[exim] Unusual Behavior

Top Page
Delete this message
Reply to this message
Author: Harold Huggins
Date:  
To: exim-users
Subject: [exim] Unusual Behavior
SMTP Mail Relay between the local host and remote computer exhibits the
following behavior:

~$ telnet dslxxxxxxxx.com 25
Trying 72.167.97.127...
Connected to dslxxxxxxxx.com.
Escape character is '^]'.
220-ms.dslxxxxxxxx.com ESMTP Exim 4.69 #1 Wed, 21 Oct 2009 13:34:34 -0700
220-We do not authorize the use of this system to transport unsolicited,
220 and/or bulk e-mail.
helo mail.dyndns.com
250 ms.dslxxxxxxxx.com Hello xen.thisisnotatrueending.com [216.146.46.13]
mail from:noone@???
250 OK
rcpt to:support@???
421 Unexpected failure, please try later
rcpt to:admin@???
421 Unexpected failure, please try later
rcpt to:doesnotexist@???
421 Unexpected failure, please try later
rcpt to:fdfd
421 Unexpected failure, please try later
rcpt to:421 Unexpected failure, please try later
exit 421 Unexpected failure, please try later
quit 221 ms.dslxxxxxxxx.com closing connection
Connection closed by foreign host.

For each of the above RCPT TO lines, your server should return a
500-level permanent failure error. For example:

rcpt to:support@???
421 Unexpected failure, please try later

should become:

rcpt to:support@???
550 Relay denied

Of course, your server should accept mail for itself:

rcpt to:admin@???
250 OK

Similarly, and likely related to this behavior, the local server
transmitting all of the mail it received (potentially forwarding) to
itself via Outbound, using the sender's address as the From: address:

2009-10-21 18:00:38 1N0fUE-000HqZ-NG <= automailer@???
H=ip-72-167-97-127.ip.secureserver.net (ms.dslxxxxxxxx.com)
[72.167.97.127] P=esmtpsa X=TLSv1:AES256-SHA:256 A=login:uisiscom S=2688
id=20091020060530.E40F036177B@???
2009-10-21 18:00:39 1N0fUE-000HqZ-NG => admin@???
R=dnslookup T=remote_smtp H=mx1.mailhop.org [216.146.33.1]
2009-10-21 18:00:39 1N0fUE-000HqZ-NG Completed

2009-10-21 18:00:59 1N0fUZ-000Hvz-6h <= notifier07@???
H=ip-72-167-97-127.ip.secureserver.net (ms.dslxxxxxxxx.com)
[72.167.97.127] P=esmtpsa X=TLSv1:AES256-SHA:256 A=login:uisiscom S=4185
id=5438227.418371256102709656.JavaMail.root@???
2009-10-21 18:00:59 1N0fUZ-000Hvz-6h no immediate delivery: more than 15
messages received in one connection


2009-10-21 18:07:23 1N0fal-000KwZ-IM <= bounces@???
H=ip-72-167-97-127.ip.secureserver.net (ms.dslxxxxxxxx.com)
[72.167.97.127] P=esmtpsa X=TLSv1:AES256-SHA:256 A=login:uisiscom S=6456
id=1195177925.98772@???
2009-10-21 18:07:24 1N0fal-000KwZ-IM => beta@??? R=dnslookup
T=remote_smtp H=mx1.mailhop.org [216.146.33.3]
2009-10-21 18:07:24 1N0fal-000KwZ-IM Completed