Skip to main content

Email Received but from wrong accounts

Comments

5 comments

  • milen777
    the funny thing is that someotheruser@mycpaneldomain.com it is real account on the server, but peter did not send email to that otheruser but to myemail@mycpaneldomain.com thanks....
    0
  • milen777
    hah, I fixit it but still dont know why this rewrite of remote header happen.... I disable "EXPERIMENTAL: Rewrite From: header to match actual sender" and now no more incorrect FROM accounts
    0
  • cPanelMichael
    hah, I fixit it but still dont know why this rewrite of remote header happen.... I disable "EXPERIMENTAL: Rewrite From: header to match actual sender" and now no more incorrect FROM accounts

    Hello, Was the "EXPERIMENTAL: Rewrite From: header to match actual sender" option configured as "All" or "Remote" before you disabled it? Is it possible the message came from a local account through a PHP script? You can search for one of the messages in /var/log/exim_mainlog to get a better idea of what happened with a command such as:
    exigrep MSGID /var/log/exim_mainlog
    Thank you.
    0
  • milen777
    Hi this code return the following:
    2016-06-01 16:02:50 1b7zEw-000646-De <= someusr@gmail.com H=mail-oi0-f44.google.com [209.85.218.44]:34485 P=esmtps X=TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128 CV=no S=526236 id=-6228852111706072935@unknownmsgid T="Quote for shirts." for stores@example.org 2016-06-01 16:02:50 1b7zEw-000646-De => stores R=virtual_user T=virtual_userdelivery 2016-06-01 16:02:50 1b7zEw-000646-De Completed
    I can not remember what the "EXPERIMENTAL: Rewrite From: header to match actual sender:" was set to but it will pickup random cpanel email account and place it on all the remote incoming emails. faking the email address of the remote sender email address with local cpanel email address, so no one pay attention and when hit reply and send the email was going to random cpanel email address, and not to the remote domain. I think i was fighting spam when i tick it to see what will happened, and forgot about it, by default is disabled. absolutely no problem since i disable it.everything is going smooth as whiskey on ice. No php script. the emails was coming from identified senders, when they complain that are not getting our emails i check and found out the email headers was re-written with local cpanel email addresses, and replacing the actual sender email address with cpanel random email accounts
    0
  • cPanelMichael
    Would you mind opening a support ticket so we can attempt to reproduce this issue on your system and determine why that happened? You can post the ticket number here so we can update this thread with the outcome. Thank you.
    0

Please sign in to leave a comment.