+ Reply to Thread
Results 1 to 5 of 5

Thread: QMail - log analysis

  1. #1

    QMail - log analysis

    Hi all,

    This is a copy of a post i have on the Psoft forum but thought i'd put on here too to see if anyone has anythoughts...

    We're having serious problems with our mailserver and I need help understading the qmail logs to determine the cause of the problem.

    It appears we are experiencing an abnormal amount of email activity and the recent maillogs are exceeding 2GB in size!

    I am not too linux savvy so i'm struggling to know where to turn but thought i'd first start by trying to understand why these logs are so large. Especially as before we started having problems these logs were only around 60MB in size.

    At the moment i am not sure if qmail has its knickers in a twist or whether someone is trying to compromise our server so i need to ascertain some kind of behavioural pattern for our emails.

    From what i can see there are a huge number of emails that seem to be destined for the same account, here's an example from the maillog:

    Nov 24 09:18:43 web qmail: 1164359923.602551 new msg 184487

    Nov 24 09:18:43 web qmail: 1164359923.603869 info msg 184487: bytes 12616 from qp 7279 uid 399

    Nov 24 09:33:17 web qmail: 1164360797.575379 starting delivery 3349641: msg 184487 to local duckworth-and-kent.com-wildcard@localdomain.com

    Nov 24 09:33:18 web qmail: 1164360798.909860 end msg 184487
    Now from what i can tell this is a log for an inbound message that is destined for one of our local domains. That's fine. But what's really puzzling me is that the wildcard / catchall feature for this domain was turned off a few days ago so why would qmail be trying to deliver the message to the wildcard address?

    Is there anyway i can check whether the catchall is really turned off, from with HSphere it says so but i'm assuming there must be an underlying parameter to correspond to this.


    Any help on the matter is going to be really appreciated here guys. This has fallen in my hand and i am by no means the best man for the job but i have customers who are experiencing huge delays on emails and need to get the problem sorted asap!

    Dan.

  2. #2
    dch
    dch is offline
    xoozoo.com Ltd
    no reviews yet. Post Review
    Certified Standard Host
    I have made 1009 posts
    11 posts within 6 months
    Contact Me, Company profile
    dch is on a distinguished road
    Hi Dan,

    I didn't notice the post over at PSoft yet - I will go and take a look and add some more details if possible...

    But with volumes like that is is probably a dictionary attack on a catchall - the /var/hsphere/mail/logs/stats file is a live log for mail accepted (or rejected sue to Clam/SA) - maybe just do a
    Code:
    tail -f /var/hsphere/mail/logs/stats
    on it to see if you can quickly see the pattern.

    May also be worth checking to see how many of your accounts have catch all enabled.

    Cheers,
    Sean
    » Sean Andrews,
    » xoozoo.com ltd - www.xoozoo.com
    » Free DNS Report tools - dr.xoozoo.com
    » Company no:6482396

  3. #3
    Certified VIP Host
    I have made 6419 posts
    544 posts within 6 months
    Contact Me, Company profile
    othelloRob is on a distinguished road
    Quote Originally Posted by CoXeY View Post
    Is there anyway i can check whether the catchall is really turned off
    Restart qmail, in case its just not re-read the settings
    You should be able to see the catchall in the valiases/virtusers files
    Rob Golding Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410 Tel:0871 277 6875
    consultancy domains email forwarding resellers ecommerce colo rackspace ip transit secondary mx/dns dedicated servers backup/DR
    * OthelloHosts.net Linux and Windows Clustered High-Availability Professional Email / Web / Secure Hosting
    * OthelloVPS.net Managed Xen Enterprise Virtual Private Servers and Dedicated Servers
    # Currently buying web hosts and domain resellers - www.hostacquisitions.co.uk

  4. #4
    Restarting Qmail has no affect and I am unable to find the valiases/virtusers files - any ideas where these are?

    Also, have a look at the logs below, what do you make of them:

    Dec 7 11:56:57 web named[1754]: MAXQUERIES exceeded, possible data loop in resolving (externaldomain.com)

    and

    Dec 7 11:56:58 web named[1754]: Lame server on 'externaldomain.com' (in 'externaldomain.com'?): [66.218.xx.xxx].53 'yns1.yahoo.com': learnt (A=194.203.xx.xx,NS=194.203.xx.xx)
    The 194.203.xx.xx entry in the second log a DNS forwarder server that we use to resove DNS on our network.

  5. #5
    Problem solved!

    Needed to delete the queue in order to the clear the backlog and now everything seems to be ticking along just fine.

    Thanks again guys

    Dan.

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. dot-qmail question
    By pelinor in forum Shared and Reseller Web Hosting
    Replies: 5
    Last Post: 5th February 2004, 11:18 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Content Relevant URLs by vBSEO 3.5.0 RC2