I'm running a mailserver based on postfix. There are a lot of connection failures like this:
Transcript of session follows.
Out: 220 hostname.tld ESMTP Postfix
In: .
Out: 502 5.5.2 Error: command not recognized
In:
Out: 500 5.5.2 Error: bad syntax
Session aborted, reason: lost connection
These connections come from different IPs, but in most cases in/as a bulk of a few tenths to hundreds attempts per IP.
What causes these connections? If this were viruses, worms or botnets that are "knocking on the door", why so many multiple times per host? Or is sending a single dot some kind of functionality test and my server reacts in the wrong way? Again, multiple tries make no sense. And it's far away from any DoS scale.
Maybe some of you know what's going on there?