Web Host Chat
Bringing Hosts & Customers together since 2001
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Advertising
User Information
»REGISTER NOW!

Go Back   Web Host Chat > Web Hosting Chat > Networking, Routing and Transit
Reply
 
LinkBack Thread Tools
Old 6th December 2006   #1 (permalink)
Certified User (53)
Silver Quality
Join Date: Feb 2006
Location: Hertfordshire
Posts: 49
CoXeY is on a distinguished road
QMail - log analysis

Hi all,

This is a copy of a post i have on the Psoft forum but thought i'd put on here too to see if anyone has anythoughts...

We're having serious problems with our mailserver and I need help understading the qmail logs to determine the cause of the problem.

It appears we are experiencing an abnormal amount of email activity and the recent maillogs are exceeding 2GB in size!

I am not too linux savvy so i'm struggling to know where to turn but thought i'd first start by trying to understand why these logs are so large. Especially as before we started having problems these logs were only around 60MB in size.

At the moment i am not sure if qmail has its knickers in a twist or whether someone is trying to compromise our server so i need to ascertain some kind of behavioural pattern for our emails.

From what i can see there are a huge number of emails that seem to be destined for the same account, here's an example from the maillog:

Quote:
Nov 24 09:18:43 web qmail: 1164359923.602551 new msg 184487

Nov 24 09:18:43 web qmail: 1164359923.603869 info msg 184487: bytes 12616 from qp 7279 uid 399

Nov 24 09:33:17 web qmail: 1164360797.575379 starting delivery 3349641: msg 184487 to local duckworth-and-kent.com-wildcard@localdomain.com

Nov 24 09:33:18 web qmail: 1164360798.909860 end msg 184487
Now from what i can tell this is a log for an inbound message that is destined for one of our local domains. That's fine. But what's really puzzling me is that the wildcard / catchall feature for this domain was turned off a few days ago so why would qmail be trying to deliver the message to the wildcard address?

Is there anyway i can check whether the catchall is really turned off, from with HSphere it says so but i'm assuming there must be an underlying parameter to correspond to this.


Any help on the matter is going to be really appreciated here guys. This has fallen in my hand and i am by no means the best man for the job but i have customers who are experiencing huge delays on emails and need to get the problem sorted asap!

Dan.
__________________
Registered User
CoXeY is offline   Reply With Quote
Old 6th December 2006   #2 (permalink)
I am Staff at
xoozoo Ltd
About My Company!

Certified Host
Join Date: Nov 2001
Location: Totnes
Posts: 861
dch is on a distinguished road
Hi Dan,

I didn't notice the post over at PSoft yet - I will go and take a look and add some more details if possible...

But with volumes like that is is probably a dictionary attack on a catchall - the /var/hsphere/mail/logs/stats file is a live log for mail accepted (or rejected sue to Clam/SA) - maybe just do a
Code:
tail -f /var/hsphere/mail/logs/stats
on it to see if you can quickly see the pattern.

May also be worth checking to see how many of your accounts have catch all enabled.

Cheers,
Sean
__________________
» Sean Andrews,
» xoozoo.com ltd - www.xoozoo.com
» Free DNS Report tools - dr.xoozoo.com
» Company no:6482396
__________________
Web Host - Certified Member
dch is offline   Reply With Quote
Old 7th December 2006   #3 (permalink)
othellotech's Avatar
Join Date: Mar 2002
Location: London, United Kingdom
Age: 38
Posts: 4,253
othellotech is on a distinguished road
Quote:
Originally Posted by CoXeY View Post
Is there anyway i can check whether the catchall is really turned off
Restart qmail, in case its just not re-read the settings
You should be able to see the catchall in the valiases/virtusers files
__________________
Rob Golding, Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410. T:0871 277 6875 F:0871 277 6875
domains email forwarding resellers ecommerce colocation rackspace ip transit secondary mx/dns datacentre ih online/offsite backup
* OthelloHosts.net CPanel/WHM, H-Sphere, Plesk, Ensim, DirectAdmin High-Availability Professional Email / Web Hosting
* OthelloVPS.net Managed Xen4 Enterprise Virtual Private Servers and Dedicated Servers
# Currently buying 123-reg, ukreg, heart-internet and enom domain resellers - www.hostacquisitions.co.uk
__________________
Web Host - VIP Member
othellotech is online now   Reply With Quote
Old 7th December 2006   #4 (permalink)
Certified User (53)
Silver Quality
Join Date: Feb 2006
Location: Hertfordshire
Posts: 49
CoXeY is on a distinguished road
Restarting Qmail has no affect and I am unable to find the valiases/virtusers files - any ideas where these are?

Also, have a look at the logs below, what do you make of them:

Quote:
Dec 7 11:56:57 web named[1754]: MAXQUERIES exceeded, possible data loop in resolving (externaldomain.com)

and

Dec 7 11:56:58 web named[1754]: Lame server on 'externaldomain.com' (in 'externaldomain.com'?): [66.218.xx.xxx].53 'yns1.yahoo.com': learnt (A=194.203.xx.xx,NS=194.203.xx.xx)
The 194.203.xx.xx entry in the second log a DNS forwarder server that we use to resove DNS on our network.
__________________
Registered User
CoXeY is offline   Reply With Quote
Old 8th December 2006   #5 (permalink)
Certified User (53)
Silver Quality
Join Date: Feb 2006
Location: Hertfordshire
Posts: 49
CoXeY is on a distinguished road
Problem solved!

Needed to delete the queue in order to the clear the backlog and now everything seems to be ticking along just fine.

Thanks again guys

Dan.
__________________
Registered User
CoXeY is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
dot-qmail question pelinor Shared and Reseller Web Hosting 5 5th February 2004 11:18 AM


Some great companies!


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0