Ок допустим я сделаю грей лист он остановит это?
Пользователь сперва получает отбойник от MAILER-DAEMON@proofpoint1.rfn.ru о том что письмо не дошло до oknoff.kmv@mail.ru потому что 550 spam message rejected Исходник письма на стороне пользователя
Received: from mail.moidomen.ru (10.0.0.249) by Mail.moidomen.local (172.16.1.235) with Microsoft SMTP Server id 8.3.377.0; Tue, 1 Sep 2015 08:38:26 +0300
Received: from proofpoint1.rfn.ru (proofpoint1.rfn.ru [80.247.46.68]) by mail.moidomen.ru (Postfix) with ESMTP id B191E2EB840 for <user@moidomen.ru>; Tue, 1 Sep 2015 08:37:48 +0300 (MSK)
Received: from pps.filterd (proofpoint1 [127.0.0.1]) by proofpoint1.rfn.ru (8.14.5/8.14.5) with SMTP id t814gPaX013974 for <user@moidomen.ru>; Tue, 1 Sep 2015 08:38:51 +0300
Received: from mqueue.dsn (localhost [127.0.0.1]) by proofpoint1.rfn.ru with ESMTP id 1wmh5808yd-9025 for <user@moidomen.ru>; Tue, 01 Sep 2015 08:38:51 +0300
Received: from localhost (localhost) by proofpoint1.rfn.ru (8.14.5/8.14.5) id t7VAZ8C9030642; Mon, 31 Aug 2015 23:44:31 +0300
Date: Mon, 31 Aug 2015 23:44:31 +0300
From: Mail Delivery Subsystem <MAILER-DAEMON@proofpoint1.rfn.ru>
Message-ID: <201508312044.t7VAZ8C9030642@proofpoint1.rfn.ru>
To: <user@moidomen.ru>
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
boundary="----=_NextPart_000_02DD_01D0E491.926F1A50"
Subject: [Malicious object deleted]Returned mail: see transcript for details
Auto-Submitted: auto-generated (failure)
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:5.14.151,1.0.33,0.0.0000 definitions=2015-08-31_02:2015-08-31,2015-08-31,1970-01-01 signatures=0
Return-Path:
X-KSE-AntiSpam-Interceptor-Info: scan successful
X-KSE-AntiSpam-Version: 5.5.3, Database issued on: 09/01/2015 05:14:09
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4913
X-KSE-AntiSpam-Status: KAS_STATUS_FORMAL
X-KSE-AntiSpam-Method: none
X-KSE-AntiSpam-Rate: 0
X-KSE-AntiSpam-Info: Lua profiles 83089 [Sep 01 2015]
X-KSE-AntiSpam-Info: LuaCore: 263 263 4f49118830d428d351d8fb9d486a228258f3d0a4
X-KSE-AntiSpam-Info: Version: 5.5.3
X-KSE-AntiSpam-Info: Envelope from: <>
X-KSE-AntiSpam-Info: {Formal}
X-KSE-AntiSpam-Info: proofpoint1.rfn.ru:4.0.4;80.247.46.68:2.4.1,4.0.2,7.1.2,201.1.0;d41d8cd98f00b204e9800998ecf8427e.com:7.1.1;help.mail.ru:4.0.4,7.1.1;127.0.0.199:7.1.2;mail.moidomen.ru:7.1.1
X-KSE-AntiSpam-Info: {DNS response errors}
X-KSE-AntiSpam-Info: Rate: 0
X-KSE-AntiSpam-Info: Status: formal
X-KSE-AntiSpam-Info: Method: none
X-KSE-AntiSpam-Info: Moebius-Timestamps: 3719247, 3719273, 3719233
X-KSE-Antiphishing-Info: Clean
X-KSE-Antiphishing-Method: None
X-KSE-Antiphishing-Bases: 09/01/2015 05:18:00
X-MS-Exchange-Organization-SCL: 2
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-Antispam-Report: DV:3.3.15225.492;SV:3.3.4604.600;TIME:TimeBasedFeatures;OrigIP:80.247.46.68
X-KSE-Antivirus-Interceptor-Info: scan successful
X-KSE-Antivirus-Info: Disinfected
В логах сервера
# cat /var/log/maillog | grep B191E2EB840
Sep 1 08:37:48 mail postfix/smtpd[3495]: input attribute value: B191E2EB840
Sep 1 08:37:48 mail postfix/smtpd[3495]: B191E2EB840: client=proofpoint1.rfn.ru[80.247.46.68]
Sep 1 08:37:48 mail postfix/cleanup[3496]: B191E2EB840: message-id=<201508312044.t7VAZ8C9030642@proofpoint1.rfn.ru>
Sep 1 08:37:48 mail postfix/smtpd[3495]: > proofpoint1.rfn.ru[80.247.46.68]: 250 2.0.0 Ok: queued as B191E2EB840
Sep 1 08:37:48 mail postfix/qmgr[94414]: B191E2EB840: from=<>, size=200442, nrcpt=1 (queue active)
Sep 1 08:37:49 mail postfix/smtp[3479]: B191E2EB840: to=<user@moidomen.ru>, relay=172.16.1.235[172.16.1.235]:25, delay=0.83, delays=0.07/0/0/0.75, dsn=2.6.0, status=sent (250 2.6.0 <201508312044.t7VAZ8C9030642@proofpoint1.rfn.ru> Queued mail for delivery)
Sep 1 08:37:49 mail postfix/qmgr[94414]: B191E2EB840: removed
Не смотря на то что пришло от from=<> у пользователя в аутлуке он от MAILER-DAEMON@proofpoint1.rfn.ru выглядит так http://clip2net.com/s/3mSukW3
Ну или через час 13мин http://clip2net.com/s/3mSv34A о том что сервер будет пытаться доставить.
Самое не приятное что сервер по сути становиться опенрелеем из этого лога
# cat /var/log/maillog | grep BA34A2EB8BC
Sep 1 11:33:12 mail postfix/cleanup[4588]: BA34A2EB8BC: message-id=<20150901083312.BA34A2EB8BC@mail.moidomen.ru>
Sep 1 11:33:12 mail postfix/bounce[4649]: 4AD1C2EB858: sender non-delivery notification: BA34A2EB8BC
Sep 1 11:33:12 mail postfix/qmgr[94414]: BA34A2EB8BC: from=<>, size=3570, nrcpt=1 (queue active)
Sep 1 11:33:18 mail postfix/smtp[4607]: BA34A2EB8BC: to=<ruoczyrnv@kotioser.co.ua>, relay=mail.kotioser.co.ua[89.163.152.5]:25, delay=5.4, delays=0.02/0/5.2/0.18, dsn=2.0.0, status=sent (250 2.0.0 Ok: queued as 6B86AC52F3A)
Sep 1 11:33:18 mail postfix/qmgr[94414]: BA34A2EB8BC: removed