Автор: plastunspb
Дата сообщения: 05.07.2016 08:53
Утра всем. С некоторых пор у пары сотрудников появилась такая проблема:
Их начало засыпать спамом от их же самих.
Вот заголовок письма:
Received: from [41.191.68.242] ([41.191.68.242])
by mail.tek-know.ru (mail.tek-know.ru)
(MDaemon PRO v11.0.3)
with ESMTP id md50000768409.msg
for <korneev@tek-know.ru>; Mon, 04 Jul 2016 20:02:31 +0300
Return-Path: <korneev@tek-know.ru>
Reply-To: <korneev@tek-know.ru>
From: <korneev@tek-know.ru>
To: korneev@tek-know.ru
Subject: Ocupacion parcial
Date: Mon, 4 Jul 2016 19:29:12 +0300
Вот лог Сервера:
Mon 2016-07-04 20:01:51: Session 3073; child 1; thread 0
Mon 2016-07-04 20:01:51: Accepting SMTP connection from [41.191.68.242:11920] to [193.104.69.228:25]
Mon 2016-07-04 20:01:51: --> 220 mail.tek-know.ru ESMTP MDaemon 11.0.3; Mon, 04 Jul 2016 20:01:51 +0300
Mon 2016-07-04 20:01:54: <-- EHLO [41.191.68.242]
Mon 2016-07-04 20:01:54: --> 250-mail.tek-know.ru Hello [41.191.68.242], pleased to meet you
Mon 2016-07-04 20:01:54: --> 250-ETRN
Mon 2016-07-04 20:01:54: --> 250-AUTH=LOGIN
Mon 2016-07-04 20:01:54: --> 250-AUTH LOGIN CRAM-MD5
Mon 2016-07-04 20:01:54: --> 250-8BITMIME
Mon 2016-07-04 20:01:54: --> 250 SIZE 20480000
Mon 2016-07-04 20:01:57: <-- MAIL From:<korneev@tek-know.ru>
Mon 2016-07-04 20:01:57: Performing PTR lookup (242.68.191.41.IN-ADDR.ARPA)
Mon 2016-07-04 20:01:58: * Error: * Сервер имен сообщает, что имя домена не опознано
Mon 2016-07-04 20:01:58: * No PTR records found
Mon 2016-07-04 20:01:58: ---- End PTR results
Mon 2016-07-04 20:01:58: Performing IP lookup (tek-know.ru)
Mon 2016-07-04 20:01:58: * D=tek-know.ru TTL=(15) A=[90.156.201.80]
Mon 2016-07-04 20:01:58: * D=tek-know.ru TTL=(15) A=[90.156.201.102]
Mon 2016-07-04 20:01:58: * D=tek-know.ru TTL=(15) A=[90.156.201.55]
Mon 2016-07-04 20:01:58: * D=tek-know.ru TTL=(15) A=[90.156.201.85]
Mon 2016-07-04 20:01:58: * P=010 S=000 D=tek-know.ru TTL=(0) MX=[mail.tek-know.ru]
Mon 2016-07-04 20:01:58: * D=tek-know.ru TTL=(15) A=[90.156.201.80]
Mon 2016-07-04 20:01:58: ---- End IP lookup results
Mon 2016-07-04 20:01:58: Performing SPF lookup (tek-know.ru / 41.191.68.242)
Mon 2016-07-04 20:01:58: * Result: none; no SPF record in DNS
Mon 2016-07-04 20:01:58: ---- End SPF results
Mon 2016-07-04 20:01:58: --> 250 <korneev@tek-know.ru>, Sender ok
Mon 2016-07-04 20:02:02: <-- RCPT To:<korneev@tek-know.ru>
Mon 2016-07-04 20:02:02: Производится поиск DNS-BL (41.191.68.242 – соединение с IP)
Mon 2016-07-04 20:02:02: * zen.spamhaus.org - прошло
Mon 2016-07-04 20:02:03: * b.barracudacentral.org - не удалось - 127.0.0.2
Mon 2016-07-04 20:02:03: ---- Конечные результаты DNS-BL
Mon 2016-07-04 20:02:03: --> 250 <korneev@tek-know.ru>, Recipient ok
Mon 2016-07-04 20:02:07: <-- DATA
Mon 2016-07-04 20:02:07: Creating temp file (SMTP): c:\mdaemon\queues\temp\md50000371063.tmp
Mon 2016-07-04 20:02:07: --> 354 Enter mail, end with <CRLF>.<CRLF>
Mon 2016-07-04 20:02:20: Message size: 2275 bytes
Mon 2016-07-04 20:02:20: Performing DKIM lookup
Mon 2016-07-04 20:02:20: * File: c:\mdaemon\queues\temp\md50000371063.tmp
Mon 2016-07-04 20:02:20: * Message-ID: FB5241E9BDE8FA15BCAF07530614FB52@XY6CYHXLITC
Mon 2016-07-04 20:02:20: * Result: neutral
Mon 2016-07-04 20:02:20: ---- End DKIM results
Mon 2016-07-04 20:02:20: Performing DomainKeys lookup (Sender: korneev@tek-know.ru)
Mon 2016-07-04 20:02:20: * File: c:\mdaemon\queues\temp\md50000371063.tmp
Mon 2016-07-04 20:02:20: * Message-ID: FB5241E9BDE8FA15BCAF07530614FB52@XY6CYHXLITC
Mon 2016-07-04 20:02:20: * Querying for policy: tek-know.ru
Mon 2016-07-04 20:02:20: * Querying: _domainkey.tek-know.ru ...
Mon 2016-07-04 20:02:20: * DNS: * Сервер имен сообщает, что имя домена не опознано
Mon 2016-07-04 20:02:20: * Result: neutral
Mon 2016-07-04 20:02:20: ---- End DomainKeys results
Mon 2016-07-04 20:02:20: Passing message through AntiVirus (Size: 2275)...
Mon 2016-07-04 20:02:20: * Сообщение чистое (вирусов не обнаружено)
Mon 2016-07-04 20:02:20: ---- End AntiVirus results
Mon 2016-07-04 20:02:27: Создание сообщения successful: c:\mdaemon\queues\inbound\md50000768409.msg
Mon 2016-07-04 20:02:27: --> 250 Ok, message saved <Message-ID: FB5241E9BDE8FA15BCAF07530614FB52@XY6CYHXLITC>
Mon 2016-07-04 20:02:27: <-- QUIT
Mon 2016-07-04 20:02:27: --> 221 See ya in cyberspace
Mon 2016-07-04 20:02:27: SMTP session successful (Bytes in/out: 2376/452)
Mon 2016-07-04 20:02:27: ----------
Mon 2016-07-04 20:02:31: Routing message (inbound queue): c:\mdaemon\queues\inbound\md50000768409.msg
Mon 2016-07-04 20:02:31: * From: korneev@tek-know.ru; Recipient: korneev@tek-know.ru; Size: 3701; Message: c:\mdaemon\queues\local\md50001222725.msg
Mon 2016-07-04 20:02:31: * Subject: Ocupacion parcial
Mon 2016-07-04 20:02:31: * Message-ID: FB5241E9BDE8FA15BCAF07530614FB52@XY6CYHXLITC
Mon 2016-07-04 20:02:31: ----------
Mon 2016-07-04 20:02:31: SecurityPlus AntiVirus processing c:\mdaemon\queues\local\md50001222725.msg...
Mon 2016-07-04 20:02:31: * Message return-path: prvs=199342f5f5=korneev@tek-know.ru
Mon 2016-07-04 20:02:31: * Message from: korneev@tek-know.ru
Mon 2016-07-04 20:02:31: * Message to: korneev@tek-know.ru
Mon 2016-07-04 20:02:31: * Message subject: Ocupacion parcial
Mon 2016-07-04 20:02:31: * Message ID: <FB5241E9BDE8FA15BCAF07530614FB52@XY6CYHXLITC>
Mon 2016-07-04 20:02:31: Start SecurityPlus AntiVirus results
Mon 2016-07-04 20:02:31: * Total attachments scanned : 3 (including multipart/alternatives and message body)
Mon 2016-07-04 20:02:31: * Total attachments infected : 0
Mon 2016-07-04 20:02:31: * Total attachments disinfected: 0
Mon 2016-07-04 20:02:31: * Total errors while scanning : 0
Mon 2016-07-04 20:02:31: * Total attachments removed : 0
Mon 2016-07-04 20:02:31: End of SecurityPlus AntiVirus results
Mon 2016-07-04 20:02:31: ----------
Mon 2016-07-04 20:02:31: Content Filter processing c:\mdaemon\queues\local\md50001222725.msg...
Mon 2016-07-04 20:02:31: * Message return-path: prvs=199342f5f5=korneev@tek-know.ru
Mon 2016-07-04 20:02:31: * Message from: korneev@tek-know.ru
Mon 2016-07-04 20:02:31: * Message to: korneev@tek-know.ru
Mon 2016-07-04 20:02:31: * Message subject: Ocupacion parcial
Mon 2016-07-04 20:02:31: * Message ID: <FB5241E9BDE8FA15BCAF07530614FB52@XY6CYHXLITC>
Mon 2016-07-04 20:02:31: Start Content Filter results
Mon 2016-07-04 20:02:31: * Matched 0 of 18 active rules
Mon 2016-07-04 20:02:31: End of Content Filter results
Mon 2016-07-04 20:02:31: ----------
Mon 2016-07-04 20:02:33: Routing message (local queue): c:\mdaemon\queues\local\pd50001222725.msg
Mon 2016-07-04 20:02:33: * From: korneev@tek-know.ru; Recipient: korneev@tek-know.ru
Mon 2016-07-04 20:02:33: * Subject: Ocupacion parcial
Mon 2016-07-04 20:02:33: * Message-ID: <FB5241E9BDE8FA15BCAF07530614FB52@XY6CYHXLITC>
Mon 2016-07-04 20:02:33: * Размер: 3766; Сообщение: d:\backup\mdaemon\users\tek-know.ru\korneev\md50000117232.msg
Mon 2016-07-04 20:02:33: ----------