We've been getting connections from systems that look like they're dictionary sniffing for names to spam. Here's a quick snip:
10:01 10:16 SMTPD(00AB0274) [64.30.43.3] connect 194.198.208.9 port 1725 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] HELO sitemail.everyone.net 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] MAIL From: <[EMAIL PROTECTED]> 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]> 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com invalid user <[EMAIL PROTECTED] 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]> 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com invalid user <[EMAIL PROTECTED] 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]> 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com invalid user <[EMAIL PROTECTED] 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]> 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com invalid user <[EMAIL PROTECTED] 10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]> Now, this is just a small sample. They come in shots of 15-20, but it's every hour or so. I can deny the IP at the router, or something, but is there any better way to handle this? Oblio To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
