Hello
yesterday i had some security issue on my mail server. some user trying to sent 20k mails. i cancel this operation after 6k mails but i wonder it is possible that on proxmox mail gtw (we used it in front of -> including outgoing traffic) will be some reglamentation to send lot of mail in the same time ? it is possible to hold this mails and notify the admin ? below two radnom mails. (i have bounced mails and delivered)
yesterday i had some security issue on my mail server. some user trying to sent 20k mails. i cancel this operation after 6k mails but i wonder it is possible that on proxmox mail gtw (we used it in front of -> including outgoing traffic) will be some reglamentation to send lot of mail in the same time ? it is possible to hold this mails and notify the admin ? below two radnom mails. (i have bounced mails and delivered)
Code:
Jul 5 17:20:40 mx postfix/smtpd[12580]: connect from mail-sensor.external.domain[X.X.X.X]
Jul 5 17:20:40 mx postfix/smtpd[12580]: 3F566405B2: client=mail-sensor.external.domain[X.X.X.X]
Jul 5 17:20:40 mx postfix/cleanup[12606]: 3F566405B2: message-id=<20210705162034.367C38DA2E341361@sender.domain>
Jul 5 17:20:40 mx postfix/qmgr[945]: 3F566405B2: from=<some_user@sender.domain>, size=8033, nrcpt=1 (queue active)
Jul 5 17:20:40 mx postfix/smtpd[12580]: disconnect from mail-sensor.external.domain[X.X.X.X] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7
Jul 5 17:20:40 mx pmg-smtp-filter[12529]: 60F1B60E323484103B: new mail message-id=<20210705162034.367C38DA2E341361@sender.domain>#012
Jul 5 17:20:40 mx postfix/smtpd[12565]: connect from localhost.localdomain[127.0.0.1]
Jul 5 17:20:40 mx postfix/smtpd[12565]: 4F97940ACA: client=localhost.localdomain[127.0.0.1], orig_client=mail-sensor.external.domain[X.X.X.X]
Jul 5 17:20:40 mx postfix/cleanup[12560]: 4F97940ACA: message-id=<20210705162034.367C38DA2E341361@sender.domain>
Jul 5 17:20:40 mx postfix/qmgr[945]: 4F97940ACA: from=<some_user@sender.domain>, size=8236, nrcpt=1 (queue active)
Jul 5 17:20:40 mx postfix/smtpd[12565]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Jul 5 17:20:40 mx pmg-smtp-filter[12529]: 60F1B60E323484103B: accept mail to <a.basamad@bonnoncoffee.com> (4F97940ACA) (rule: default-accept)
Jul 5 17:20:40 mx pmg-smtp-filter[12529]: 60F1B60E323484103B: processing time: 0.066 seconds (0, 0.046, 0)
Jul 5 17:20:40 mx postfix/lmtp[12561]: 3F566405B2: to=<a.basamad@bonnoncoffee.com>, relay=127.0.0.1[127.0.0.1]:10023, delay=0.08, delays=0/0/0/0.07, dsn=2.5.0, status=sent (250 2.5.0 OK (60F1B60E323484103B))
Jul 5 17:20:40 mx postfix/qmgr[945]: 3F566405B2: removed
Jul 5 17:21:22 mx postfix/smtp[12613]: 4F97940ACA: to=<a.basamad@bonnoncoffee.com>, relay=mail.bonnoncoffee.com[160.153.54.128]:25, delay=42, delays=0.01/0.01/22/20, dsn=5.0.0, status=bounced (host mail.bonnoncoffee.com[160.153.54.128] said: 550 This is an Invalid Email Address ! (in reply to RCPT TO command))
Jul 5 17:21:22 mx postfix/qmgr[945]: 4F97940ACA: removed
Jul 5 17:25:12 mx postfix/smtpd[14913]: connect from mail-sensor.external.domain[X.X.X.X]
Jul 5 17:25:12 mx postfix/smtpd[14913]: EDC534304B: client=mail-sensor.external.domain[X.X.X.X]
Jul 5 17:25:12 mx postfix/cleanup[15092]: EDC534304B: message-id=<20210705162115.2CF04B7FFE3DA3DD@sender.domain>
Jul 5 17:25:12 mx postfix/smtpd[14913]: disconnect from mail-sensor.external.domain[X.X.X.X] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7
Jul 5 17:25:12 mx postfix/qmgr[945]: EDC534304B: from=<some_user@sender.domain>, size=7991, nrcpt=1 (queue active)
Jul 5 17:25:12 mx pmg-smtp-filter[15192]: 60F2560E32458F0BF0: new mail message-id=<20210705162115.2CF04B7FFE3DA3DD@sender.domain>#012
Jul 5 17:25:13 mx postfix/smtpd[14852]: connect from localhost.localdomain[127.0.0.1]
Jul 5 17:25:13 mx postfix/smtpd[14852]: 08A0C42F65: client=localhost.localdomain[127.0.0.1], orig_client=mail-sensor.external.domain[X.X.X.X]
Jul 5 17:25:13 mx postfix/cleanup[15093]: 08A0C42F65: message-id=<20210705162115.2CF04B7FFE3DA3DD@sender.domain>
Jul 5 17:25:13 mx postfix/qmgr[945]: 08A0C42F65: from=<some_user@sender.domain>, size=8190, nrcpt=1 (queue active)
Jul 5 17:25:13 mx postfix/smtpd[14852]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Jul 5 17:25:13 mx pmg-smtp-filter[15192]: 60F2560E32458F0BF0: accept mail to <adapres@adadarters.com> (08A0C42F65) (rule: default-accept)
Jul 5 17:25:13 mx pmg-smtp-filter[15192]: 60F2560E32458F0BF0: processing time: 0.059 seconds (0, 0.037, 0)
Jul 5 17:25:13 mx postfix/lmtp[14691]: EDC534304B: to=<adapres@adadarters.com>, relay=127.0.0.1[127.0.0.1]:10023, delay=0.07, delays=0.01/0/0.01/0.06, dsn=2.5.0, status=sent (250 2.5.0 OK (60F2560E32458F0BF0))
Jul 5 17:25:13 mx postfix/qmgr[945]: EDC534304B: removed
Jul 5 17:25:25 mx postfix/smtp[12668]: 08A0C42F65: to=<adapres@adadarters.com>, relay=mail.adadarters.com[67.20.113.97]:25, delay=13, delays=0.01/0/6.5/6.4, dsn=2.0.0, status=sent (250 OK id=1m0QTM-0037FK-T9)
Jul 5 17:25:25 mx postfix/qmgr[945]: 08A0C42F65: removed