I am getting "Undelivered Mail Returned to Sender" messages. The relevant mail messages are being forwarded using a valid user ([email protected]) on my server (server1.nbicharts.com). I control that email address, so it is not me that's doing the forwarding. I have tested that my server is not an open relay so I need help on how to track the vulnerability that is allowing this to happen. I presume that although I am seeing only the undelivered messages, there must be more that are being delivered.
Any help will be greatly appreciated.
Here is a typical message:
This is the mail system at host server1.nbicharts.com.
I'm sorry to have to inform you that your message could not be delivered to one or more recipients. It's attached below.
For further assistance, please send mail to postmaster.
If you do so, please include this problem report. You can delete your own text from the attached returned message.
The mail system
<[email protected]>: host b.as.safentrix.com[23.239.12.179] said:
550 5.1.1 <[email protected]>: Recipient address rejected: User
unknown (in reply to RCPT TO command)
Reporting-MTA: dns; server1.nbicharts.com
X-Postfix-Queue-ID: D7340580C88
X-Postfix-Sender: rfc822; [email protected]
Arrival-Date: Sat, 25 Jul 2015 06:35:04 -0400 (EDT)
Final-Recipient: rfc822; [email protected]
Original-Recipient: rfc822;[email protected]
Action: failed Status: 5.1.1
Remote-MTA: dns; b.as.safentrix.com
Diagnostic-Code: smtp; 550 5.1.1 <[email protected]>: Recipient
address rejected: User unknown
ForwardedMessage.eml
Subject: Reply: kavithamai
From: kavithamai <[email protected]>
Date: 07/25/2015 01:35 AM
To: "hrrecruitmentcell" <[email protected]>
Begin forwarded message
>
>>
>>> http://freefinancialstresstest.com/lazbqala.php?kavithamai
>
> From: Kavithamai [email protected]
> Date: Fri, 25 Jul 2015 11:35:04 +0000
> To: Hrrecruitmentcell
> Subject: Re: Fwd
>
> 7/25/2015 11:35:04 AM
Sent from my iPad
Here the mail.log
Jul 25 06:35:06 server1 postfix/smtp[18650]: D7340580C88: to=<[email protected]>, relay=b.as.safentrix.com[23.239.12.179]:25, delay=1.8, delays=1.1/0/0.45/0.2, dsn=5.1.1, status=bounced (host b.as.safentrix.com[23.239.12.179] said: 550 5.1.1 <[email protected]>: Recipient address rejected: User unknown (in reply to RCPT TO command))