Interpreting the exim mainlog?

skyraider

Verified User
Joined
Jun 9, 2006
Messages
10
Hi,

I have hundreds of entries like these in my exim mainlog (I replaced my domain names with "DUDE"):

2006-10-30 08:12:30 H=finance.ufanet.ru [81.30.200.51] F=<[email protected]> rejected RCPT <adam@DUDE>:
2006-10-30 08:12:30 H=finance.ufanet.ru [81.30.200.51] incomplete transaction (QUIT) from <[email protected]>
2006-10-30 08:28:58 H=24-216-189-217.dhcp.stls.mo.charter.com [24.216.189.217] F=<[email protected]> rejected RCPT <rac@DUDE>:
2006-10-30 08:28:59 H=24-216-189-217.dhcp.stls.mo.charter.com [24.216.189.217] incomplete transaction (QUIT) from <[email protected]>
2006-10-30 08:31:42 1GeXEq-0003uK-Lu <= [email protected] H=bed95.neoplus.adsl.tpnet.pl (fffff-b063a9e35) [83.28.15.95] P=esmtp S=1539 [email protected] T="Less lb_s, more fun in life!" from <[email protected]> for info@DUDE postmaster@DUDE
2006-10-30 08:31:42 1GeXEq-0003uK-Lu ** postmaster@DUDE F=<[email protected]> R=virtual_aliases:
2006-10-30 08:31:42 1GeXEq-0003uK-Lu => info <info@DUDE> F=<[email protected]> R=virtual_user T=virtual_localdelivery S=1739
2006-10-30 08:31:42 1GeXEs-0003um-KD <= <> R=1GeXEq-0003uK-Lu U=mail P=local S=2394 T="Mail delivery failed: returning message to sender" from <> for [email protected]

Also, here's some stuff in the DA mail queu admin:

1GeXEs-0003um-KD 2h 2.3K <> yes [email protected]

1GeVVo-0002Za-GG 3h 3.5K <> yes [email protected]

1GeUcp-0001vk-Dy 4h 56K <> yes [email protected]

1GeUNe-0001jL-VK 5h 55K <> yes [email protected]

1GeOGh-0006yQ-EK 11h 2.3K <> yes [email protected]
It looks like these are spammers trying to spam me, but I'm not sure. Could someone show me how to tell whether this means my server is trying to send out spam?

Thanks.
 
skyraider said:
I have hundreds of entries like these in my exim mainlog (I replaced my domain names with "DUDE")
They look like they were blocked by one of the rules in exim.conf. Are they also in the rejectlog file?

Jeff
 
Back
Top