I've got some curious entries in my Spam filter logs. After testing this program for nearly 2 months, I decided to switch all of my client mx records today so that Spam Filter ISP is protecting their email. I did this switch early this morning, and more and more emails are coming through.
At 2:20p, 4:03p, and 7:20p today, I've had 3 sets of 49 entries, with the beginning of each log entry in a particular group 30 seconds apart from the others in that group, that look like this:
09/24/05 14:20:28:885 -- (104284) Connection from: <my SF IP> - Originating country : United States 09/24/05 14:20:28:978 -- (104284) Resolving <my SF IP> - Not found 09/24/05 14:20:28:978 -- (104284) Bypassed all rules for: <valid_ client_address> from <unknown_3rd_party_address> ( We Are Sender) 09/24/05 14:20:29:056 -- (104284) EMail from <unknown_3rd_party_address> to <valid_ client_address> was queued. Size: 1 KB, 1024 bytes 09/24/05 14:20:29:056 -- (107472) (107472) Sending email from <unknown_3rd_party_address> to <valid_ client_address> 09/24/05 14:20:29:088 -- (110004) Time to add Msg to Bayes corpus:0 09/24/05 14:20:29:119 -- (104284) Disconnect 09/24/05 14:20:29:306 -- (107472) (107472) EMail from <unknown_3rd_party_address> to <valid_ client_address> was forwarded to <my.mail.server>:25
What I distinguish as a group is different to and from addresses and an actual break in the time sequence.
I've done open relay tests, and I've tried using a pop client to send through SF without success. The only thing that has come close is using SF as the sending server from a pop client actually on the mail server itself. That test produced a log entry very similar to that above. However, I have no indication that I've had a server security breach, and a virus scan turns up nothing out of the ordinary.
Does anyone have anything similar? Do a search on your log files for the phrase "We are sender". That's how I found mine. The reason I thought to look for this was that I watched one come in on the activity log.
This is most puzzling. The fact that's been exactly 49 messages each time and that each message is 30 seconds apart from the last leads me to believe that its some sort of program doing this, but I can't seem to find any indication of that. Any help would be most appreciated.
|