Perhaps if someone could confirm my interpretation of this log entry I
would be grateful.
2003-10-29 11:57:21 H=(student.lboro.ac.uk) [195.14.168.188] sender
verify fail for <i.bicnerstaff-97@???>: Unrouteable
address
2003-10-29 11:57:21 H=(student.lboro.ac.uk) [195.14.168.188]
F=<i.bicnerstaff-97@???> rejected RCPT
<i.bicnerstaff-97@???>: Sender verify failed
Firstly there is no i.bicnerstaff-97 at our site, must be an old email
address. Now H=(student.lboro.ac.uk) [195.14.168.188] is odd because a
dig on student.lboro.ac.uk will tell you it is one of our old sun
servers and does not have an ip address of 195.14.168.188. A dig -x on
that ip address gives an answer of
188.168.14.195.in-addr.arpa. 86088 IN PTR thebest.optiva.lt.
Now this ip address only appears in the log once and it finishes with
2003-10-29 11:57:21 unexpected disconnection while reading SMTP command
from (student.lboro.ac.uk) [195.14.168.188]
So is this some sort of probe to find out if they can relay through our
site or what.
Regards
/Ron
--
Ron McKeating
Senior IT Services Specialist
Internet Services and Software Solutions
Loughborough University
01509 222329