Hi all,
One of our mail servers was recently added to SpamHaus. Luckily one of our customers caught it and submitted it for removal - which in fact it was removed.
However, I'd like to track down the spammer that is spamming on our servers, hurting business for other customers.
What tools/techniques do you folks use to track down the culprit? I've tried to look at DA to see if their bandwidth is over normal use, as well as tailing the /var/log/exim/mainlog.* and I see the emails where we get notified that we are on a spamlist, but I don't know how to find the culprit.
Thanks in advance.
One of our mail servers was recently added to SpamHaus. Luckily one of our customers caught it and submitted it for removal - which in fact it was removed.
However, I'd like to track down the spammer that is spamming on our servers, hurting business for other customers.
What tools/techniques do you folks use to track down the culprit? I've tried to look at DA to see if their bandwidth is over normal use, as well as tailing the /var/log/exim/mainlog.* and I see the emails where we get notified that we are on a spamlist, but I don't know how to find the culprit.
Thanks in advance.