Hello, how do I know if my mail server is compromised?
If you write an email to one of my clients, you will always get an email from a Russian server, which I have nothing to do with.
This is the message it sends back.
forward2office@mail.ua
Remote Server returned '554 5.4.0 < #4.4.1 X-Postfix; connect to mxs.mail.ru[94.100.180.104]:25: Connection timed out>'
Encabezados de mensajes originales:
Return-Path: <withheld for security reasons>
Received: by host.bytecanarias.work (Postfix, from userid 101)
id 69878900BC7; Thu, 26 Mar 2020 20:00:20 +0000 (GMT)
X-Sieve: Pigeonhole Sieve 0.4.24 (124e06aa)
X-Sieve-Redirected-From: withheld for security reasons
Delivered-To: withheld for security reasons
Received: from localhost (unknown [127.0.0.1])
by host.bytecanarias.work (Postfix) with ESMTP id 59EBC9005D5
for <withheld for security reasons>; Thu, 26 Mar 2020 20:00:20 +0000 (UTC)
X-Virus-Scanned: amavisd-new at bytecanarias.work
Received: from host.bytecanarias.work ([127.0.0.1])
by localhost (host.bytecanarias.work [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id hs_r8si4EHlt for <withheld for security reasons>;
Thu, 26 Mar 2020 20:00:14 +0000 (GMT)
Received: from smtpout1.r2.mail-out.ovh.net (smtpout1.r2.mail-out.ovh.net [54.36.141.1])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(No client certificate requested)
by host.bytecanarias.work (Postfix) with ESMTPS id AD0609005D7
for <withheld for security reasons>; Thu, 26 Mar 2020 20:00:14 +0000 (GMT)
Received: from ex3.mail.ovh.net (unknown [10.109.143.189])
by mo511.mail-out.ovh.net (Postfix) with ESMTPS id 5BB53D1C926B
for <withheld for security reasons>; Thu, 26 Mar 2020 21:00:14 +0100 (CET)
Received: from DAG5EX3.indiv3.local (172.16.2.20) by DAG5EX3.indiv3.local
(172.16.2.20) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.1913.5; Thu, 26 Mar
2020 21:00:13 +0100
Received: from DAG5EX3.indiv3.local ([fe80::a912:a56d:69ec:3645]) by
DAG5EX3.indiv3.local ([fe80::a912:a56d:69ec:3645%2]) with mapi id
15.01.1913.007; Thu, 26 Mar 2020 21:00:13 +0100
From: =?iso-8859-1?Q?Direcci=F3n?= <withheld for security reasons>
To: CARUMAQ SL <withheld for security reasons>
Subject: CERTIFICADO
Thread-Topic: CERTIFICADO
Thread-Index: AdYDqRkq9c7lIpW8RjKQwcNtrIYHZw==
Date: Thu, 26 Mar 2020 20:00:13 +0000
Message-ID: <7e3fe5605ee64234b9f6b09e29d5e1a1@gestidoasesores.com>
Accept-Language: es-ES, en-US
Content-Language: es-ES
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
x-originating-ip: [83.40.14.70]
Content-Type: text/plain
MIME-Version: 1.0
X-Ovh-Tracer-Id: 706502192279941469
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 0
X-VR-SPAMCAUSE: