How to detect compromised accounts?

ChiquiFornari

Member
Apr 22, 2020
6
1
23
43
I've had an email server which had a script to inmediately alert administrator if a user sent more than X mails a day/hour.
That way it was easy to quickly detect if an account was compromised and used to send spam and have it dealt with before making a lot a damage.

I've investigated Mail Filter rules but I don't think it can do that, or at least I couldn't figure out how.

Is there anything to do this -or another way to detect compromised accounts- in PMG?

Thank you
 
Last edited:
Currently there is no rate-limiting (or mail-counting) objects available in PMG - so this vector cannot be used.

Depending on your needs it can be enough to check the logs in a while - or have some monitoring script setup to watch the maillog for such behavior.

some users also setup postfwd for similar reasons (search the forum for postfwd)

I hope this helps!
 
  • Like
Reactions: ChiquiFornari

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!