Skip to main content

root emailing an account but can't figure out what or why.

Comments

9 comments

  • postcd
    Isnt your hosted php script set to send an email to non existing address? im just guessing, im noob.
    0
  • keat63
    It's not a PHP script, its an application running on a PC in the office. Basically works just like an email client, which has a valid to and from address. Its seems the auto.invoice address is replying to root, but i can't see root sending anything, so i'm confused why it's replying.
    0
  • cPanelMichael
    Hello :) What's the output when you search for "auto.invoice" in /var/log/exim_mainlog? EX:
    exigrep auto.invoice /var/log/exim_mainlog
    Thank you.
    0
  • keat63
    Unfortunately, auto.invoice is sending a very large number of legitimate emails, so the logs will be huge. However, i found this around the time. I believe this might be auto.invoice emailing root.
    2015-02-25 18:44:06 cwd=/home/user-acc 3 args: /usr/sbin/sendmail -fauto.invoice@mydomain.com -t 2015-02-25 18:44:06 1YQgwH-0007KR-VJ <= <> R=1YQGZZ-0007aZ-K6 U=mailnull P=local S=1133 T="Warning: message 1YQGZZ-0007aZ-K6 delayed 24 hours" for auto.invoice@mydomain.com 2015-02-25 18:44:06 1YQgwH-0007KR-VJ => auto.invoice R=virtual_user T=virtual_userdelivery 2015-02-25 18:44:06 1YQgwH-0007KR-VJ => |/usr/local/cpanel/bin/autorespond auto.invoice@mydomain.com /home/user-acc/.autorespond (auto.invoice@mydomain.com) R=virtual_aliases_nostar T=jailed_virtual_address_pipe 2015-02-25 18:44:06 1YQgwH-0007KR-VJ Completed 2015-02-25 18:44:06 1YQgwI-0007Kb-Jj <= auto.invoice@mydomain.com U=user-acc P=local S=1016 T="re: Warning: message 1YQGZZ-0007aZ-K6 delayed 24 hours" for Mailer-Daemon@host.myserver.co.uk 2015-02-25 18:44:07 1YQgwI-0007Kb-Jj => server (root@host.myserver.co.uk, postmaster@host.myserver.co.uk) R=virtual_user T=virtual_userdelivery 2015-02-25 18:44:07 1YQgwI-0007Kb-Jj Completed
    And here is the K6 going out.
    2015-02-24 14:34:54 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1YQGZZ-0007aZ-K6 2015-02-25 18:44:05 cwd=/var/spool/exim 7 args: /usr/sbin/exim -t -oem -oi -f <> -E1YQGZZ-0007aZ-K6 2015-02-25 18:44:06 1YQgwH-0007KR-VJ <= <> R=1YQGZZ-0007aZ-K6 U=mailnull P=local S=1133 T="Warning: message 1YQGZZ-0007aZ-K6 delayed 24 hours" for auto.invoice@mydomain.co.uk 2015-02-25 18:44:06 1YQgwH-0007KR-VJ => auto.invoice R=virtual_user T=virtual_userdelivery 2015-02-25 18:44:06 1YQgwH-0007KR-VJ => |/usr/local/cpanel/bin/autorespond auto.invoice@mydomain.co.uk /home/user-acc/.autorespond (auto.invoice@mydomain.co.uk) R=virtual_aliases_nostar T=jailed_virtual_address_pipe 2015-02-25 18:44:06 1YQgwH-0007KR-VJ Completed 2015-02-25 18:44:06 1YQgwI-0007Kb-Jj <= auto.invoice@mydomain.co.uk U=user-acc P=local S=1016 T="re: Warning: message 1YQGZZ-0007aZ-K6 delayed 24 hours" for Mailer-Daemon@host.servername.co.uk 2015-02-25 18:44:07 1YQgwI-0007Kb-Jj => server (root@host.servername.co.uk, postmaster@host.servername.co.uk) R=virtual_user T=virtual_userdelivery 2015-02-25 18:44:07 1YQgwI-0007Kb-Jj Completed +++ 1YQGZZ-0007aZ-K6 has not completed +++ 2015-02-24 14:34:54 1YQGZZ-0007aZ-K6 H=host81-134-17-175.in-addr.btopenworld.com (PRINTMACHINEPC) [xx.xxx.xx.xxx]:55231 Warning: Message has been scanned: no virus or other harmful content was found 2015-02-24 14:34:54 1YQGZZ-0007aZ-K6 <= auto.invoice@mydomain.co.uk H=hostxx-xxx-xx-xxx.in-addr.btopenworld.com (PRINTMACHINEPC) [xx.xxx.xx.xxx]:55231 P=esmtpa A=dovecot_login:auto.invoice@mydomain.co.uk S=225290 id=BFA8A45A0A014D0AB0ADFDD202BC929C@user-acc.local for caroline@customer.co.uk 2015-02-24 14:34:54 1YQGZZ-0007aZ-K6 SMTP connection outbound 1424788494 1YQGZZ-0007aZ-K6 mydomain.co.uk caroline@customer.co.uk 2015-02-24 14:35:57 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-24 14:35:57 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-24 15:00:02 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-24 15:00:02 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-24 16:00:02 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-24 16:00:02 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-24 17:00:02 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-24 17:00:02 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-24 19:00:02 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-24 19:00:02 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-24 21:00:02 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-24 21:00:02 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-25 00:00:02 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-25 00:00:02 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-25 04:00:02 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-25 04:00:02 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-25 09:44:08 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-25 09:44:08 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-25 18:44:05 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-25 18:44:05 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-26 03:44:07 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-26 03:44:07 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out 2015-02-26 12:44:07 1YQGZZ-0007aZ-K6 customer.co.uk [69.172.201.208] Connection timed out 2015-02-26 12:44:07 1YQGZZ-0007aZ-K6 == caroline@customer.co.uk R=dkim_lookuphost T=dkim_remote_smtp defer (110): Connection timed out
    0
  • cPanelMichael
    Should the "auto.invoice@mydomain" email address receive any email? If not, then you could setup an email filter that fails with a specific bounce message (e.g. not a valid address, call number) instead of using an autoresponder. Thank you.
    0
  • keat63
    Being a new application bolted to our antiquated invoicing system, there are a number of typo's and mis formed email addresses, so i sort of rely on the mailbox to capture any bounces. The bounces give me more information as to who the customer was, so really need the it to be honest.
    0
  • cPanelMichael
    ] About twice per day, i receive one of these auto responses in myemail@mydomain.com, but for the life of me can't figure out why.

    You may just want to setup a filter to move these specific messages to another email folder for your review. Thank you.
    0
  • kdean
    You originally asked why root was receiving an email and I don't think I've seen anyone explain. From the contents of your first post this what looks to be happening. auto.invoice@mydomain.com is sending an email to an address that your mail server is having problems delivering to, causing a delay. Your Mailer-Daemon@host.servername.com is sending a "delayed 24 hours" email notification to auto.invoice@mydomain.com which in turns triggers it's auto-reply to respond to Mailer-Daemon@host.servername.com which in turn delivers that response to root. This is why root is receiving an email as far as I could see. Seems that cPanel should add a feature so that mail accounts don't auto respond to local Mailer-Daemon emails.
    0
  • keat63
    KDean. That makes perfect sense.
    0

Please sign in to leave a comment.