Results 1 to 2 of 2

Thread: possible to trace auth user to sent mail?

  1. #1
    Join Date
    Jul 2008
    Rep Power

    Question possible to trace auth user to sent mail?

    Dealing with spambots that probably have auth user/pwd to send mail. We need to trace down what account is sending a volume of messages. Tried hunting the logs and the x- headers, but those show only localhost6, so my assumption is that webmail is being used to transmit those but I can't seem to link the outgoing mail to a given user.

    Is it possible to show who is sending emails or at least trace it down?


    version: Zimbra Community Server 6.0.4
    Last edited by gazumping; 05-05-2010 at 01:33 PM. Reason: zimbra version

  2. #2
    Join Date
    Oct 2005
    USA, Canada and India
    Rep Power


    tail -n 1000000 /var/log/maillog | grep "sasl_username=" > smtpauthlogins.txt
    above will spit out the "smtpauthlogins.txt" open it and see which user's name (sasl_username=USER_NAME) is repeating the most, that dude has a virus infected outlook or spammer got hold of his simple password and relaying SPAM by using SMTP AUTH

    change the password for that user asap.

    i2k2 Networks
    Dedicated & Shared Zimbra Hosting Provider

Similar Threads

  1. smtp auth failing 'auth_zimbra: not initialized'
    By kkg039 in forum Administrators
    Replies: 7
    Last Post: 09-05-2013, 11:10 AM
  2. Replies: 7
    Last Post: 02-03-2011, 06:01 AM
  3. [SOLVED] service zimbra starting slow
    By lufermalgo in forum Administrators
    Replies: 5
    Last Post: 02-05-2010, 02:06 PM
  4. Replies: 30
    Last Post: 01-13-2009, 07:00 AM
  5. fatal: Queue report unavailable - mail system is down
    By zzzzsg in forum Administrators
    Replies: 16
    Last Post: 08-24-2006, 02:31 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts