New domain, endless spam. Old catch all?
I have faith in my mail server configuration. A majority are receiving 504 and 554 responses. These mailboxes don't exist on my end, the spammers aren't using FQDNs, and a majority are hitting my RBLs. Those that aren't receiving errors are bouncing against my greylist. I'm not a relay, and have been successfully using this server for about a year. Unfortunately, I'm not a professional sys admin, and don't have much experience in stopping these sorts of things properly. I added a few senders to my shorewall blacklist, but these messages are pouring in from thousands of IPs all over the world, so that's kind of fruitless.
I have a feeling I picked up a domain with an old catch-all address that ended up absorbing a ton of crud over the years. Is there any way to effectively stop these bots from even attempting to hit these mailboxes/ my server, or is this something I'll inherit forever? It's not causing me performance or stability issues, but I'd enjoy it if my logs weren't growing and filling with all this junk. Thanks in advance for your suggestions.
10 Replies
Like this one:
@hoopycat:
If you want to receive mail for that domain, you'll have to receive mail for that domain. No way around it, really. Best bet is to ignore it and let logrotate take care of the logs. You can throw money at the problem and let someone else's logs fill up, but I'd rather spend the money on little chocolate donuts. They're proven to work.
![](
@nomad89:
Wish there was an in-house way to resolve this, but it sounds like the only solution is a mediation server. Mail route looks interesting, will read into it more. Thanks for the info.
There is an in-house way:
spamassassin, clamav, amavisd, etc are common software used. Though these take some skill and time to setup and get going.
But if you don't want to do that, those other services where you simply adjust your mx record will take care of the spam filtering for you.
Cheers,
@neo:
If you are using RBLs like spamhaus.org pretty soon they will ask you to pay to continue to use their services because of the volume of checks you perform.
You have to exceed 100,000 SMTP connections/day and/or 300,000 queries/day before you outgrow their free service.
@vonskippy:
@neo:If you are using RBLs like spamhaus.org pretty soon they will ask you to pay to continue to use their services because of the volume of checks you perform.
You have to exceed 100,000 SMTP connections/day and/or 300,000 queries/day before you outgrow their free service. It is a little ironic that 'all' a spammer has to do to circumvent a free service is to send even more spam. Although I guess that's more of an attack than spam.
@vonskippy:
@neo:If you are using RBLs like spamhaus.org pretty soon they will ask you to pay to continue to use their services because of the volume of checks you perform.
You have to exceed 100,000 SMTP connections/day and/or 300,000 queries/day before you outgrow their free service.
OP said he receives "about 1 or 2 messages per second".