Community Discussions and Support
Spammers - how to stop them? please help!

Oalf, thank you!

 I checked the three options under "compliance" tab.

1) limited maximum number of failed RCPTS to 4  

2) require clients to use an ESMTP size declaration.

3) Refuse messages that have not "date" field.

Thank you for helping!!!

 

 

  

<P>Oalf, thank you!</P> <P> I checked the three options under "compliance" tab.</P> <P>1) limited maximum number of failed RCPTS to 4   </P> <P>2) require clients to use an ESMTP size declaration.</P> <P>3) Refuse messages that have not "date" field.</P> <P>Thank you for helping!!!</P> <P mce_keep="true"> </P> <P mce_keep="true"> </P> <P>   </P>

Team, I am looking over my mercury log for last few days. there are many attempts/logs like the following, but they are from different IPs.

----------------------------------------------------------------- 

T 20140204 174852 52ef7f1e Connection closed with 213.186.183.252, 2 sec. elapsed.
T 20140204 181552 52ef7f1f Connection from 174.76.243.53
T 20140204 181552 52ef7f1f EHLO [192.168.2.33]
T 20140204 181553 52ef7f1f MAIL FROM: <test@live.com>
T 20140204 181553 52ef7f1f RCPT TO: <therichsheickc@yahoo.com>
E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from <test@live.com> to <therichsheickc@yahoo.com>.
T 20140204 181553 52ef7f1f RCPT TO: <therichsheick1@yahoo.com>
E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from <test@live.com> to <therichsheick1@yahoo.com>.
T 20140204 181553 52ef7f1f RCPT TO: <therichsheick9@yahoo.com>
E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from <test@live.com> to <therichsheick9@yahoo.com>.
T 20140204 181553 52ef7f1f RCPT TO: <therichsheick2@yahoo.com>
E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from <test@live.com> to <therichsheick2@yahoo.com>.
T 20140204 181553 52ef7f1f RCPT TO: <therichsheick0@yahoo.com>
E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from <test@live.com> to <therichsheick0@yahoo.com>.
T 20140204 181553 52ef7f1f QUIT
T 20140204 181553 52ef7f1f Connection closed with 174.76.243.53, 1 sec. elapsed.

-----------------------------------------------------------------  

I have no ideas about test@live.com ; therichsheickc@yahoo.com and IPs. I think that some one/computers are doing spams on my email server. I am not sure what I should do? I set up SMTP/passwords, so I do not think that these email went out, but I do not know what to check or if I need to worry about it or not? please advise?

thank you 

 

&lt;P&gt;Team, I am looking over my mercury log for last few days. there are many attempts/logs like the following, but they are from different IPs.&lt;/P&gt; &lt;P&gt;-----------------------------------------------------------------&amp;nbsp; &lt;/P&gt; &lt;P&gt;T 20140204 174852 52ef7f1e Connection closed with 213.186.183.252, 2 sec. elapsed. T 20140204 181552 52ef7f1f Connection from 174.76.243.53 T 20140204 181552 52ef7f1f EHLO [192.168.2.33] T 20140204 181553 52ef7f1f MAIL FROM: &amp;lt;&lt;A href=&quot;mailto:test@live.com&quot;&gt;test@live.com&lt;/A&gt;&amp;gt; T 20140204 181553 52ef7f1f RCPT TO: &amp;lt;&lt;A href=&quot;mailto:therichsheickc@yahoo.com&quot;&gt;therichsheickc@yahoo.com&lt;/A&gt;&amp;gt; E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from &amp;lt;&lt;A href=&quot;mailto:test@live.com&quot;&gt;test@live.com&lt;/A&gt;&amp;gt; to &amp;lt;&lt;A href=&quot;mailto:therichsheickc@yahoo.com&quot;&gt;therichsheickc@yahoo.com&lt;/A&gt;&amp;gt;. T 20140204 181553 52ef7f1f RCPT TO: &amp;lt;&lt;A href=&quot;mailto:therichsheick1@yahoo.com&quot;&gt;therichsheick1@yahoo.com&lt;/A&gt;&amp;gt; E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from &amp;lt;&lt;A href=&quot;mailto:test@live.com&quot;&gt;test@live.com&lt;/A&gt;&amp;gt; to &amp;lt;&lt;A href=&quot;mailto:therichsheick1@yahoo.com&quot;&gt;therichsheick1@yahoo.com&lt;/A&gt;&amp;gt;. T 20140204 181553 52ef7f1f RCPT TO: &amp;lt;&lt;A href=&quot;mailto:therichsheick9@yahoo.com&quot;&gt;therichsheick9@yahoo.com&lt;/A&gt;&amp;gt; E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from &amp;lt;&lt;A href=&quot;mailto:test@live.com&quot;&gt;test@live.com&lt;/A&gt;&amp;gt; to &amp;lt;&lt;A href=&quot;mailto:therichsheick9@yahoo.com&quot;&gt;therichsheick9@yahoo.com&lt;/A&gt;&amp;gt;. T 20140204 181553 52ef7f1f RCPT TO: &amp;lt;&lt;A href=&quot;mailto:therichsheick2@yahoo.com&quot;&gt;therichsheick2@yahoo.com&lt;/A&gt;&amp;gt; E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from &amp;lt;&lt;A href=&quot;mailto:test@live.com&quot;&gt;test@live.com&lt;/A&gt;&amp;gt; to &amp;lt;&lt;A href=&quot;mailto:therichsheick2@yahoo.com&quot;&gt;therichsheick2@yahoo.com&lt;/A&gt;&amp;gt;. T 20140204 181553 52ef7f1f RCPT TO: &amp;lt;&lt;A href=&quot;mailto:therichsheick0@yahoo.com&quot;&gt;therichsheick0@yahoo.com&lt;/A&gt;&amp;gt; E 20140204 181553 52ef7f1f Relay attempt by 174.76.243.53: from &amp;lt;&lt;A href=&quot;mailto:test@live.com&quot;&gt;test@live.com&lt;/A&gt;&amp;gt; to &amp;lt;&lt;A href=&quot;mailto:therichsheick0@yahoo.com&quot;&gt;therichsheick0@yahoo.com&lt;/A&gt;&amp;gt;. T 20140204 181553 52ef7f1f QUIT T 20140204 181553 52ef7f1f Connection closed with 174.76.243.53, 1 sec. elapsed.&lt;/P&gt; &lt;P&gt;-----------------------------------------------------------------&amp;nbsp;&amp;nbsp; &lt;/P&gt; &lt;P&gt;I have no ideas about&amp;nbsp;&lt;A href=&quot;mailto:test@live.com&quot;&gt;test@live.com&lt;/A&gt; ; &lt;A href=&quot;mailto:therichsheickc@yahoo.com&quot;&gt;therichsheickc@yahoo.com&lt;/A&gt;&amp;nbsp;and&amp;nbsp;IPs. I think that some one/computers are&amp;nbsp;doing spams&amp;nbsp;on my email server. I am not&amp;nbsp;sure what I should do? I set up SMTP/passwords, so I do not think that these email went out, but I do not&amp;nbsp;know what to check or if I need to worry about it or not? please advise?&lt;/P&gt; &lt;P&gt;thank you&amp;nbsp;&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt;

They don't spam ... they are testing your mailhost on possibilities of missusing it. As long as you have disabled relaying on non-local mail and/or only enabled it with authorisation, this attempts should result in an error ... as shown in your log.

bye    Olaf

 

&lt;p&gt;They don&#039;t spam ... they are testing your mailhost on possibilities of missusing it. As long as you have disabled relaying on non-local mail and/or only enabled it with authorisation, this attempts should result in an error ... as shown in your log.&lt;/p&gt;&lt;p&gt;bye &amp;nbsp;&amp;nbsp; Olaf&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

Olaf, thank you! understood now. are there any ways to stop these kinds of testing? thank you

Olaf, thank you! understood now. are there any ways to stop these kinds of testing? thank you

There's not realy a possibility. You could reject the IP-addresses of that servers in Mercury - but:

  • most times the tests are done by robots, which are hacked into that server
  • if you reject the IP-address, next time it will be another mailhost where testmails are send from

I have been using Mercury/NLM for a long time and since a couple of years Mercury/32. I never allowed relaying and Mercury has never been missused. May be you should have an addidtional look at the features under "Compliance" with MercuryS.

bye    Olaf

 

&lt;p&gt;There&#039;s not realy a possibility. You could reject the IP-addresses of that servers in Mercury - but:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;most times the tests are done by robots, which are hacked into that server&lt;/li&gt;&lt;li&gt;if you reject the IP-address, next time it will be another mailhost where testmails are send from&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;I have been using Mercury/NLM for a long time and since a couple of years Mercury/32. I never allowed relaying and Mercury has never been missused. May be you should have an addidtional look at the features under &quot;Compliance&quot; with MercuryS.&lt;/p&gt;&lt;p&gt;bye &amp;nbsp;&amp;nbsp; Olaf&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

Hello Olaf, thank you for helping!

1) here is my setting for MercuryS SMTP server : under connection control > Relay control

option 1 : don't permit smtp relaying of non-local mail  ( this option is checked, but it is grayed out)

option 2: use strict local relaying restrictions ( this option is also checked)

option 3: Authenticated SMTO connection may relay mail ( this option is also checked)

so I have above three options checked. Is it ok?

2) I also looked under "Compliance", But I am do not know what to check or not? ( newbee :) What is kind of setting do you have? can you give me some details here or point me some guides?  

Thank you !!!!

 

&lt;P&gt;Hello Olaf, thank you for helping!&lt;/P&gt; &lt;P&gt;1) here is my setting for MercuryS SMTP server : under connection control &amp;gt; Relay control &lt;/P&gt; &lt;P&gt;option 1 : don&#039;t permit smtp relaying of non-local mail&amp;nbsp; ( this option is checked, but it is grayed out)&lt;/P&gt; &lt;P&gt;option 2: use strict local relaying restrictions ( this option is also checked)&lt;/P&gt; &lt;P&gt;option 3: Authenticated SMTO connection may relay mail ( this option is also checked)&lt;/P&gt; &lt;P&gt;so I have above three options checked. Is it ok?&lt;/P&gt; &lt;P&gt;2) I also looked under &quot;Compliance&quot;, But I am do not know what to check or not? ( newbee :) What is kind of setting do you have?&amp;nbsp;can you give me some details here or point me some guides?&amp;nbsp;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thank you&amp;nbsp;!!!!&lt;/P&gt; &lt;P mce_keep=&quot;true&quot;&gt;&amp;nbsp;&lt;/P&gt;

> 1) here is my setting for MercuryS SMTP server : under connection control > Relay control

They seem to be OK (and if one of the lower options is checked, option 1 is grayed -  see help)

> 2) I also looked under "Compliance", But I am do not know what to check or not?

You may i.e. "Limit maximum number of failed RCPT commands" and "Limit maximum number of failed RCPT commands"  in conjunction with "Enable short-term blacklisting for compliance failures". But do it with care - read the help or the Mercury manual. I activate them on need - in case those atempts increase.

> What is kind of setting do you have?

Activated "Enable transaction-level expression filtering" and put in some special rules there. But these rules depend on using a NDS/eDirectory of Novell for authentification. In NDS are objects represaenting organisation and it may be possible to send mails to the organisation ... resulting in errormessages (these objects don't have a mailaddress :-). I stopped this boring errors by creating rules so MercuryS will reject those mails already on communication with sender.

Have a killfile for some addresses that come on and on ... and activated "Check originator address fields against the killfile". Perhaps you may need a whitelist in addition.

You may reject mails on missing headers like subject and date ... but this is more to "educate" the senders to put in a significant subject or to use mailclients setting the date-header. I didn't enable it but it may be, that not a few spammers miss setting date or subject and it may be a possibility to reduce contacts by spammers.

At least all these setting are for enabling MercuryS to reject mails already on communication with originator or a delivering external mailhost.

If you have problems with spammails, read on spamhalter and install it in Mercury. You have to do a lot of training for selflearning spamhalter in the beginning and always have to look for false positiv.

bye    Olaf

 

&lt;p&gt;&amp;gt; 1) here is my setting for MercuryS SMTP server : under connection control &amp;gt; Relay control &lt;/p&gt;&lt;p&gt;They seem to be OK (and if one of the lower options is checked, option 1 is grayed -&amp;nbsp; see help)&lt;/p&gt;&lt;p&gt;&amp;gt; 2) I also looked under &quot;Compliance&quot;, But I am do not know what to check or not? &lt;/p&gt;&lt;p&gt;You may i.e. &quot;Limit maximum number of failed RCPT commands&quot; and &quot;Limit maximum number of failed RCPT commands&quot;&amp;nbsp; in conjunction with &quot;Enable short-term blacklisting for compliance failures&quot;. But do it with care - read the help or the Mercury manual. I activate them on need - in case those atempts increase.&lt;/p&gt;&lt;p&gt;&amp;gt; What is kind of setting do you have? &lt;/p&gt;&lt;p&gt;Activated &quot;Enable transaction-level expression filtering&quot; and put in some special rules there. But these rules depend on using a NDS/eDirectory of Novell for authentification. In NDS are objects represaenting organisation and it may be possible to send mails to the organisation ... resulting in errormessages (these objects don&#039;t have a mailaddress :-). I stopped this boring errors by creating rules so MercuryS will reject those mails already on communication with sender. &lt;/p&gt;&lt;p&gt;Have a killfile for some addresses that come on and on ... and activated &quot;Check originator address fields against the killfile&quot;. Perhaps you may need a whitelist in addition.&lt;/p&gt;&lt;p&gt;You may reject mails on missing headers like subject and date ... but this is more to &quot;educate&quot; the senders to put in a significant subject or to use mailclients setting the date-header. I didn&#039;t enable it but it may be, that not a few spammers miss setting date or subject and it may be a possibility to reduce contacts by spammers.&lt;/p&gt;&lt;p&gt;At least all these setting are for enabling MercuryS to reject mails already on communication with originator or a delivering external mailhost. &lt;/p&gt;&lt;p&gt;If you have problems with spammails, read on spamhalter and install it in Mercury. You have to do a lot of training for selflearning spamhalter in the beginning and always have to look for false positiv.&lt;/p&gt;&lt;p&gt;bye &amp;nbsp;&amp;nbsp; Olaf&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft