I am getting "Undelivered Mail Returned to Sender" messages. The relevant mail messages are being forwarded using a valid user (mike@proactech.com) on my server (server1.nbicharts.com). I control that email address, so it is not me that's doing the forwarding. I have tested that my server is not an open relay so I need help on how to track the vulnerability that is allowing this to happen. I presume that although I am seeing only the undelivered messages, there must be more that are being delivered.
Any help will be greatly appreciated.
Here is a typical message:
This is the mail system at host server1.nbicharts.com.
I'm sorry to have to inform you that your message could not be delivered to one or more recipients. It's attached below.
For further assistance, please send mail to postmaster.
If you do so, please include this problem report. You can delete your own text from the attached returned message.
The mail system
<hrrecruitmentcell@tvssons.com>: host b.as.safentrix.com[23.239.12.179] said:
550 5.1.1 <hrrecruitmentcell@tvssons.com>: Recipient address rejected: User
unknown (in reply to RCPT TO command)
Reporting-MTA: dns; server1.nbicharts.com
X-Postfix-Queue-ID: D7340580C88
X-Postfix-Sender: rfc822; mike@proactech.com
Arrival-Date: Sat, 25 Jul 2015 06:35:04 -0400 (EDT)
Final-Recipient: rfc822; hrrecruitmentcell@tvssons.com
Original-Recipient: rfc822;hrrecruitmentcell@tvssons.com
Action: failed Status: 5.1.1
Remote-MTA: dns; b.as.safentrix.com
Diagnostic-Code: smtp; 550 5.1.1 <hrrecruitmentcell@tvssons.com>: Recipient
address rejected: User unknown
ForwardedMessage.eml
Subject: Reply: kavithamai
From: kavithamai <mike@proactech.com>
Date: 07/25/2015 01:35 AM
To: "hrrecruitmentcell" <hrrecruitmentcell@tvssons.com>
Begin forwarded message
>
>>
>>> http://freefinancialstresstest.com/lazbqala.php?kavithamai
>
> From: Kavithamai -kavithamai@yahoo.co.in-
> Date: Fri, 25 Jul 2015 11:35:04 +0000
> To: Hrrecruitmentcell
> Subject: Re: Fwd
>
> 7/25/2015 11:35:04 AM
Sent from my iPad
Here the mail.log
Jul 25 06:35:06 server1 postfix/smtp[18650]: D7340580C88: to=<hrrecruitmentcell@tvssons.com>, relay=b.as.safentrix.com[23.239.12.179]:25, delay=1.8, delays=1.1/0/0.45/0.2, dsn=5.1.1, status=bounced (host b.as.safentrix.com[23.239.12.179] said: 550 5.1.1 <hrrecruitmentcell@tvssons.com>: Recipient address rejected: User unknown (in reply to RCPT TO command))