Skip to main content

Mail Statistics Summary

Comments

16 comments

  • cPanelMichael
    Hello :) I recommend reviewing the following log file: /var/log/exim_mainlog
    This will give you a better idea about what email is received/sent from your server. Thank you.
    0
  • khalled
    [quote="cPanelMichael, post: 1638201">Hello :) I recommend reviewing the following log file: /var/log/exim_mainlog
    This will give you a better idea about what email is received/sent from your server. Thank you.
    when i go to check the file exim_mainlog i found it volume veru huge and difficult to downlaod and check it but from Mail Statistics Summary in WHM i found the following Mail Statistics Summary in attached word file, i hope if you can help me to analysis it
    0
  • cPanelMichael
    Try using the "tail" command to view the last several lines of /var/log/exim_mainlog. EX: tail -500 /var/log/exim_mainlog
    The mail statistics are helpful, but it's not going to really help you to determine the source/cause of the email activity. Thank you.
    0
  • khalled
    very thanks for help i run the "tail" command and i get the following can you help me anylsis it
    0
  • cPanelMichael
    Hello :) I removed the output you provided because it's not good practice to post real email addresses on a public forum. From what I noticed, the messages were mostly from: [QUOTE]/home/*****/public_html/images
    I suggest reviewing the script in that directory and determine if it's legitimate or should be removed for sending out SPAM. Thank you.
    0
  • khalled
    very thanks for your help and for removing the output, i will check and give feedback
    0
  • khalled
    you are right cPanelMichael , i found send.php file the path you refer to which send this massages and i delete it alos i temporary change the name of usr/sbin/sendmail to stop mail spam but when i check [QUOTE]tail -500 /var/log/exim_mainlog
    i still have the following message which seam to be spam massage, i try to Remove All messages From the Mail Queue but not succeed by using # exim -bp | awk '/^ *[0-9]+[mhd]/{print "exim -Mrm " $3}' | bash # exim -bp | exiqgrep -i | xargs exim -Mrm the result of "tail" command as show below (you can delete it after review if it is wrong to share) very thanks for your help - Removed -
    0
  • Infopro
    [QUOTE]you are right cPanelMichael, i found send.php file the path you refer to which send this massages
    How would an email script file get into the images directory, unless the account has been compromised? Spam coming out of that account may not be your only problem.
    0
  • khalled
    i search internet to Remove All messages From the Mail Queue and run many commands but the service exim (exim-4.82-3.cp1136) failed, and when try to restart it iget the error [QUOTE]Waiting for exim to restart...............................................................finished. exim has failed, please contact the sysadmin.
    is any way to make it run or to remove and reinstall it
    0
  • cPanelMichael
    Please review the last couple of lines in /var/log/exim_mainlog or /var/log/exim_paniclog when Exim fails to restart. Do you notice any particular error messages? Thank you.
    0
  • khalled
    This the result and last couple of lines in /var/log/exim_mainlog or /var/log/exim_paniclog /root$ tail -500 /var/log/exim_mainlog 2014-05-08 09:17:56 1WiIaZ-0005je-RW no immediate delivery: load average 25.77 2014-05-08 09:17:56 cwd=/home/******/public_html/images 3 args: /usr/sbin/sendmail -oi -t 2014-05-08 09:17:56 1WiIaZ-0005jn-TH <= ******@server.******.net U=****** P=local S=773 id=13e49bbd4f55ee976dac803f544276e4@www.******.net T="Confirm Receipt" for username @aol.com 2014-05-08 09:17:56 1WiIaZ-0005jn-TH no immediate delivery: load average 25.77 2014-05-08 09:17:56 cwd=/home/******/public_html/images 3 args: /usr/sbin/sendmail -oi -t 2014-05-08 09:17:56 1WiIaa-0005kg-CU <= ******@server.******.net U=****** P=local S=4596 id=8bdd4afaa8424013763d0e8f99313943@www.******.net T="THE TRANSFER WILL BE DONE TODAY, IF WE HEAR FROM YOU." for username @aol.com 2014-05-08 09:17:56 1WiIaa-0005kg-CU no immediate delivery: load average 25.77 2014-05-08 09:17:56 cwd
    /root$ tail -500 /var/log/exim_paniclog 2014-05-08 09:17:03 1WiIZi-00047m-C1 User 0 set for local_delivery transport is on the never_users list 2014-05-08 09:17:03 1WiIZj-0004AN-JH User 0 set for local_delivery transport is on the never_users list 2014-05-08 09:17:13 1WiIZs-0004g8-LC User 0 set for local_delivery transport is on the never_users list 2014-05-08 09:17:14 1WiIZs-0004gB-O5 User 0 set for local_delivery transport is on the never_users list 2014-05-08 09:17:15 1WiIZt-0004iN-W4 User 0 set for local_delivery transport is on the never_users list
    0
  • cPanelMichael
    I see no entries that would indicate a reason why Exim is failing. Are you sure it's not running? Is the Exim process active? Thank you.
    0
  • khalled
    [quote="cPanelMichael, post: 1641352">I see no entries that would indicate a reason why Exim is failing. Are you sure it's not running? Is the Exim process active? Thank you.
    i check service as shown in this post
    0
  • khalled
    [quote="khalled, post: 1641491">i check service as shown in this post
    0
  • khalled
    thanks it run and i do the following if any suffer from that WHM"cPanel "Upgrade to Latest Version Upgrade to Latest Version check Force a reinstall even if the system is up to date. and Upgrade
    0
  • cPanelPeter cPanel Staff
    Hello, Yes, an upgrade (upcp) can usually solve problems like what you were experiencing. Thanks for updating this thread.
    0

Please sign in to leave a comment.