I misinterpreted the log
Because of the last lines in the maillog
smtp: to=<children@ aDomain>, ⊠status=sent
and having from=<caefisfelltranun@ bDomain> (none of my domains)
=> i thought that is bouncing an incoming message
Than I recogniced:
18:29:41 inuit postfix/smtpd[]: connect from localhost[127.0.0.1]
âwhy from localhostâ ?
At the same time in other logs
/var/log/messages
May 11 18:29:41 inuit sshd[14926]: error: connect_to 185.26.123.232 port 25: failed.
und in httpd/error_log a huge number of this entries at the same time:
Fri May 11 18:29:41âŠPHP Fatal error: require_once(): Failed opening required â/var/lib/nethserver/vhost/ixpert.at/cloud/conf/bootstrap_context.phpâ (include_path=â.:/usr/share/pear:/usr/share/phpâ) in /var/lib/nethserver/vhost/ixpert.at/cloud/base.conf.php on line 27
The folder âcloudâ was an old pydio instance that I did not use for a long time
Never on nethserver => was transferred from my macOS machine with the other vhost content
I deleted that => No such pattern as before since that
before:
cat /var/log/maillog | grep â<=?utf-8?â | wc -l
327
cat /var/log/maillog | grep âru>â | grep ârcpts:â | wc -l
327
in that mime_rcpt Part:
mime_rcpt: <=?utf-8?B?aW5mbw==?=@ myserverDNS>
mime_rcpt: <=?utf-8?B?cnM=?=@ myserverDNS>
mime_rcpt: <=?utf-8?B?cmVjZXA=?=@ myserverDNS> ⊠usw
The complete section of such an issue:
/var/log/maillog
Summary
May 11 18:29:41 inuit postfix/smtpd[16699]: connect from localhost[127.0.0.1]
May 11 18:29:41 inuit rspamd[2528]: ; proxy; proxy_accept_socket: accepted milter connection from /var/run/rspamd/worker-proxy port 0
May 11 18:29:42 inuit postfix/smtpd[16699]: 99A4530032E97: client=localhost[127.0.0.1]
May 11 18:29:42 inuit rspamd[2528]: ; milter; rspamd_milter_process_command: got connection from 127.0.0.1:35492
May 11 18:29:42 inuit postfix/cleanup[16685]: 99A4530032E97: message-id=
May 11 18:29:43 inuit rspamd[2528]: ; proxy; rspamd_mime_part_detect_language: detected part language: ru
May 11 18:29:43 inuit rspamd[2528]: ; proxy; rspamd_message_parse: loaded message; id: ; queue-id: <99A4530032E97>; size: 22281; checksum:
May 11 18:29:43 inuit rspamd[2528]: ; proxy; dkim_symbol_callback: skip DKIM checks for local networks and authorized users
May 11 18:29:43 inuit rspamd[2528]: ; proxy; spf_symbol_callback: skip SPF checks for local networks and authorized users
May 11 18:29:43 inuit rspamd[2528]: ; lua; once_received.lua:84: Skipping once_received for authenticated user or local network
May 11 18:29:43 inuit rspamd[2528]: ; lua; dmarc.lua:218: skip DMARC checks for local networks and authorized users
May 11 18:29:43 inuit rspamd[2528]: ; lua; ip_score.lua:312: skip IP Score for local networks and authorized users
May 11 18:29:43 inuit rspamd[2528]: ; lua; replies.lua:113: storing message-id for replies check
May 11 18:29:43 inuit rspamd[2528]: ; proxy; rspamd_task_write_log: id: , qid: <99A4530032E97>, ip: 127.0.0.1, from: <caefisfelltranun@ bDomain>, (default: F (rewrite subject): [7.06/6.00] [BAYES_SPAM(3.56){98.56%;},FROM_EXCESS_BASE64(1.50){},TO_EXCESS_BASE64(1.50){},MID_RHS_NOT_FQDN(0.50){},MIME_BASE64_TEXT(0.10){},MIME_GOOD(-0.10){multipart/alternative;text/plain;},FROM_EQ_ENVFROM(0.00){},FROM_HAS_DN(0.00){},RCPT_COUNT_TWO(0.00){2;},RCVD_COUNT_ZERO(0.00){0;},RCVD_TLS_ALL(0.00){},TO_DN_NONE(0.00){},TO_MATCH_ENVRCPT_SOME(0.00){}]), len: 22281, time: 110.548ms real, 7.291ms virtual, dns req: 0, digest: , rcpts: <children@ aDomain>, mime_rcpt: <=?utf-8?B?Y2hpbGRyZW4=?=@ myserverDNS>
May 11 18:29:43 inuit rspamd[2528]: ; proxy; rspamd_protocol_http_reply: regexp statistics: 46 pcre regexps scanned, 6 regexps matched, 172 regexps total, 9 regexps cached, 71.24k bytes scanned using pcre, 71.24k bytes scanned total
May 11 18:29:43 inuit postfix/qmgr[1811]: 99A4530032E97: from=<caefisfelltranun@ bDomain>, size=22491, nrcpt=1 (queue active)
May 11 18:29:43 inuit postfix/smtp[16786]: Untrusted TLS connection established to asmtp.drei.at[213.94.80.8]:587: TLSv1 with cipher ADH-AES256-SHA (256/256 bits)
May 11 18:29:43 inuit postfix/smtpd[16699]: disconnect from localhost[127.0.0.1]
May 11 18:29:43 inuit rspamd[2528]: <8af855>; proxy; proxy_milter_finish_handler: finished milter connection
May 11 18:29:44 inuit postfix/smtp[16786]: 99A4530032E97: to=<children@ aDomain>, relay=asmtp.drei.at[213.94.80.8]:587, delay=1.7, delays=0.7/0.01/0.39/0.63, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as C5F876F61C4)
May 11 18:29:44 inuit postfix/qmgr[1811]: 99A4530032E97: removed