Frozen message from one domain

remikk

Verified User
Joined
Apr 30, 2008
Messages
158
Location
Poland
From few weeks in mail queue I have many message frozen only for one domain.
I try to understand why? I check, and I don't have autoresponder set.
Recipients not exist.

i think that some spam server send to my server to recipients which doesn't exist and back. But I'm not sure.

Code:
1MGpGc-0008Ka-UO-H
mail 8 8
<>
1245222546 0
-ident mail
-received_protocol local
-body_linecount 112
-allow_unqualified_recipient
-allow_unqualified_sender
-frozen 1245222546
-localerror
XX
1
[email protected]

154P Received: from mail by da.softgroup.pl with local (Exim 4.67)
	id 1MGpGc-0008Ka-UO
	for [email protected]; Wed, 17 Jun 2009 09:09:06 +0200
054  X-Failed-Recipients: [email protected]
029  Auto-Submitted: auto-replied
059F From: Mail Delivery System <[email protected]>
037T To: [email protected]
059  Subject: Mail delivery failed: returning message to sender
048I Message-Id: <[email protected]>
038  Date: Wed, 17 Jun 2009 09:09:06 +0200

1MGpGc-0008Ka-UO-D
This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  [email protected]
    

------ This is a copy of the message, including all the headers. ------

Return-path: <[email protected]>
Received: from mail by da.softgroup.pl with spam-scanned (Exim 4.67)
	(envelope-from <[email protected]>)
	id 1MGpGY-0008KS-DH
	for [email protected]; Wed, 17 Jun 2009 09:09:06 +0200
Received: from localhost by da.softgroup.pl
	with SpamAssassin (version 3.2.4);
	Wed, 17 Jun 2009 09:09:06 +0200
From: "miroslawa.jarzab" <[email protected]>
To: "miroslawa.jarzab" <[email protected]>
Subject: *****WIADOMOSC UZNANA JAKO SPAM***** ID698539 UK Pfizer!
Date: Wed, 17 Jun 2009 07:08:56 -0330
Message-Id: <1efe01c9ef48$947f8a40$62405277@LENOVO-9B99FC12>
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 3.2.4 (2008-01-01) on da.softgroup.pl
X-Spam-Level: *********
X-Spam-Status: Yes, score=9.4 required=5.0 tests=BAYES_80,DATE_IN_FUTURE_03_06,
	RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_XBL,RCVD_NUMERIC_HELO,RDNS_NONE autolearn=no
	version=3.2.4
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_4A389692.36F5C5D7"

This is a multi-part message in MIME format.

------------=_4A389692.36F5C5D7
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

----------------- AUTOMATYCZNY raport antySPAMowy ----------------------
Oprogramowanie  do  wykrywania  spamu,  dzia³aj±ce  na  serwerze:
*** "da.softgroup.pl" ***,
zidentyfikowa³o  ten email  jako prawdopodobny  spam. Oryginalna  wiadomo¶æ
zosta³a do³±czona    do tej, aby mo¿na by³o j± przejrzeæ, zweryfikowaæ  lub
zablokowaæ na  przysz³o¶æ. Je¿eli masz jakie¶ w±tpliwo¶ci, to kieruj je pod
adres the administrator of that system

Przegl±d zawarto¶ci:  17.6.2009 USA Doctor $FIRST_NAMES Best Price On Net 75% 0FF!
   http://groups.yahoo.com/group/suforekoqofaz31/message/1 [...] 

Szczegó³y analizy zawarto¶ci: (9.4 zaliczonych, 5.0 wymaganych)

pkt  nazwa regu³y           krótki opis
---- ---------------------- -------------------------------------------
 2.1 RCVD_NUMERIC_HELO      Received: zawiera numeryczne HELO
 0.3 DATE_IN_FUTURE_03_06   Data: jest od 3 do 6 godzin po dacie z Received:
 2.0 BAYES_80               BODY: Bayesowskie prawdopodobieñstwo spamu wynosi 80 do 95%
                            [score: 0.9260]
 3.0 RCVD_IN_XBL            RBL: Received via a relay in Spamhaus XBL
                            [119.82.64.98 listed in zen.spamhaus.org]
 2.0 RCVD_IN_BL_SPAMCOP_NET RBL: Odebrane od systemu klasy RELAY w/g:
                            bl.spamcop.net
                [Blocked - see <http://www.spamcop.net/bl.shtml?119.82.64.98>]
 0.1 RDNS_NONE              Delivered to trusted network by a host with no rDNS

Oryginalna wiadomo¶æ nie by³a w ca³o¶ci  tekstowa, w zwi±zku z tym otwarcie
jej za  pomoc± niektórych  programów pocztowych   mo¿e  nie  byæ ca³kowicie
bezpieczne; w  szczególno¶ci,   przesy³ka  mo¿e   zawieraæ  wirusa  lub kod
informuj±cy spamera, ¿e twój adres pocztowy jest  prawid³owy    i mo¿na  na
niego przysy³aæ wiêcej spamu.  Je¿eli  chcesz    j± przejrzeæ, bezpieczniej
bêdzie zapisaæ j± najpierw na dysk, a nastêpnie otworzyæ edytorem tekstu.


------------=_4A389692.36F5C5D7
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: attachment
Content-Transfer-Encoding: 8bit

Received: from [119.82.64.98] (helo=119.82.64.98)
	by da.softgroup.pl with smtp (Exim 4.67)
	(envelope-from <[email protected]>)
	id 1MGpGX-0008IW-TN
	for [email protected]; Wed, 17 Jun 2009 09:09:02 +0200
Message-ID: <1efe01c9ef48$947f8a40$62405277@LENOVO-9B99FC12>
From: "miroslawa.jarzab" <[email protected]>
To: "miroslawa.jarzab" <[email protected]>
Reply-To: [email protected]
Subject: ID698539 UK Pfizer!
Date: Wed, 17 Jun 2009 07:08:56 -0330
MIME-Version: 1.0
Content-Type: multipart/related;
	boundary="----=_NextPart_000_1EFC_01C9EF48.947F8A40"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138

This is a multi-part message in MIME format.

------=_NextPart_000_1EFC_01C9EF48.947F8A40
Content-Type: text/plain;
	charset="windows-1251"
Content-Transfer-Encoding: 8bit

17.6.2009 USA Doctor $FIRST_NAMES Best Price On Net 75% 0FF!
http://groups.yahoo.com/group/suforekoqofaz31/message/1



------------=_4A389692.36F5C5D7--

2009-06-17 09:09:06 Received from <> R=1MGpGY-0008KS-DH U=mail P=local S=5237 T="Mail delivery failed: returning message to sender"
2009-06-17 09:09:06 [email protected] F=<> R=virtual_aliases: 
*** Frozen (delivery error message)
 
Last edited:
I check
Code:
cat mainlog | grep 1MHXL8-0005lV-Lr
2009-06-19 08:12:44 1MHXL8-0005lV-Lr <= <> R=1MHXL3-0005l1-9J U=mail P=local S=8534 T="Mail delivery failed: returning message to sender" from <> for [email protected]
2009-06-19 08:12:45 1MHXL8-0005lV-Lr ** [email protected] F=<> R=virtual_aliases:
2009-06-19 08:12:45 1MHXL8-0005lV-Lr Frozen (delivery error message)

Only this. What should I looking for ?

For example grep by address:

Code:
cat mainlog | grep [email protected]
2009-06-19 08:15:05 1MHXNO-00062d-QJ <= [email protected] H=(adsl-99-165-22-14.dsl.lsan03.sbcglobal.net) [99.165.22.14] P=esmtp S=4346 id=XDPCZVTBBYEC.OKTOSASQBBGRHUN53473090030@adsl-99-165-22-14.dsl.lsan03.sbcglobal.net T="Code for activation" from <[email protected]> for [email protected]
2009-06-19 08:15:09 1MHXNR-00065i-4K <= [email protected] U=mail P=spam-scanned S=9094 id=XDPCZVTBBYEC.OKTOSASQBBGRHUN53473090030@adsl-99-165-22-14.dsl.lsan03.sbcglobal.net T="Code for activation" from <[email protected]> for [email protected]
2009-06-19 08:15:09 1MHXNR-00065i-4K => discarded <[email protected]> R=domain_filter
2009-06-19 08:15:09 1MHXNO-00062d-QJ => throughout <[email protected]> F=<[email protected]> R=spamcheck_director T=spamcheck S=8976
2009-06-19 08:15:09 1MHXNO-00062d-QJ Completed
 
grep email id in /var/log/exim/rejectlog to see why it got frozen.

Depending on your configuration you could check also paniclog.
That should clear out everything.
 
grep email id in /var/log/exim/rejectlog to see why it got frozen.

Depending on your configuration you could check also paniclog.
That should clear out everything.

yes, I was checking, but nothing in rejectlog (only messages which was greylisted, but not frozen) and paniclog is empty.
For example now from mainlog
Code:
2009-06-19 12:30:24 1MHbMW-0005xs-04 <= [email protected] H=([125.188.147.201]) [125.188.147.201] P=esmtp S=4262 id=KOVGAEGAKSKW.KKYRPQUPTZWFMJH48386505560@[125.188.147.201] T="Web-interface update" from <[email protected]> for [email protected]
2009-06-19 12:30:29 1MHbMW-0005xy-NN <= [email protected] U=mail P=spam-scanned S=8114 id=KOVGAEGAKSKW.KKYRPQUPTZWFMJH48386505560@[125.188.147.201] T="Web-interface update" from <[email protected]> for [email protected]
2009-06-19 12:30:29 1MHbMW-0005xy-NN ** [email protected] F=<[email protected]> R=virtual_aliases:
2009-06-19 12:30:29 1MHbMb-0005y6-Rp <= <> R=1MHbMW-0005xy-NN U=mail P=local S=8905 T="Mail delivery failed: returning message to sender" from <> for [email protected]
2009-06-19 12:30:29 1MHbMb-0005y6-Rp ** [email protected] F=<> R=virtual_aliases:
2009-06-19 12:30:29 1MHbMW-0005xs-04 => time <[email protected]> F=<[email protected]> R=spamcheck_director T=spamcheck S=7996

This is only for one domain on my server.
 
The exim rejectlog only reports emails you reject, not emails from you rejected by other servers.

It appears that your server is trying to send email to nonexistent servers, and it's being refused. Your server can't send it back where it got it from (it's probably something called collateral spam; check these forums), so it freezes. You can remove frozen messages from your queue if your queue is getting unmanageably large, but they will eventually be removed automatically.

Jeff
 
Back
Top