Hi there, I have a problem and maybe someone on here can help me. I have read a lot of posts on this forum already, but I haven't fount a solution yet. Maybe I have not looked up the correct keywords. So any help is appreciated.
Our PMG receives a lot of spammails from mailservers like these:
And I haven't found a way to get rid of it yet.
At the moment they use addresses like "<randomly-chosen-alphabet-characters>@tmc.edu". But in the initial contact, there is no "from"-address.
When I block the IP as a WHO object, they come back with a trillion other IPs.
When I block .+@tmc.edu$ as a WHO object, sometimes they are blocked and other times they aren't.
When I block .+@tmc.edu$ as a WHAT object with matching field as From, sometimes they are blocked and sometimes they aren't.
What am I missing here? How do I get rid of these?
Our PMG receives a lot of spammails from mailservers like these:
Code:
astmpdsfsdf-i102telefonica.westeurope.cloudapp.azure.com
adsfsdf-i36p.northeurope.cloudapp.azure.com
akafud-wohj7tip6953gbx.eastus.cloudapp.azure.com
astmpdsfsdf-i53pok.eastus.cloudapp.azure.com
adsfsdf-i62p.northeurope.cloudapp.azure.com
And I haven't found a way to get rid of it yet.
At the moment they use addresses like "<randomly-chosen-alphabet-characters>@tmc.edu". But in the initial contact, there is no "from"-address.
Code:
Feb 27 15:28:22 pmg postfix/smtpd[4582]: connect from adsfsdf-i62p.northeurope.cloudapp.azure.com[40.85.76.105]
Feb 27 15:28:22 pmg postfix/smtpd[4582]: F3A3B30264F: client=adsfsdf-i62p.northeurope.cloudapp.azure.com[40.85.76.105]
Feb 27 15:28:23 pmg postfix/cleanup[4552]: F3A3B30264F: message-id=<JoVpeRH-SpApkRnJG-MtQyYzVu@tmc.edu>
Feb 27 15:28:23 pmg postfix/qmgr[1419]: F3A3B30264F: from=<>, size=10882, nrcpt=1 (queue active)
Feb 27 15:28:23 pmg pmg-smtp-filter[4360]: 302664603A570707E39: new mail message-id=<JoVpeRH-SpApkRnJG-MtQyYzVu@tmc.edu>#012
Feb 27 15:28:23 pmg postfix/smtpd[4582]: disconnect from adsfsdf-i62p.northeurope.cloudapp.azure.com[40.85.76.105] ehlo=1 mail=1 rcpt=1 bdat=2 quit=1 commands=6
Feb 27 15:28:23 pmg pmg-smtp-filter[4360]: 302664603A570707E39: SA score=0/5 time=0.672 bayes=0.00 autolearn=no autolearn_force=no hits=BAYES_00(-1.9),HTML_IMAGE_RATIO_06(0.001),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KHOP_HELO_FCRDNS(0.001),MIME_HTML_ONLY(0.1),SPF_HELO_NONE(0.001),TO_NO_BRKTS_HTML_ONLY(1.999)
Feb 27 15:28:23 pmg postfix/smtpd[4557]: connect from localhost.localdomain[127.0.0.1]
Feb 27 15:28:23 pmg postfix/smtpd[4557]: B4921302B3D: client=localhost.localdomain[127.0.0.1], orig_client=adsfsdf-i62p.northeurope.cloudapp.azure.com[40.85.76.105]
Feb 27 15:28:23 pmg postfix/cleanup[4552]: B4921302B3D: message-id=<JoVpeRH-SpApkRnJG-MtQyYzVu@tmc.edu>
Feb 27 15:28:23 pmg postfix/qmgr[1419]: B4921302B3D: from=<>, size=11691, nrcpt=1 (queue active)
Feb 27 15:28:23 pmg postfix/smtpd[4557]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Feb 27 15:28:23 pmg pmg-smtp-filter[4360]: 302664603A570707E39: accept mail to <xxx@xxx.xxx> (B4921302B3D) (rule: default-accept)
Feb 27 15:28:23 pmg pmg-smtp-filter[4360]: 302664603A570707E39: processing time: 0.711 seconds (0.672, 0.016, 0)
Feb 27 15:28:23 pmg postfix/lmtp[4553]: F3A3B30264F: to=<xxx@xxx.xxx>, relay=127.0.0.1[127.0.0.1]:10024, delay=0.76, delays=0.04/0/0/0.72, dsn=2.5.0, status=sent (250 2.5.0 OK (302664603A570707E39))
Feb 27 15:28:23 pmg postfix/qmgr[1419]: F3A3B30264F: removed
Feb 27 15:28:23 pmg postfix/smtp[4558]: B4921302B3D: to=<xxx@xxx.xxx>, relay=xxx.xxx.xxx.xxx[xxx.xxx.xxx.xxx]:25, delay=0.07, delays=0/0/0.05/0.01, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 5A8CF3400BF)
Feb 27 15:28:23 pmg postfix/qmgr[1419]: B4921302B3D: removed
When I block the IP as a WHO object, they come back with a trillion other IPs.
When I block .+@tmc.edu$ as a WHO object, sometimes they are blocked and other times they aren't.
When I block .+@tmc.edu$ as a WHAT object with matching field as From, sometimes they are blocked and sometimes they aren't.
What am I missing here? How do I get rid of these?
Attachments
Last edited: