Start a conversation

Anti-Spoofing not preventing Spoofed Spam Messages from a certain IP

Overview

You have enabled Anti-Spoofing, but continue to see spoofed spam emails from a particular IP address, such as the Localhost (127.0.0.1), getting stuck in the mail queue with the errors like “4.4.2 Connection Lost.” 

 

mceclip0.png

 

Solution

This issue can occur when the emails are being relayed from an IP address contained within your Security Configuration's IP address groups exceptions, such as the default "Local Clients" group. In some cases, this can be the result of a compromised device within your network. 

To help mitigate this issue while investigating the source of the messages, you can reference the steps below:

  1. Make the following adjustments to prevent new spam emails from reaching the message queue:
    1. Navigate to Web Admin > Configuration > SMTP Server > Relay Control:
      1. Disable “Users from IP address Group
      2. Enable "Users authenticated through SMTP for outgoing mail."
        mceclip2.png
    2. Web Admin > Configuration > Security > Security Policy.
      1. Disable “Allow unsecured authentication from IP Address group”
        mceclip3.png
    3. Web Admin > Configuration > Security > Sender Policy.
      1. Disable “Never Reject Messages from this IP address group”
        mceclip4.png
  2. Manually Clear the Message Queue.
  3. Monitor the Message Queue for new messages.

 

Testing

After removing the IP Address Groups, the Message Queue should no longer fill with these spoofed spam messages. It is suggested that you then reference the steps within Detecting Compromised Servers Used for Spamming to help isolate the source of the spam messages.

Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted
  3. Updated

Comments