Is my server being used by spammers? Hundreds of bounced emails being returned...

SpaceshipSpaceship
Watch

HeyGeek

Established Member
Impact
8
Hi,
I have a VDS at godaddy, and I use cpanel to administrate it.

I have the "catch all" email address for one of my domains redirect to my email account on yahoo, and recently I have started getting hundreds of "undeliverable" spam getting sent back from really random email addresses, with my sites domain as the sender (example: "Unable to deliver message" from [email protected]).

I realize that someone could just be using forging my domain into the header, but I am really worried that they are actually using the server to send spam, and I don't want to have my account suspended over it.

My question is: how do I check to see if any unathorized people have been sending email from my domain? I do us the "formail.cgi" program and I know that can sometimes be hijacked.

Please explain as simply as possible....

Thanks is advance....
George
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
It's likely forged, not hacked, and quite common occurrence these days. Only thing you can do is let the spam take its toll, it usually dies down after a period of time. But for best results, disable your catchall for now.
 
0
•••
Thanks, that does make me feel a little better... still, I do want to make sure....so...I'm not really the best at reading headers... if I pmed you the header from one of the bounced emails would you be willing to look at it real quick and let me know what you think? Or can you even tell from headers?

Thanks for your help,
George
 
0
•••
0
•••
Thanks, that helps.
 
0
•••
i get tons and tons of these bouce back messages from my 3letter domains :(
 
0
•••
Most likely forged, I get them as well even on personal addresses.

Use the following to check for formmails:

Find Command
find / -name "[Ff]orm[mM]ai*"

Find CGIemail (Another risk.)
find / -name "[Cc]giemai*"

Disable Formmail
chmod a-rwx /path/to/filename

(a-rwx translates to all types, no read, write or execute permissions.)

If you can get away from using formmail, I would advise it.
 
0
•••
Dynadot — .com TransferDynadot — .com Transfer
Appraise.net

We're social

Escrow.com
Spaceship
Rexus Domain
CryptoExchange.com
Domain Recover
CatchDoms
DomainEasy — Payment Flexibility
DomDB
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back