Недавно обнаружил что с почты root@*mydomain* идут рассылки на левые ящики. Сам ящик рута отключен в postfixadmin. Папки исходящие нет. Не знаю как посмотреть какие письма отправить пытается и самое главное выглядит как спам-рассылка, по 10-15 сообщений в день в разное время. ClamAV вирусы не нашел. Смена пароля на руте не привела ни к чему. Может кто знает что это и куда смотреть?
Какие логи и конфиги предоставить в первую очередь?
Вот лог отправки письма с рута:
Jul 16 05:55:40 mail opendkim[25902]: 9B0D53766737: DKIM-Signature field added (s=mail, d=*mydomain*)
Jul 16 05:55:40 mail postfix/qmgr[4310]: 9B0D53766737: from=<root@*mydomain*>, size=4243, nrcpt=1 (queue active)
Jul 16 05:55:40 mail postfix/smtp[29993]: 854DC3766731: to=<galonsoma@pep.pemex.com>, relay=127.0.0.1[127.0.0.1]:10025, delay=0.25, delays=0.07/0/0.04/0.14, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 9B0D53766737)
Jul 16 05:56:11 mail postfix/smtp[30121]: 9B0D53766737: to=<galonsoma@pep.pemex.com>, relay=none, delay=30, delays=0.14/0/30/0, dsn=4.4.1, status=deferred (connect to pep.pemex.com[200.23.91.68]:25: Connection timed out)
И вот
Jul 15 18:05:59 mail postfix/smtpd[22261]: 028943766740: client=localhost[127.0.0.1]
Jul 15 18:05:59 mail postfix/cleanup[22263]: 028943766740: message-id=<20200715150558.E0C84376673F@*mydomain*>
Jul 15 18:05:59 mail opendkim[25902]: 028943766740: DKIM-Signature field added (s=mail, d=*mydomain*)
Jul 15 18:05:59 mail postfix/qmgr[4310]: 028943766740: from=<root@*mydomain*>, size=7414, nrcpt=1 (queue active)
Jul 15 18:05:59 mail postfix/smtp[22258]: E0C84376673F: to=<gallerojr@live.com.mx>, relay=127.0.0.1[127.0.0.1]:10025, delay=0.23, delays=0.08/0/0.04/0.11, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 028943766740)
Jul 15 18:06:00 mail postfix/smtp[22844]: 028943766740: host nam.olc.protection.outlook.com[104.47.56.161] said: 451 4.7.650 The mail server [*myipserver*] has been temporarily rate limited due to IP reputation. For e-mail delivery information, see https://postmaster.live.com (S775) [CO1NAM11FT061.eop-nam11.prod.protection.outlook.com] (in reply to MAIL FROM command)
Jul 15 18:06:00 mail postfix/smtp[22844]: 028943766740: lost connection with nam.olc.protection.outlook.com[104.47.56.161] while sending RCPT TO
Jul 15 18:06:00 mail postfix/smtp[22844]: 028943766740: to=<gallerojr@live.com.mx>, relay=nam.olc.protection.outlook.com[104.47.58.161]:25, delay=1.9, delays=0.11/0/1.7/0.16, dsn=5.5.0, status=bounced (host nam.olc.protection.outlook.com[104.47.58.161] said: 550 5.5.0 Requested action not taken: mailbox unavailable (S2017062302). (in reply to RCPT TO command))
Jul 15 18:06:01 mail postfix/bounce[22686]: 028943766740: sender non-delivery notification: 0F2B53766744
Jul 15 18:06:01 mail postfix/qmgr[4310]: 028943766740: removedJul 15 18:05:59 mail postfix/smtpd[22261]: 028943766740: client=localhost[127.0.0.1]
Jul 15 18:05:59 mail postfix/cleanup[22263]: 028943766740: message-id=<20200715150558.E0C84376673F@*mydomain*>
Jul 15 18:05:59 mail opendkim[25902]: 028943766740: DKIM-Signature field added (s=mail, d=*mydomain*)
Jul 15 18:05:59 mail postfix/qmgr[4310]: 028943766740: from=<root@*mydomain*>, size=7414, nrcpt=1 (queue active)
Jul 15 18:05:59 mail postfix/smtp[22258]: E0C84376673F: to=<gallerojr@live.com.mx>, relay=127.0.0.1[127.0.0.1]:10025, delay=0.23, delays=0.08/0/0.04/0.11, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 028943766740)
Jul 15 18:06:00 mail postfix/smtp[22844]: 028943766740: host nam.olc.protection.outlook.com[104.47.56.161] said: 451 4.7.650 The mail server [*myipserver*] has been temporarily rate limited due to IP reputation. For e-mail delivery information, see https://postmaster.live.com (S775) [CO1NAM11FT061.eop-nam11.prod.protection.outlook.com] (in reply to MAIL FROM command)
Jul 15 18:06:00 mail postfix/smtp[22844]: 028943766740: lost connection with nam.olc.protection.outlook.com[104.47.56.161] while sending RCPT TO
Jul 15 18:06:00 mail postfix/smtp[22844]: 028943766740: to=<gallerojr@live.com.mx>, relay=nam.olc.protection.outlook.com[104.47.58.161]:25, delay=1.9, delays=0.11/0/1.7/0.16, dsn=5.5.0, status=bounced (host nam.olc.protection.outlook.com[104.47.58.161] said: 550 5.5.0 Requested action not taken: mailbox unavailable (S2017062302). (in reply to RCPT TO command))
Jul 15 18:06:01 mail postfix/bounce[22686]: 028943766740: sender non-delivery notification: 0F2B53766744
Jul 15 18:06:01 mail postfix/qmgr[4310]: 028943766740: removed