limit mail account access to my IP
Hello
is thier a way to limit my mail account access to my IP only?
I can not trust strong password only so I need more security proceedures to protect my mail account from spamers
-
Hello :) Are you attempting to limit email access globally for the entire server or limit access to a single account? Thank you. 0 -
Limit email access globally for the entire server. the past few days I am getting huge login failure alerted by LFD/csf firewall like this: [QUOTE] Time: Sat Mar 1 17:03:03 2014 +0300 IP: 27.55.7.191 (TH/Thailand/ppp-27-55-7-191.revip3.asianet.co.th) Failures: 1 (smtpauth) Interval: 3600 seconds Blocked: Permanent Block
and the pattern change to be attacks on mod_security: [QUOTE] Time: Mon Mar 3 09:48:12 2014 +0300 IP: 217.69.133.191 (RU/Russian Federation/fetcher7.mail.ru) Failures: 1 (mod_security) Interval: 3600 seconds Blocked: Permanent Block
I really dont understand what is happening and why suddenly all these huge attacks!!!!0 -
The following options might be of help to you if you want to block access for all IP addresses except for your own: "WHM Home " Security Center " Host Access Control" "WHM Home " Security Center " cPHulk Brute Force Protection" Thank you. 0 -
Thank you cPanelMichael, I already done that long time ago but that didnt stop the spammer from hijacking my email account password. If I already configured /etc/hosts.deny to ALL:ALL and etc/hosts.allow to allow ONLY my Ip adress, how the spammer was able access my email account with different IP adress than mine? 0 -
We need more information about the emails that were sent out to address that question. For instance, what information were you able to obtain from the mail headers or logs in /var/log/exim_mainlog? Thank you. 0 -
There is no doubts the spam emails were sent from my server, when I checked (mail queue manager) in WHM there were hundreds of those emails listed and waiting to be sent as shown in the attached image. what info do I need from mail headers or logs in /var/log/exim_mainlog? from the attachement its is obvious the spam is sent from my server and it stopped after I changed the email account password (strong one this time) 0 -
The mail headers and logs in /var/log/exim_mainlog might help explain "how" the messages were sent out (e.g. authentication or through a PHP script). Thank you. 0 -
Ok, here is the headers of one of spam emails: [QUOTE] Return-path: <> Envelope-to: webmaster@mydomain.com Delivery-date: Sat, 01 Mar 2014 13:13:41 +0300 Received: from mailnull by mydomain.softlayer.com with local (Exim 4.82) id 1WJgvM-00081W-Tz for webmaster@mydomain.com; Sat, 01 Mar 2014 13:13:40 +0300 X-Failed-Recipients: sabbre@hotmail.com, json.5@hotmail.com, mjbarron35@hotmail.com, kjtaft@hotmail.com Auto-Submitted: auto-replied From: Mail Delivery System To: webmaster@mydomain.com Subject: Mail delivery failed: returning message to sender Message-Id: Date: Sat, 01 Mar 2014 13:13:40 +0300 0 -
Is that a header of a message that you see in the mail queue? If you search for "determine spam source" on our forums you will see several threads that will help you through the process of how to identify the source of a SPAM message. EX: SPAM Mail Sent From Server Thank you. 0
Please sign in to leave a comment.
Comments
9 comments