcript of session follows.
In: MAIL FROM: SIZE=36772
Out: 250 2.1.0 Ok
In: RCPT TO:<supplier>
ORCPT=rfc822;supplier@mail.domain.tld
Out: 250 2.1.5 Ok
In: BDAT 27384 LAST
Out: 250 2.5.0 OK (12053C6237DD3AEAF1C)
In: MAIL FROM: SIZE=28313
Out: 250 2.1.0 Ok
In: RCPT TO:<supplier>
ORCPT=rfc822;supplier@mail.domain.tld
Out: 250 2.1.5 Ok
In: BDAT 18518 LAST
Out: 250 2.5.0 OK (12053C6237DD3D22443)
In: MAIL FROM: SIZE=28314
Out: 250 2.1.0 Ok
In: RCPT TO:<supplier>
ORCPT=rfc822;supplier@mail.domain.tld
Out: 250 2.1.5 Ok
In: BDAT 18518 LAST
Out: 250 2.5.0 OK (12053C6237DD3F8BC7F)
In: MAIL FROM: SIZE=36758
Out: 250 2.1.0 Ok
In: RCPT TO:<supplier>
ORCPT=rfc822;supplier@mail.domain.tld
Out: 250 2.1.5 Ok
In: BDAT 27384 LAST
Out: 250 2.5.0 OK (12053C6237DD41CF5B4)
In: MAIL FROM: SIZE=28362
Out: 250 2.1.0 Ok
In: RCPT TO:<supplier>
ORCPT=rfc822;supplier@mail.domain.tld
Out: 250 2.1.5 Ok
In: BDAT 18518 LAST
Out: 250 2.5.0 OK (12053C6237DD440DE6D)
In: MAIL FROM: SIZE=28361
Out: 250 2.1.0 Ok
In: RCPT TO:<supplier>
ORCPT=rfc822;supplier@mail.domain.tld
Out: 250 2.1.5 Ok
In: BDAT 18518 LAST
Out: 250 2.5.0 OK (12053C6237DD464BE2A)
In: MAIL FROM: SIZE=36758
Out: 250 2.1.0 Ok
In: RCPT TO:<supplier>
ORCPT=rfc822;supplier@mail.domain.tld
Out: 250 2.1.5 Ok
In: BDAT 27384 LAST
Out: 451 4.3.0 Error: queue file write error
In: QUIT
Out: 221 2.0.0 Bye
For other details, see the local mail logfile</supplier></supplier></supplier></supplier></supplier></supplier></supplier>
When I look at my tracking log and filter by "supplier@mail.domain.tld" I see a ton of incoming and outgoing messages that look like this:
Code:
Mar 23 09:54:51 mailgate postfix/smtpd[1509659]: connect from srvex2013.domain.tld[192.168.180]
Mar 23 09:54:51 mailgate postfix/smtpd[1509659]: Anonymous TLS connection established from srvex2013.domain.tld[192.168.180]: TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)
Mar 23 09:54:51 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:54:54 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE05BE921C); from=<> to=<no-reply@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:54:54 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:54:55 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE05E21395); from=<booking@domain.tld> to=<info@hoteldelaville.org> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:54:55 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:54:57 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE05FB6CD1); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:54:58 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:00 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE0624640E); from=<> to=<no-reply@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:00 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:02 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE0648F97F); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:02 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:04 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE066B967A); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:04 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:07 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE068E4936); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:07 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:09 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE06B905D6); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:09 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:11 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE06DBFF86); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:11 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:12 mailgate pmg-smtp-filter[1516420]: 12056A623AE07005811: new mail message-id=<3dec71cf590a43efa09687ffb426fa6b@srvex2013.domain.tld>#012
Mar 23 09:55:13 mailgate pmg-smtp-filter[1516420]: 12056A623AE07005811: SA score=0/5 time=1.725 bayes=0.00 autolearn=ham autolearn_force=no hits=ALL_TRUSTED(-1),AWL(0.120),BAYES_00(-1.9),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_BLOCKED(0.001)
Mar 23 09:55:13 mailgate postfix/smtpd[1516321]: connect from localhost.localdomain[127.0.0.1]
Mar 23 09:55:13 mailgate postfix/smtpd[1516321]: D0380E1190: client=localhost.localdomain[127.0.0.1], orig_client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:13 mailgate postfix/cleanup[1516114]: D0380E1190: message-id=<3dec71cf590a43efa09687ffb426fa6b@srvex2013.domain.tld>
Mar 23 09:55:13 mailgate postfix/qmgr[1313648]: D0380E1190: from=<s.battazza@domain.tld>, size=32949, nrcpt=1 (queue active)
Mar 23 09:55:13 mailgate pmg-smtp-filter[1516420]: 12056A623AE07005811: accept mail to <pauline.lehmann@hiltonstrasbourg.com> (D0380E1190) (rule: default-accept)
Mar 23 09:55:13 mailgate postfix/smtpd[1516321]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Mar 23 09:55:13 mailgate pmg-smtp-filter[1516420]: 12056A623AE07005811: processing time: 1.88 seconds (1.725, 0.059, 0)
Mar 23 09:55:13 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE07005811); from=<s.battazza@domain.tld> to=<pauline.lehmann@hiltonstrasbourg.com> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:13 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:14 mailgate postfix/smtp[1515690]: Trusted TLS connection established to hiltonstrasbourg-com.mail.protection.outlook.com[104.47.8.36]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Mar 23 09:55:14 mailgate postfix/smtp[1515690]: D0380E1190: to=<pauline.lehmann@hiltonstrasbourg.com>, relay=hiltonstrasbourg-com.mail.protection.outlook.com[104.47.8.36]:25, delay=0.9, delays=0.05/0/0.46/0.39, dsn=2.6.0, status=sent (250 2.6.0 <3dec71cf590a43efa09687ffb426fa6b@srvex2013.domain.tld> [InternalId=102349070685070, Hostname=AM7PR09MB4101.eurprd09.prod.outlook.com] 43355 bytes in 0.086, 490.513 KB/sec Queued mail for delivery)
Mar 23 09:55:14 mailgate postfix/qmgr[1313648]: D0380E1190: removed
Mar 23 09:55:17 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE071E7D41); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:17 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:20 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE075D0B11); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:20 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:22 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE0780DFAC); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:22 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:24 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE07A257ED); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:24 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:26 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE07C72088); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:26 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:28 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE07E8EC30); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:28 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:31 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE080D51F0); from=<> to=<supplier@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:31 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:33 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE08344EBA); from=<> to=<no-reply@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:33 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:35 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE08576A35); from=<> to=<no-reply@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:35 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.180]
Mar 23 09:55:37 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE087A4AEC); from=<> to=<no-reply@mail.domain.tld> proto=ESMTP helo=<mail.domain.tld>
Mar 23 09:55:37 mailgate postfix/smtpd[1509659]: disconnect from srvex2013.domain.tld[192.168.180] ehlo=2 starttls=1 mail=20 rcpt=20 bdat=20 quit=1 commands=64
Here is what I pulled from my Syslog around the same time as above:
Code:
Mar 23 09:54:54 mailgate postfix/qmgr[1313648]: 0A3E5E1190: from=<>, size=21277, nrcpt=1 (queue active)
Mar 23 09:54:54 mailgate pmg-smtp-filter[1516312]: 12056A623AE05BE921C: accept mail to <no-reply@mail.domain.tld> (0A3E5E1190) (rule: default-accept)
Mar 23 09:54:54 mailgate postfix/smtpd[1516321]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Mar 23 09:54:54 mailgate pmg-smtp-filter[1516312]: 12056A623AE05BE921C: processing time: 2.136 seconds (2.013, 0.039, 0)
Mar 23 09:54:54 mailgate postfix/smtpd[1509659]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (12056A623AE05BE921C); from=<> to=<no-reply@mail.domain.tld> proto=ESMTP helo=<mai>
Mar 23 09:54:54 mailgate postfix/smtpd[1509659]: NOQUEUE: client=srvex2013.domain.tld[192.168.1.80]
Mar 23 09:54:54 mailgate pmg-smtp-filter[1516324]: 2022/03/23-09:54:54 CONNECT TCP Peer: "[127.0.0.1]:38506" Local: "[127.0.0.1]:10023"
Mar 23 09:54:54 mailgate pmg-smtp-filter[1516324]: 12056A623AE05E21395: new mail message-id=<fbb379cd413d481f93eeff021cbb4893@srvex2013.domain.tld>#012
Mar 23 09:54:54 mailgate postfix/smtp[1515941]: Trusted TLS connection established to mail.domain.tld[192.168.1.80]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 b>
Mar 23 09:54:55 mailgate postfix/smtp[1515941]: 0A3E5E1190: to=<no-reply@mail.domain.tld>, relay=mail.domain.tld[192.168.1.80]:25, delay=1.3, delays=0.05/0/0.2/1.1, dsn=>
Mar 23 09:54:55 mailgate postfix/qmgr[1313648]: 0A3E5E1190: removed
Mar 23 09:54:55 mailgate postfix/postscreen[1515396]: PASS NEW [209.85.221.47]:44819
Mar 23 09:54:55 mailgate postfix/smtpd[1514779]: connect from mail-wr1-f47.google.com[209.85.221.47]
Mar 23 09:54:55 mailgate pmg-smtp-filter[1516324]: 12056A623AE05E21395: SA score=0/5 time=1.446 bayes=0.00 autolearn=no autolearn_force=no hits=ALL_TRUSTED(-1),AWL(-0.059),BAYES_0>
Mar 23 09:54:55 mailgate postfix/smtpd[1516321]: connect from localhost.localdomain[127.0.0.1]
Mar 23 09:54:55 mailgate postfix/smtpd[1516321]: A8536E1190: client=localhost.localdomain[127.0.0.1], orig_client=srvex2013.domain.tld[192.168.1.80]
Mar 23 09:54:55 mailgate postfix/smtpd[1514779]: Anonymous TLS connection established from mail-wr1-f47.google.com[209.85.221.47]: TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/>
Mar 23 09:54:55 mailgate postfix/cleanup[1516114]: A8536E1190: message-id=<fbb379cd413d481f93eeff021cbb4893@srvex2013.domain.tld>
What the hell am I looking at?
I've seen reference to a similar issue here:
https://forum.proxmox.com/threads/451-4-3-0-error-queue-file-write-error.76423/
But I am not using any plugins, is this an issue with DNSBLs or Bayes?
The only thing I've adjusted as of late is upping my heuristic score from 3 to 5 and swapping out some DNSBLs.
This still leaves me perplex by this "supplier@mail.domain.tld".
First off, again I don't have a mailbox or account setup with that name.
Secondly, even if I did, my mailboxes are setup as "name@domain.tld" not "name@mail.domain.tld"
My logs are FULL of these instances, constantly. I have no idea what is going on. Has anyone else encountered this?
Thanks in advance.